Back to skill

Security audit

港股 AI 概念板块专属投研顾问。结合宏观流动性、南向资金博弈与 AI 产业基本面,提供深度的个股挖掘与风控策略。

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed Hong Kong AI-sector finance assistant, but it asks for raw API credentials, including an OpenAI key, without explaining why it needs that access.

Review before installing. Use a dedicated, low-privilege market-data key if needed, and avoid granting OPENAI_API_KEY unless the publisher documents a specific required use. Treat outputs as research support only, not investment advice.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:8
Finding

Overprivileged Access to Sensitive API Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 8
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Complete Code Snippet:

yaml
environment_variables: ["MARKET_DATA_API_KEY", "OPENAI_API_KEY"]

Technical Analysis

The skill requests direct access to two sensitive environment variables. Its documented function is market analysis, but it provides no implementation demonstrating a legitimate need to access the raw OPENAI_API_KEY. Direct credential exposure violates least-privilege and secret-isolation principles.

The current skill text does not instruct the agent to read, disclose, or transmit these credentials. Therefore, this is an excessive-permission risk rather than evidence of active credential theft. Nevertheless, direct secret availability increases the consequences of future prompt injection, unauthorized modification, or compromise of the skill.

Attack Path

  1. The host grants the environment-variable permissions declared by the skill.
  2. The skill gains access to the raw market-data and OpenAI API credentials.
  3. An attacker injects instructions through untrusted market content or modifies the skill after deployment.
  4. The compromised instructions access one or both environment variables.
  5. The credentials are disclosed through generated output or transmitted through an allowed network channel.
  6. The attacker uses the exposed credentials subject to their account-level scopes and provider controls.

This path is conditional: the reviewed file contains no instruction that performs these actions.

Impact Assessment

Successful exploitation could expose the API privileges associated with MARKET_DATA_API_KEY and OPENAI_API_KEY. Depending on provider-side scopes, quotas, and account configuration, this could enable unauthorized API consumption, financial charges, quota exhaustion, access to provider resources available to the k ...[truncated 332 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove OPENAI_API_KEY from the declared environment variables unless a documented, indispensable use case exists.
  2. Do not expose raw credentials to the skill context. Route requests through a narrowly scoped host-side broker or dedicated market-data tool.
  3. If market-data authentication is required, issue a dedicated credential with read-only access, restricted endpoints, low quotas, and no administrative privileges.
  4. Enforce destination allowlists at the network layer rather than relying only on prompt instructions.
  5. Prevent environment-variable values from appearing in model context, logs, error messages, tool results, or generated output.
  6. Add automatic secret redaction, usage monitoring, spending limits, short expiration periods, and regular credential rotation.
  7. Document the specific purpose and minimum scope of every requested permission and reject execution when unnecessary permissions are declared.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is narrowly themed around Hong Kong AI-sector equity research, but the activation phrasing described by the finding is still broad enough to catch generic requests like market review, stock analysis, or macro judgment without strong sector or geography gating. This can cause unintended invocation, leading the agent to answer outside the user's intended scope and potentially provide overconfident finance content under a specialized persona.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.