Back to skill

Security audit

Stock Filter Skills

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis skill is mostly coherent, but it needs review because it sends an API key to a configurable server and can mutate or delete remote presets without strong URL and identifier validation.

Install only if you trust the configured API server and can use a narrowly scoped, revocable API key. Prefer HTTPS for any remote API endpoint, avoid using this with untrusted prompts or pasted identifiers, and confirm any hot-factor create/update/sort/delete action before letting the agent run it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/config.js:8
Finding

API key may be transmitted to an untrusted or plaintext endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools.js:30
Finding

Unencoded path identifiers allow authenticated API route manipulation

Content
View full analysis
apiRequest(`/stocks/${code}`) .then(data => ({ code, ...(data.data || data) })) .catch(e => ({ code, error: e.message })) ) ); ``` `src/tools.js:47-51`: ```js export async function stock_compare({ codes, fields }) { const stocks = await Promise.all( codes.map(code => apiRequest(`/stocks/${code}`) .then(data => ({ code, ...(data.data || data) })) .catch(e => ({ code, error: e.message })) ``` `src/tools.js:73-89`: ```js export async function hot_factor_update({ preset_id, name, factors }) { const body = {}; if (name != null) body.name = name; if (factors != null) body.factors = factors; const data = await apiRequest(`/hot-factors/${preset_id}`, { method: "PUT", body }); return formatJson(data.data || data); } export async function hot_factor_delete({ preset_id }) { const data = await apiRequest(`/hot-factors/${preset_id}`, { method: "DELETE" }); return formatJson(data.data || data); } export async function hot_factor_use({ preset_id }) { const data = await apiRequest(`/hot-factors/${preset_id}/use`, { method: "POST" }); return formatJson(data.data || data); } ``` `src/tools.js:124-127`: ```js export async function douyin_hotspot_detail({ aweme_id }) { const data = await apiRequest(`/douyin/hotspots/${aweme_id}`); return formatJson(data.data || data); } ``` ### Technical Analysis The `code`, `preset_id`, and `awem ...[truncated 3074 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (35)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

export STOCK_API_TIMEOUT="30"

text

### 方式二:.env 文件

```bash
cp .env.example .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 39)May include surrounding context.

export STOCK_API_TIMEOUT="30"

text

### 方式二:.env 文件

```bash
cp .env.example .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

方式二:.env 文件

bash
cp .env.example .env
# 编辑 .env 填写实际配置

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

md
node src/main.js <tool_name> '<JSON 参数>'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/config.js (reported line 6)May include surrounding context.

js
import { fileURLToPath } from "url";

const __dirname = dirname(fileURLToPath(import.meta.url));
loadDotenv({ path: resolve(__dirname, "..", ".env") });

export const API_BASE_URL = (process.env.STOCK_API_BASE_URL || "").replace(/\/+$/, "");
export const API_KEY = process.env.STOCK_API_KEY || "";

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that mentioning broad trigger phrases like “股票筛选”, “热门因子”, “股票分析”, or “抖音热点” will cause the agent to automatically invoke tools. Overly broad natural-language triggers can cause unintended tool execution from casual conversation, quoted text, or adversarial prompt content, increasing the risk of data access or outbound API calls without clear user intent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly requires environment variables and invokes a Node CLI that will make outbound API requests, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens containment and reviewability: an agent may invoke a network-capable skill with access to secrets without a clearly documented or enforced boundary, increasing the chance of unintended data access or transmission.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.