Finbot A股数据工具

Security checks across malware telemetry and agentic risk

Overview

This stock-data skill appears coherent and purpose-aligned, with disclosed public market-data fetching and local report generation but some capability overclaiming.

Before installing, treat this as a public market-data helper rather than investment advice. Expect it to contact Sina Finance and to create local Markdown reports or optional CSV snapshots; also note that the advertised multi-factor selection feature appears incomplete.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill documentation declares no permissions, yet the described functionality and static analysis indicate network access and local file writes. This creates a transparency and consent problem: users or hosting platforms may grant execution assuming a lower-risk capability set than the skill actually uses.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose does not fully match the observed behavior: the skill reportedly fetches historical data and writes CSV/Markdown outputs locally, while also claiming multi-factor stock selection that is not actually implemented. This mismatch is dangerous because users may run the skill under false assumptions about data handling and capabilities, which can lead to unauthorized persistence of data or misplaced trust in outputs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal