Back to skill

Security audit

china-stock-analysis

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only stock analysis skill whose web lookups and recommendation format match its stated purpose, with some scope and language limitations users should understand.

Install only if you want an assistant to search the web for stock prices and produce general stock-analysis commentary. Treat its buy/hold/sell output as informational, not professional financial advice, and ask for your preferred language or market scope when needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation description is broad enough that the skill may trigger on generic stock-related requests and provide buy/sell recommendations without tight market or task boundaries. In an agent system, over-broad routing can cause inappropriate invocation, increasing the chance of misleading financial guidance, wrong-market analysis, or unintended web lookups in contexts the user did not specifically request.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description limits the skill to Chinese stock analysis, specifically A-shares and Hong Kong stocks. However, the supported markets table includes US tickers such as AAPL, TSLA, and NVDA, which expands the skill beyond its declared scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill prescribes a Chinese-language output template without offering user choice, which can cause the agent to ignore the user's language preference or system-level UX expectations. While not a classic exploit, this is a prompt-quality and control-boundary issue that can degrade reliability, miscommunicate financial information, and lead to user misunderstanding in a high-stakes investment context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill analyzes Chinese stock prices, specifically A-shares and HK stocks, but this reference file also includes a dedicated 'US Stocks' section with US tech giants and Chinese ADRs. That broadens the operational scope beyond the stated China-focused market coverage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file is largely written in Chinese but includes English section headers and search instructions such as "Hong Kong Stocks," "US Stocks," and "stock price." Under the natural-language policy rule, forcing a specific language or mixed locale presentation without user opt-in can be a policy issue when no language choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.