Back to skill

Security audit

Stock Query

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed stock-query tool, but its shell-based portfolio and history commands contain unsafe input handling that can enable local code execution.

Review before installing. Use only with trusted prompts and avoid letting untrusted text control stock codes, dates, portfolio names, quantities, or prices until the shell/Python injection paths are fixed. Do not store credentials in portfolio.csv, and expect queried symbols to be sent to external market-data services.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:164
Finding

Command Injection in Documented Portfolio Management Operations

Content
View full analysis
/dev/null; then echo "DUPLICATE:{code}" else echo "{code},{name},{shares},{cost}" >> "$PFILE" && echo "ADDED:{code},{name},{shares},{cost}" fi ``` ```bash OLD=$(grep "^{code}," "$PFILE") if [ -z "$OLD" ]; then echo "NOT_FOUND:{code}" else NEW="{code},{name},{shares},{cost}" tmp=$(mktemp) awk -F',' -v c="{code}" -v n="$NEW" \ 'BEGIN{OFS=","} $1==c{print n;next}{print}' "$PFILE" > "$tmp" && mv "$tmp" "$PFILE" echo "BEFORE:$OLD" echo "AFTER:$NEW" fi ``` ```bash DEL=$(grep "^{code}," "$PFILE") if [ -z "$DEL" ]; then echo "NOT_FOUND:{code}" else tmp=$(mktemp) grep -v "^{code}," "$PFILE" > "$tmp" && mv "$tmp" "$PFILE" echo "DELETED:$DEL" fi ``` ### Technical Analysis The Skill instructs the agent to construct executable Bash source by replacing placeholders such as `{code}`, `{name}`, `{shares}`, and `{cost}` with values obtained from user input or remote market-data responses. There is no requirement to validate or safely encode these values before inserting them into the command text. Values placed inside double-quoted Bash strings are still subject to command substitution, parameter expansion, and backtick expansion when the resulting command is interpreted by Bash. Quote-breaking input can also alter the command structure. For example, if a supplied portfolio field is substituted as `$(id)`, the generated command can contain: ```bash NEW="AAPL,Apple,$(id),220.00" ``` Bash executes `id` while assigning `NEW`. More complex substitutions could read or modify files or execute another local program. Similar risks exist in the `grep` expressions, where unescaped values are interpreted as regular expressions. Although these operations appear in documenta ...[truncated 1465 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sq.sh:644
Finding

Python Code Injection Through Historical Query Date Arguments

Content
View full analysis
&2; exit 1; } beg="${2//-/}"; has_date_range=true; shift 2 ;; --end) [[ -z "${2:-}" ]] && { printf 'sq hist: --end requires YYYY-MM-DD\n' >&2; exit 1; } end="${2//-/}"; has_date_range=true; shift 2 ;; ``` ```bash # YYYYMMDD → Unix timestamp (cross-platform through python3) local p1 p2 p1=$(python3 -c "from datetime import datetime; s='${beg}'; print(int(datetime(int(s[:4]),int(s[4:6]),int(s[6:])).timestamp()))" 2>/dev/null || echo "") p2=$(python3 -c "from datetime import datetime; s='${end}'; print(int(datetime(int(s[:4]),int(s[4:6]),int(s[6:])).timestamp()))" 2>/dev/null || echo "") ``` ### Technical Analysis The `--start` and `--end` options accept any nonempty string. The only transformation removes hyphen characters; the code does not verify that the result contains exactly eight digits. The resulting values are interpolated directly into source code passed to `python3 -c`: ```python s='${beg}' ``` An input containing a single quote can terminate the intended Python string and append arbitrary Python statements. Removing hyphens does not neutralize quotes, semicolons, parentheses, underscores, or other Python syntax. A malicious value conceptually equivalent to the following can escape the assignment: ```text 20240101';__import__('os').system('id');# ``` After interpolation, the Python interpreter receives source equivalent to: ```python from datetime import datetime; s='20240101';__import__('os').system('id');#'; print(...) ``` The injected `os.system` call executes before the remainder of the intended expression. This path is reached for date-range historical queries against US-market symbols. ### Attack Path ...[truncated 1177 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. Validate that the date exists rather than only checking its textual format. 3. Never interpolate input into Python source. Pass it as an argument: ```bash p1=$(python3 -c ' import sys from datetime import datetime print(int(datetime.strptime(sys.argv[1], "%Y-%m-%d").timestamp())) ' "$start") ``` 4. Apply the same treatment to `--end`. 5. Reject inverted ranges and impose a maximum supported interval. 6. Add regression tests using quotes, semicolons, comments, command-substitution syntax, malformed dates, and excessively long arguments. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sq.sh:374
Finding

