Back to skill

Security audit

Wyckoff Analysis AShare

Security checks for vulnerabilities and agentic risk

Overview

The skill appears non-malicious, but it should be reviewed because it gives concrete portfolio trading actions without clear financial-risk safeguards.

Install only if you want a Chinese/Beijing-time A-share analysis workflow that fetches public market data and may generate direct-sounding portfolio actions. Treat any add, reduce, exit, switch, or cash-deployment output as analysis to review with your own risk tolerance and professional advice, not as an instruction to trade.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction requires printing 当前北京时间:YYYY-MM-DD HH:MM(UTC+8) in Chinese, and the fixed output contract later mandates Chinese-language labels for key sections. This imposes a specific language on all users without offering a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation text is broad enough to trigger this skill for a wide range of stock-analysis requests without clear boundaries or explicit user intent. In a skill that performs online data fetching and produces trading recommendations, overbroad activation increases the chance of unintended invocation, unnecessary exposure of portfolio data, and unrequested financial advice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file requires all user time references to be interpreted in Beijing time and requires every answer to present current Beijing time, with no indication that the user can choose another language or locale. This is a natural-language locale policy constraint applied globally rather than as an explicit user opt-in or a clearly justified region-specific tool boundary.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt first mandates loading Chinese fonts only via explicit font file paths and forbids using system/default font families, but later instructs automatic detection/loading of system Chinese fonts such as SimHei/CJK/Heiti. These directives conflict and could cause the skill to behave inconsistently depending on which instruction is followed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to generate add/reduce/exit/rotation recommendations for holdings and cash deployment without requiring any risk disclosure, suitability check, or clear limitation that this is not personalized financial advice. In a trading skill, this materially increases the chance of harmful real-world actions by users, especially because the instructions push automatic portfolio decisions rather than descriptive analysis only.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The core task says to execute a continuous workflow of analysis followed by plotting, and the subsequent steps describe mandatory chart generation. However, the final instruction says to skip plotting during intraday trading time, which directly contradicts the earlier unconditional workflow requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The plotting section specifies 'Chinese annotation constraints,' which is a locale/language restriction embedded in the skill instructions. Because the skill does not offer an alternative language or ask for user preference, this can violate language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The default prompt mandates a fixed analysis workflow and output behavior, limiting user control over how the model responds. In a financial-analysis context, this can cause the system to deliver prescriptive trading recommendations or perform networked data retrieval even when the user's intent, locale, or compliance requirements differ.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs online fetching from third-party financial sources and requires audit logging of user-provided symbols and normalized identifiers, but provides no user-facing notice, consent boundary, or retention limits. This creates a privacy and transparency issue because user inputs and trading-related interests may be transmitted to external services and stored in logs without clear disclosure, which is especially sensitive in a finance-related skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.