Back to skill

Security audit

AKShare股票分析

Security checks for vulnerabilities and agentic risk

Overview

The skill is a stock-analysis helper, but it under-discloses external data sharing for portfolio diagnosis and its documentation does not fully match the shipped CLI behavior.

Install only if you are comfortable with a market-data skill making external requests, including sending stock codes from your portfolio to third-party finance endpoints. Avoid entering sensitive portfolio details unless needed, use an isolated virtual environment, and prefer pinned dependency versions before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–20
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

bash
pip install akshare --upgrade
pip install pandas numpy

Technical Analysis

The installation instructions fetch and install akshare, pandas, and numpy without pinning reviewed versions or validating package hashes. The --upgrade option explicitly directs pip to select a newer available release from the configured package index.

Consequently, installation is not reproducible: the code installed later may differ from the code available when this Skill was audited. If a package, transitive dependency, configured package index, or package publisher account is compromised, following these instructions could introduce attacker-controlled code. Python packages can execute code during build or installation, and imported packages execute module initialization code at runtime.

This finding concerns unsafe dependency acquisition rather than evidence that the currently named packages are malicious.

Attack Path

  1. An attacker compromises a named package, one of its transitive dependencies, a publisher account, or a package index trusted by the user's pip configuration.
  2. The attacker publishes a malicious release that satisfies pip's unconstrained version resolution.
  3. A user follows the documented installation instructions.
  4. The --upgrade or unversioned installation command downloads the attacker-controlled package.
  5. Malicious code executes during package installation, package build, or subsequent import by scripts/akshare_cli.py.

Impact Assessment

Malicious dependency code would generally execute with the same operating-system privileges as the user running pip or the CLI. Depending on those privileges, it could read or alter accessible files, steal environment variables or credentials, make arbitrary network request ...[truncated 322 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace unconstrained installation commands with a reviewed requirements or lock file containing exact versions for direct and transitive dependencies.
  2. Record and enforce cryptographic hashes using pip's --require-hashes option.
  3. Remove --upgrade from routine installation instructions; review dependency upgrades separately before updating the lock file.
  4. Install from an explicitly approved HTTPS package index and prevent fallback to untrusted extra indexes.
  5. Run dependency vulnerability and provenance checks in CI before releasing updates.
  6. Install packages in an isolated virtual environment under a non-administrative account.
  7. A hardened installation pattern is:
bash
python -m venv .venv
.venv/bin/python -m pip install --require-hashes -r requirements.lock

The lock file should contain reviewed, exact versions and hashes for every resolved package.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The documented behavior materially differs from the described implementation, including unstated direct requests to third-party finance endpoints and overstated support for funds/futures and sector rotation analysis. Security reviewers and users may make trust decisions based on inaccurate descriptions, leading to unexpected network disclosure or reliance on analyses the skill does not actually perform.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises network-backed market data retrieval but does not declare any explicit tool scope or allowed-tools boundary in the manifest. This weakens least-privilege controls and makes it harder for a host agent or reviewer to understand and constrain the external access the skill requires.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Very broad trigger phrases like general stock or finance discussion can cause unintended invocation of a network-enabled skill during ordinary conversation. This increases the chance of surprise external requests and accidental processing of sensitive investment context without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The holdings-diagnosis workflow asks users for portfolio positions but does not warn that codes and related context will be sent over the network to external market-data providers. Even if only ticker symbols are transmitted, portfolio composition can be sensitive financial information and should be disclosed before use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes direct AKShare-based real-time data access for A-shares, funds, and futures, but this file only contains logic for stock/index quotes, stock historical data, sector proxies, and stock holding diagnosis. There are no fund- or futures-specific retrieval paths, parsers, or commands, so the implemented behavior falls materially short of the advertised cross-asset scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The holdings-diagnosis flow sends user-supplied portfolio identifiers to an external market-data endpoint without explicit warning, consent, or minimization. In a financial-analysis skill, portfolio composition is sensitive data; even if only stock codes are transmitted, this can leak investment interests and user financial context to a third party.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI help text labels the subcommand as 'K线数据', which implies raw candlestick/K-line market data. However, the implementation dispatches kline to calculate_tech_indicators, which computes and returns derived indicators such as MA, MACD, and RSI rather than a dedicated K-line dataset. This is an active documentation-to-code mismatch in the command interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The manifest description, usage examples, outputs, and operational guidance are all presented only in Chinese, and the file does not indicate that the user can choose another language or that the skill is intentionally restricted to a Chinese-speaking audience for a documented reason. This can amount to a language/locale policy issue when a skill effectively forces one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The module-level natural-language description is presented only in Chinese, which imposes a specific language/locale on users without any opt-in or alternative. This matches the policy category for language or locale constraints that are not explicitly offered as a choice or justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest frames the skill as using AKShare CLI to obtain market data without API keys, suggesting AKShare as the primary access mechanism. In contrast, quote retrieval, market summary, and holding diagnosis are implemented via direct requests.get calls to Tencent endpoints rather than through AKShare. While network access is expected for this skill, the implementation does not match the advertised data-access mechanism.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.