Back to skill

Security audit

A股估值审阅助手

Security checks for vulnerabilities and agentic risk

Overview

This is a focused financial valuation review skill with no code execution or hidden data movement, though users should avoid submitting confidential deal materials unless authorized.

Install only if you intend to use an assistant for valuation-report review. Do not paste or upload confidential, privileged, insider-restricted, or material non-public financial documents unless you are authorized and your organization permits this workflow; redact sensitive details where practical.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is designed to review IPO pricing, M&A, private valuations, and equity incentive reports, all of which commonly contain highly sensitive non-public financial, transaction, and regulatory information. Without an upfront warning about confidentiality, material non-public information, and document handling limits, users may submit restricted materials under the false assumption that this workflow is appropriate for such data.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes broad natural-language phrases such as '帮我看看这个估值' and '估值有没有问题', which are common in ordinary financial discussion and can cause accidental invocation outside the user's intent. In this skill's context, unintended activation is more concerning because users may paste confidential valuation, IPO, M&A, or financing materials, increasing the risk of unnecessary exposure or processing of sensitive non-public information.

Static analysis

No suspicious patterns detected.