Back to skill

Security audit

Deep Investment Research

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real investment-research skill, but it exposes too much of the agent environment to subprocesses and configurable helper code, so it needs user review before installation.

Install only if you are comfortable with investment topics, ticker symbols, and research queries being sent to third-party data/search providers. Avoid using it with confidential holdings or proprietary research themes, and prefer running it in an environment that contains only the specific API keys it needs, because current subprocess handling can expose unrelated environment secrets to helper scripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/policy_gov_fetcher.py:91
Finding

Configurable Search Subprocess Inherits the Complete Agent Environment

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ministry_scanner.py:318
Finding

Unvalidated Search and Page URLs Can Trigger Server-Side Request Forgery

Content
View full analysis
RECENT_DAYS: continue key = (title, url) if key in seen: continue seen.add(key) items.append({ "title": title, "url": url, "date": pub.strftime("%Y-%m-%d") if pub else "unknown", "days_old": old, "snippet": r.get("snippet", "")[:200], "source": r.get("source", ""), }) ``` When optional full-text retrieval is enabled, those URLs are fetched directly: ```python def fetch_article_content(url, max_chars=3000): try: html = safe_fetch(url) if not html: return None html = re.sub(r']*>.*?', '', html, flags=re.DOTALL) html = re.sub(r']*>.*?', '', html, flags=re.DOTALL) html = re.sub(r'<[^>]+>', ' ', html) html = re.sub(r'\s+', ' ', html).strip() return html[:max_chars] if html else None except Exception: return None ``` The shared fetch operation has no destination validation: ```python def safe_fetch(url, encoding='utf-8'): try: resp = requests.get(url, headers=HEADERS, timeout=TIMEOUT) if resp.status_code != 200: return None ``` Absolute links extracted from source page ...[truncated 2650 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/insider_transactions.py:16
Finding

Plaintext HTTP Sources Allow Research-Data Manipulation in Transit

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (79)

Tainted flow: 'FINNHUB_KEY' from os.environ.get (line 19, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/earnings_surprise.py (reported line 60)May include surrounding context.

python
from_date = (today - timedelta(days=7)).isoformat()
            to_date = today.isoformat()
            try:
                resp = requests.get(
                    f"{FINNHUB_URL}/calendar/earnings",
                    params={"from": from_date, "to": to_date, "token": FINNHUB_KEY},
                    timeout=15,

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
| 行业深度研究 | methodology/industry-research.md | templates/01 |

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
83% confidence
Finding

Copying the full parent environment into child processes can leak secrets such as API keys, tokens, proxy settings, or credentials to every fetcher subprocess, including ones that may log or mishandle them. In a data-collection pipeline that runs many external-data fetchers, broad environment inheritance increases blast radius if any child process is compromised or overly verbose.

Content

Scanner excerpt · scripts/data_daily.py (reported line 110)May include surrounding context.

python
"--output-dir", output_dir,
    ]
    
    env = os.environ.copy()
    env["PYTHONPATH"] = SCRIPTS_DIR
    
    is_heavy = FETCHERS.get(module_name, {}).get("heavy", False)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
83% confidence
Finding

This special fetcher also inherits the full process environment before spawning a child interpreter, creating the same unnecessary exposure of credentials and runtime secrets. Because this path executes a custom inline Python command, inherited secrets are available to imported code and any downstream network clients it invokes.

Content

Scanner excerpt · scripts/data_daily.py (reported line 165)May include surrounding context.

python
def run_special_fetcher(name: str, today: str, output_dir: str) -> dict:
    """Run policy_gov which has a different entry point."""
    env = os.environ.copy()
    env["PYTHONPATH"] = SCRIPTS_DIR
    
    if name == "policy_gov":

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing README content is written entirely in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises and instructs use of capabilities that imply environment-variable access, local file reads/writes, network access, and shell subprocess execution, but it does not declare any explicit permission scope. That omission weakens reviewability and least-privilege enforcement: users and platforms cannot easily tell what the skill is allowed to do before installation or execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest description is written as a Chinese-only operating description for broad investment research use, with no indication that users may choose another language. Because the skill is presented for general use rather than a clearly region-limited compliance context, this appears to impose a language/locale constraint without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger conditions are extremely broad ('any investment research request'), which can cause the skill to activate for routine conversations and unnecessarily send user prompts, symbols, or research topics to external tools. Overbroad activation increases accidental data exposure and makes it harder for users to predict when networked data collection or file writes will occur.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and required output template are entirely in Chinese, and the template is marked as mandatory to follow strictly. This imposes a specific language/locale on the skill without any opt-in, alternative language path, or documented region-specific justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The protocol is written entirely in Chinese and prescribes Chinese-centric output conventions without offering a language-selection mechanism. In a general-purpose agent skill, this can cause the model to ignore the user's preferred language, reducing transparency, increasing misunderstanding risk, and potentially causing users or downstream systems to miss critical limitations, caveats, or safety information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill is written only in Chinese and does not indicate any option for the user to choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

SQP-3 covers natural-language policy violations across all file types, including language or locale constraints. The file presents all instructions in Chinese and does not indicate that Chinese is optional, user-selected, or required for a region-specific purpose, which can amount to forcing a language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written in Chinese and presents all guidance exclusively in that language, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language policy issue under the language/locale rule because it effectively imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.