Back to skill

Security audit

Dataquant Connector 量化数据通道

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent DataQuant API connector, with the main caution that its docs encourage API-key handling methods that can leak the key into chat or shell history.

Install only if you trust DataQuant and need this data connector. Prefer setting DATAQUANT_API_KEY through a protected environment variable or secret store; avoid pasting real API keys into chat or passing them with --api-key. Review any generated backtest code before allowing an agent to run it, and consider using a virtual environment with pinned dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:85
Finding

API keys may be exposed through chat history, shell history, and process arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:19
Finding

Third-party dependency installation is not version-pinned or integrity-verified

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tainted flow: 'key' from os.environ.get (line 27, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/dataquant.py (reported line 37)May include surrounding context.

python
def _request(endpoint, params=None, api_key=None):
    key = api_key or get_api_key()
    url = f"{BASE_URL}{endpoint}"
    resp = requests.get(url, params=params, headers={"X-API-Key": key}, timeout=30)
    resp.raise_for_status()
    return resp.json()

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
| `SKILL.md` | ✅ |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that the AI will automatically read the skill definition, create directory structures, write files, and later handle script generation and execution, but it provides no trust boundary warning, review step, or consent checkpoint. This can normalize letting an agent write and run code from remotely supplied content, which increases the risk of unsafe file modifications, execution of unreviewed code, or supply-chain abuse if the skill source is tampered with. Because this skill is specifically framed as an automated backtesting pipeline, the context makes the missing warnings more dangerous, not less.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly instructs users to paste their DataQuant API key directly into an AI assistant. That encourages disclosure of a reusable secret into a conversational system that may log, retain, or further expose credentials across tools, transcripts, or downstream integrations. In this skill context, the risk is elevated because the assistant is also positioned to automate data retrieval and execution workflows, increasing the chance the key is propagated beyond the user's intent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents capabilities that require environment access and outbound network access, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates a governance gap: an agent platform may over-grant or ambiguously grant access, increasing the chance of unintended secret access or network egress beyond what users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples repeatedly pass the API key directly on the command line via --api-key KEY, which can expose credentials through shell history, process listings, logs, transcripts, or agent telemetry. In a skill specifically designed for API-backed data retrieval, this context makes the issue more dangerous because users are likely to copy-paste the examples verbatim with real secrets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and surrounding documentation are written entirely in Chinese, which signals a fixed language choice in the skill's natural-language materials. There is no indication that users may select another language or that the Chinese-only requirement is justified by a region-specific compliance need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing help strings in Chinese for the --adj and --date options while the rest of the CLI description and help text is in English. That imposes a locale/language choice on users without opt-in or documentation that the tool is intended for Chinese-speaking users only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.