Back to skill

Security audit

中国A股股票智能分析大师

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only China A-share research assistant that uses a remote MCP service and does not install code, trade, write data, or request credentials.

Before installing, confirm you trust the RedQuant hosted MCP endpoint and understand that queries may be sent to that service. Treat outputs as research only, especially where strategy subscriptions or product descriptions are discussed, and do not use it as a trading or personalized investment-advice tool.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description is written as a normative capability statement for a China A-share research skill and presents the skill as operating in Chinese, but nowhere in the file does it offer users a language choice or state that Chinese output is optional. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The persona prescribes locale-specific presentation rules such as Chinese currency units and color conventions for price movement, and the document is entirely framed in Chinese without indicating that users may choose another language or locale. This can violate language/locale policy because it effectively forces a specific locale presentation without explicit user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

get_strategy_subscription_info 获取价格/名额,get_platform_info 与策略集市枚举能力也更接近平台导购/产品分发场景;再结合后续“基金化的策略产品说明”能力,整体能力集已不只是A股只读研究信息查询。虽然这些工具未显示写操作,但其语义用途超出 manifest 所述的研究与风险提示输出范围。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

文件开头将对外工具概括为“46 个只读 MCP 工具”,且技能清单背景强调“仅输出研究信息与风险提示”。但这里公开列出的 generate_strategy_product_brief_from_config 与 generate_strategy_support_answer_from_config 明确是生成产品简介文案和客服答复,属于面向营销/运营沟通的生成能力,而非单纯只读研究查询。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
69% confidence
Finding

The file hardcodes China-market conventions such as A-share trading hours and 6位数字.SH/.SZ code formatting, but does not clarify whether these are domain-specific defaults or whether users can choose a different locale/language context. While market-specific constraints may be justified, the absence of an explicit justification or opt-in creates a mild locale-policy concern in the natural-language documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

该工具目录全文以中文呈现,且未说明这是面向特定中文用户群、地区合规要求,或提供其他语言选项。按规则,若技能在自然语言层面强制单一语言而无用户选择或明确合理说明,可视为语言/区域策略违规。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

L119 说明“内部实现类能力不会在此展示”,但 L108-L113 同页列出了“LLM集成优化”工具,如 process_query_with_optimization 和 get_llm_integration_stats,这类能力从命名看更像内部实现/集成优化能力而非普通用户业务工具。文档表述与所列内容存在直接张力。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.