Back to skill

Security audit

earnings-deep-analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language financial-report analysis workflow with a local HTML quality-check helper, and I found no hidden execution, persistence, credential access, or exfiltration behavior.

Install only if you want a Chinese-language earnings-analysis workflow. Review generated HTML and JSON before sharing, because the skill may combine user-provided financial documents with web-searched public data and the result could affect investment discussions. Do not treat its investment implications as buy/sell advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

描述将该技能定位为“财报深度解读助手”,核心职责是分析上市公司财报并产出完整 HTML 解读报告,甚至衔接 PPT。给出的代码却只是一个 reports HTML 的 lint/验收脚本:读取指定 HTML 文件并按预设规则输出 FAIL/WARN/PASS 结果。其主要目的属于质量控制/格式校验,而非财报分析或报告生成。虽然检查项与财报报告结构相关,属于同一业务域,但这只是对最终产物的合规性把关,不等同于描述中的核心能力。因此这是明显的描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向最终用户的财报分析与报告生成技能,核心能力应是理解财报内容、形成分析结论并产出解读报告。相比之下,提供的代码仅是一个测试脚本,用来验证另一个 lint 工具对 HTML 报告结构和格式规则的检查是否正确。测试样例中虽然包含财报分析章节名称,但这些只是静态测试数据,不代表代码具备财报分析、推理、生成结论或制作 PPT 的能力。因此,代码的主要目的与声明的主要用途明显不一致,属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill file is written in Chinese and presents its analysis instructions exclusively in that language, with no indication that users may choose another language or that the skill is intended only for a Chinese-language context. Under the policy, a language or locale constraint must be optional or clearly justified to avoid excluding users by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all instructions, rule descriptions, and reporting formats exclusively in Chinese. The policy flags language or locale constraints when a skill forces a specific language without user opt-in, and this file does not offer an alternative language or explain a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file title and HTML template require Chinese output, including lang="zh-CN" and Chinese-only report structure, which imposes a specific language/locale by default. The instructions do not offer an opt-in choice or explain a region-specific compliance need that would justify the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language docstrings and console messages that assume Chinese as the only interaction language. The policy allows locale constraints only when they are optional or clearly justified, which is not indicated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All usage, error, warning, and pass/fail messages printed to the user are Chinese-only. Because there is no opt-in, fallback, or documentation that this is a China-only/internal skill, this is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/tests/test_earnings_lint.py (reported line 199)May include surrounding context.

python
"""文件不存在 → 退出码 3"""
        import subprocess
        script_path = os.path.join(os.path.dirname(__file__), "..", "earnings_lint.py")
        result = subprocess.run(
            [sys.executable, script_path, "/nonexistent/path/report.html"],
            capture_output=True, text=True,
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/tests/test_earnings_lint.py (reported line 209)May include surrounding context.

python
"""无参数 → 退出码 3"""
        import subprocess
        script_path = os.path.join(os.path.dirname(__file__), "..", "earnings_lint.py")
        result = subprocess.run(
            [sys.executable, script_path],
            capture_output=True, text=True,
        )

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 11)May include surrounding context.

text
all copies or substantial portions of the Software.

2. The Software is provided "AS IS", without warranty of any kind, express or
   implied, including but not limited to the warranties of merchantability,
   fitness for a particular purpose, and non-infringement. In no event shall
   the authors or copyright holders be liable for any claim, damages, or
   other liability arising from, out of, or in connection with the Software

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 21)May include surrounding context.

text
all copies or substantial portions of the Software.

2. The Software is provided "AS IS", without warranty of any kind, express or
   implied, including but not limited to the warranties of merchantability,
   fitness for a particular purpose, and non-infringement. In no event shall
   the authors or copyright holders be liable for any claim, damages, or
   other liability arising from, out of, or in connection with the Software

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file states that files in the directory may be published via publish_artifact, which affects data handling and external distribution. The description does not include any warning or disclosure about reviewing contents for sensitive or unintended information before publication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a code file, so SQP-3 applies to natural-language content in docstrings, comments, and string literals. The file consistently uses Chinese for user-facing and developer-facing text, but there is no indication that the skill is intentionally region-specific or that users may opt into another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.