Back to skill

Security audit

Alpha Pulse

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed A-share trading signal scaffold with ordinary dependency and financial-use risks, but I found no hidden, destructive, persistent, or purpose-mismatched behavior.

Install dependencies in an isolated virtual environment, consider pinning package versions, review any generated files before overwriting existing workspace files, and avoid entering optional market-data tokens unless you understand where they will be stored and used. Treat any stock predictions as informational, not financial advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:42
Vulnerability Type: Unpinned and unverifiable third-party dependencies
Risk Level: Medium

Vulnerable Code Snippet:

text
1. Install dependencies: `pip install akshare pandas numpy xgboost`

Technical Analysis

The documented installation command retrieves mutable versions of four third-party packages and their transitive dependencies from the package index configured for pip. The project supplies no lockfile, exact version constraints, package hashes, or trusted-index requirement.

Consequently, the code installed by this command can change after the skill has been audited. Package installation may execute build-system or installation logic, while later imports execute package initialization code. A compromised package release, dependency-confusion package, malicious index mirror, or unexpectedly changed transitive dependency could therefore introduce attacker-controlled code into the environment.

The command itself does not prove that any currently published package is malicious. The vulnerability is the absence of dependency integrity and reproducibility controls around an installation step explicitly presented to users.

Attack Path

  1. A user follows the setup instructions in SKILL.md.
  2. pip resolves the latest compatible releases from the user's configured package index and resolves their unpinned transitive dependencies.
  3. An attacker compromises an upstream release or package-index account, influences an untrusted mirror, or introduces a higher-priority dependency-confusion package.
  4. pip downloads and installs the substituted package without checking it against project-maintained hashes.
  5. Malicious code executes during package build or installation, or when the scanner subsequently imports the affected package.
  6. The payload runs with the privileges of the user performing the installation or launching the skill.

...[truncated 627 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the free-form installation command with a reviewed dependency manifest containing exact versions.

  2. Generate and commit cryptographic hashes for every direct and transitive dependency.

  3. Require hash verification during installation, for example:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Use a lockfile generation workflow such as pip-tools, and regenerate it only through a controlled dependency-review process.

  5. Explicitly document and enforce the trusted package index rather than relying on potentially modified local pip configuration.

  6. Run automated vulnerability and provenance checks when dependencies are added or updated.

  7. Install dependencies in an isolated virtual environment without administrator privileges.

  8. Review updates before changing pinned versions, then rerun security and functional tests.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill description, commands, prompts, and user response instructions are presented only in Chinese, including the required continuation responses. There is no indication that the user may choose another language or that the locale restriction is intentional and justified, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly states it will immediately create config.yaml and lib/scanner.py without first requiring clear user confirmation or warning that it will modify the workspace. In an agent setting, unsolicited file creation can lead to unintended repository changes, overwrite existing files, or normalize unsafe auto-write behavior that users did not authorize.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and operational messages are written entirely in Chinese, and the skill provides no indication that users may choose another language or that the locale restriction is intentional and justified. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.