Fund Market Data Retrieved Over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

大部分声明与代码相符:代码确实支持A股/港股/美股/基金/指数的实时查询、批量查询,以及历史K线查询,并明确未涉及加密货币、期货、期权、外汇。但声明中提到的“自选股管理”“自选盈亏”在此代码块中没有对应实现。唯一相关的是 sq pfile,它只是查找 portfolio.csv 文件位置,不能构成完整的管理或盈亏功能。此外,“含均线”能力在代码中存在但实现方式较弱:均线只在 get --detail 的增强输出中添加,hist 命令输出的 K 线本身没有直接产出 MA 序列。因此总体上属于描述高于实际实现的能力不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 245)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 356)May include surrounding context.

md
| `network` | `scripts/sq.sh` 内部调用行情 API | 仅限 `qt.gtimg.cn`、`hq.sinajs.cn`、`push2.eastmoney.com`、`web.ifzq.gtimg.cn`、`query1.finance.yahoo.com`、`fundgz.1234567.

Lp1

High
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The script performs multiple outbound network requests via curl to third-party market data providers, but the skill metadata provided here does not declare a corresponding network permission. Undeclared network capability is a security issue because users and the hosting agent may not realize the skill transmits query inputs externally, weakening permission-based trust and review controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description and trigger conditions are written entirely in Chinese and define invocation around Chinese user requests, while the document consistently instructs Chinese-form output conventions. There is no stated option for users to choose another language or locale, which can violate a language/locale policy requiring opt-in rather than forced language selection.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
未找到自选股文件。请执行以下步骤创建:

1. 创建配置目录并复制模板:
   mkdir -p ~/.config/stock-query
   cp <skill安装目录>/assets/portfolio.csv ~/.config/stock-query/portfolio.csv

2. 编辑文件,填入你的自选股信息。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The visible natural-language interface and usage text are presented in Chinese, and the file does not indicate that the user can choose another language or that the skill is intentionally restricted to a Chinese-speaking locale. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sq.sh (reported line 396)May include surrounding context.

sh
else
    local resp4b
    resp4b=$(curl -s -m "$TIMEOUT" \
      "https://api.fund.eastmoney.com/f10/lsjz?fundCode=${code}&pageIndex=1&pageSize=1" \
      -H "Referer: https://fund.eastmoney.com")

    local em_nav em_date em_pct

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cmd_pfile command searches for and reveals absolute paths to portfolio.csv in several user home-directory locations, which goes beyond the stated real-time stock quote and history functionality. Even without reading file contents, exposing filesystem layout and the presence of a personal portfolio file leaks local sensitive context that other components or prompts could abuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script inspects several paths under $HOME to determine whether a portfolio file exists. Probing user home-directory contents without clear necessity expands local data access beyond market lookup and creates a privacy risk by disclosing what software or files a user has installed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and prompt are written to operate in Chinese and the trigger model is centered on Chinese-language invocations, but there is no indication that users can choose another language or locale. This can violate language-choice policy when the skill is used in broader contexts outside a clearly documented region-specific deployment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains generic terms such as “大盘”, “港股”, and “美股” that may appear in broader conversations and can cause the skill to activate when the user did not explicitly request this tool. Unintended invocation matters here because the skill has both network and shell permissions, increasing the chance of unnecessary external requests or file-touching behavior compared with a read-only skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s instructions, headers, and safety guidance are written entirely in Chinese, which imposes a specific language on users without offering an alternative or documenting a justified region-specific constraint. Under the policy for natural-language violations, language-specific content without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

When a portfolio file is found, the command prints its absolute path with no warning, masking, or user-facing disclosure. Absolute path disclosure may seem minor, but it leaks usernames, directory structure, and the existence of a potentially sensitive finance-related file, which can aid follow-on attacks or prompt abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.