Back to skill

Security audit

Stock Macro Market Analysis

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed market-analysis skill with financial-advice and language-scope caveats, but no evidence of hidden execution, persistence, exfiltration, or account-changing behavior.

Install only if you want Chinese-language stock and macro market commentary and can provide a stock-data API key. Treat any scores, sector rankings, and buy/sell/position suggestions as general information, not personalized investment advice. Also note that several referenced helper scripts and the report template are missing from the package, so parts of the workflow may not run as written.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad, generic market-analysis requests that overlap with ordinary financial conversation, so the skill may activate when the user did not explicitly intend to invoke it. In a finance context, unintended invocation is meaningful because it can cause the agent to produce analysis that users may rely on as investment guidance without clear consent or proper framing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Although the skill requires a disclaimer, it does not clearly warn that the output is not personalized investment advice and may be acted on by users as such. Because the skill generates weighted scores, market states, and action recommendations, the presentation materially increases the chance that users interpret it as actionable financial advice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module title and description are written entirely in Chinese, and all user-facing recommendation strings throughout the skill are also hard-coded in Chinese. This creates a language/locale constraint without any visible opt-in or documented justification, which matches the policy category for forced language use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

整份技能说明、触发短语和输出要求均默认使用中文语境,且面向“A股/美股/港股”分析时没有说明是否允许按用户偏好切换语言。对于覆盖多市场的技能,若默认强制单一语言而无选择机制,可能不符合语言/locale 选择政策。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.