Back to skill

Security audit

金融分析技能

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a local financial backtesting skill, not malware, but its investment outputs and install instructions need caution.

Install dependencies in a dedicated virtual environment, prefer pinned requirements, and run the skill only on CSV files and output folders you choose. Treat the reports as educational backtests, not personalized investment advice, because the implementation appears to be inverse-volatility weighting rather than a full equal-risk-contribution optimizer and it may overwrite fixed output filenames.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README’s instructional content is predominantly in Chinese, including usage guidance, data format requirements, and cautions. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation because users are not offered an alternative locale or language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest presents the skill name, description, features, and changelog entirely in Chinese, indicating a fixed language choice. Under the policy, a skill should not force a specific language or locale without offering user choice or clearly documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing descriptions, help text, and console output entirely in Chinese, starting with the module docstring and continuing throughout the CLI interface. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and user-facing behavior are presented in Chinese, and the rest of the file continues that pattern for prompts, reports, and console output. This effectively forces a specific language/locale on users without any explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that rebalancing occurs monthly, but the implementation computes evolving inverse-volatility weights and applies the previous day's weights on every trading day. This creates a mismatch between documented behavior and actual portfolio logic, which can mislead users about turnover, transaction costs, and backtest validity in a financial decision-making context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The report claims each asset contributes equally to portfolio risk, but the code only uses inverse-volatility weighting, which does not generally produce equal risk contributions when correlations are non-zero. In an investment-analysis skill, this can materially misrepresent the strategy's risk properties and cause users to rely on incorrect portfolio characterization.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide states that each asset contributes equally to portfolio risk, which is the defining property of risk parity. However, the later formula and code snippets describe weights computed as normalized inverse volatility (L127, L266-L268), which generally produces inverse-vol portfolios rather than true equal-risk-contribution portfolios. This is an intent/documentation contradiction about the strategy being implemented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document gives concrete investment suggestions, performance claims, and strategy guidance without any visible disclaimer that the content is informational only, may be inaccurate, and should not be treated as personalized financial advice. In a financial-analysis skill, this omission can cause users to over-trust backtest outputs and recommendations, increasing the risk of harmful real-world financial decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill title and most instructions are in Chinese, and the sample output is also Chinese-language, which effectively imposes a locale by default. The file does not indicate user opt-in for Chinese nor explain that the skill is limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly integrates third-party market data providers and mentions API-key usage, but it does not disclose that user-supplied symbols, portfolio contents, and related request metadata may be transmitted to external services. In a financial-analysis context, this can expose sensitive investment interests or internal research activity to outside providers, even if the data sent is limited.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The core features and FAQ claim automatic outlier identification/handling, but the explicit processing steps only mention reading CSVs, converting percentages, and deleting rows with NaN values (L115-L120). No outlier-detection method, parameter, or code snippet is documented, so the documentation appears to overstate behavior and may mislead users about what the skill actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guide encourages generation of reports, JSON, and charts that may embed local filesystem paths, data ranges, asset identifiers, and potentially sensitive financial results, but it does not warn users about disclosure risk. In a financial-analysis context, these artifacts can be shared, synced, or committed inadvertently, exposing proprietary market data locations or confidential analytical outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file documents that the skill writes multiple output artifacts, including text, JSON, and PNG files, but does not include any user-facing warning about creating or overwriting files in the output directory. For markdown files, omissions of warnings about behaviors affecting user data or system state should be flagged when such behaviors are described.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.