Back to skill

Security audit

股票数据API

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed market-data connector that uses a stock API key to query data.diemeng.chat, with no hidden persistence, destructive behavior, or unrelated data access found.

Install this only if you trust data.diemeng.chat with your API key and the market-data queries you make. Use a scoped API key if available, avoid hardcoding it in files, and consider allowing outbound traffic only to the documented API domain.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (34)

Tainted flow: 'request_headers' from os.getenv (line 63, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · stock_api.py (reported line 72)May include surrounding context.

python
try:
        if method.upper() == "GET":
            response = requests.get(url, headers=request_headers, params=params, timeout=30)
        elif method.upper() == "POST":
            response = requests.post(url, headers=request_headers, json=json_data, timeout=30)
        else:

Tainted flow: 'request_headers' from os.getenv (line 63, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · stock_api.py (reported line 74)May include surrounding context.

python
if method.upper() == "GET":
            response = requests.get(url, headers=request_headers, params=params, timeout=30)
        elif method.upper() == "POST":
            response = requests.post(url, headers=request_headers, json=json_data, timeout=30)
        else:
            raise ValueError(f"不支持的 HTTP 方法: {method}")

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述覆盖了代码的一部分核心功能:它确实调用 data.diemeng.chat,并提供股票日线、分钟线、财务指标等数据,且支持 A 股。然而代码实现的范围明显更广,不仅是“股票数据”查询,还包含多种未在描述中体现的证券品类和高级能力,如可转债、ETF、指数、港股、互联互通、条件搜索、复权因子、停牌与快照历史等。这属于能力范围的实质性扩展,描述未准确代表代码的完整实际行为,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all operational instructions exclusively in Chinese, including the title, steps, and safety checklist. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requires both environment access and outbound network access to use STOCK_API_KEY and call https://data.diemeng.chat, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens sandboxing and review because the runtime capabilities are broader than the manifest communicates, increasing the risk of unintended secret access or network use if the skill is modified or misinterpreted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description and the entire skill guidance are written in Chinese and instruct the agent in that locale, but the file does not state that the skill is region-specific or that users may choose another language. Under the policy rule, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s natural-language docstrings, console messages, and usage instructions are entirely in Chinese, and there is no indication that the user can choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest uses Chinese-only natural-language descriptions throughout, including the top-level description and configuration guidance, with no indication that the skill is region- or language-specific by design or that users may choose another language. That creates a locale/language policy concern because the skill effectively imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The skill requires users to obtain and configure a third-party API key for data.diemeng.chat, which means the skill is designed to send authenticated requests to an external service. In skill contexts, this creates a real external data-transfer and trust-boundary risk because user queries and access credentials may be disclosed to a non-local provider, even if that is the intended functionality.

Content

Scanner excerpt · skill.json (reported line 756)May include surrounding context.

json
"configuration": {
    "api_key": {
      "type": "string",
      "description": "在 https://data.diemeng.chat/ 注册登录后,在个人中心获取 API Key,并填在此处后保存。",
      "required": true,
      "env": "STOCK_API_KEY"
    },

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The default base_url is an external HTTPS endpoint, so all tool operations are intended to transmit user-supplied stock queries and authentication material to a remote service. While this is inherent to an API skill, it is still a genuine security concern because it expands the attack surface to a third-party system and can expose query contents, usage patterns, and API credentials if governance is weak.

Content

Scanner excerpt · skill.json (reported line 763)May include surrounding context.

json
"base_url": {
      "type": "string",
      "description": "API 基础地址",
      "default": "https://data.diemeng.chat/api"
    }
  }
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

All natural-language documentation in the file is written only in Chinese, including setup instructions and API descriptions, with no indication that users may choose another language. Under the stated policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the restriction is explicitly justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

md
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 276)May include surrounding context.

md
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 289)May include surrounding context.

md
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 316)May include surrounding context.

md
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 317)May include surrounding context.

md
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 333)May include surrounding context.

md
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · clawhub.json (reported line 5)May include surrounding context.

json
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · clawhub.json (reported line 12)May include surrounding context.

json
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · clawhub.json (reported line 15)May include surrounding context.

json
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · example.py (reported line 152)May include surrounding context.

python
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · example.py (reported line 161)May include surrounding context.

python
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 4)May include surrounding context.

json
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.json (reported line 7)May include surrounding context.

json
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · stock_api.py (reported line 13)May include surrounding context.

python
- 股票估值数据

使用前请确保:
1. 已在 https://data.diemeng.chat/ 注册账号
2. 已获取 API Key
3. 设置环境变量 STOCK_API_KEY 或在代码中配置
"""

Static analysis

No suspicious patterns detected.