Back to skill

Security audit

hk-intraday-trading

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly implements Hong Kong intraday selection and post-trade review, but there are mismatches between its claims and the code/metadata—most notably undeclared environment secrets (TUSHARE token, likely Feishu/webhook and possibly broker creds) and an ambiguous claim of automatic 'execution' without declared broker integrations.

Key things to check before installing/running: 1) Missing declared secrets: inspect trading_cli.py and hk_intraday_trader_optimized.py to confirm whether they connect to a broker or require credentials. The code already references TUSHARE_TOKEN and the SKILL.md describes Feishu pushes — add and verify required env vars (e.g., TUSHARE_TOKEN, FEISHU_WEBHOOK or FEISHU_TOKEN, and any broker API keys) in the skill metadata before trusting it. 2) Confirm execution vs simulation: the README language suggests '自动执行' (automatic execution). If you will run this against real capital, audit any code that places trades (search for broker endpoints, order placement, or HTTP POSTs that include trade parameters). If trading_cli.py or other scripts perform live orders, validate authentication flows and whether they use safe test/sandbox endpoints. 3) Run in a safe environment first: execute scripts in an isolated sandbox or test account, and point data/network calls to mock endpoints if possible. Review what external domains are contacted (eastmoney, qt.gtimg.cn, query1.finance.yahoo.com, api.tushare.pro, Feishu endpoints). Be mindful of rate limits and data accuracy issues raised in the code and reports. 4) Inspect Feishu notification code: confirm no secrets are hard-coded and webhook/token values are read from environment or config only. Avoid pasting production credentials until you confirm where and how they are used. 5) Add missing metadata: request the skill author include required env vars and an explicit note if any script will execute live trades. The absent declarations are the primary coherence/security concern here. 6) If unsure, seek a code review focusing on trading_cli.py and hk_intraday_trader_optimized.py to determine whether any network request could exfiltrate sensitive information or place unintended trades. Only after that, enable the skill with real credentials or live trading.

Static analysis

No suspicious patterns detected.