Back to skill

Security audit

MS Research Report

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently generates local DOCX equity research reports, with ordinary file-output risks but no evidence of hidden execution, exfiltration, persistence, or privilege misuse.

Install only if you want a local Python-based DOCX report generator. Confirm the output path before running because it can create or overwrite DOCX files, avoid embedding private local images unless intended, and review branding/disclaimer text before sharing reports externally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation description is very broad and can cause the skill to trigger for many finance-related requests without clear boundaries or confirmation steps. Over-broad activation increases the chance of unintended file generation, processing sensitive investment data, or misuse in contexts where the user did not explicitly request document creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The API and CLI documentation state that the skill writes a .docx file to a caller-specified path, but the skill description does not warn users that it performs filesystem writes. Hidden or implicit write behavior can surprise users, overwrite existing files, or create sensitive reports on disk in shared or monitored environments.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This .py file contains user-facing natural-language documentation that defaults to Chinese for the module description and usage context. Under the policy rule for language/locale choice, forcing a specific language without opt-in can be a policy concern, especially because the API surface advertises a configurable language parameter.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The main make_report docstring frames file output responsibility narrowly around the final .docx path, but the implementation also creates temporary chart image files via tempfile.mkstemp during chart rendering and analysis sections. This is not just omitted detail in one helper; the public entrypoint documentation gives a materially incomplete impression of write behavior while the code performs additional filesystem writes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The argument parser sets --language to zh by default, which imposes a specific language choice unless the user explicitly overrides it. Under the policy, forcing a language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.