Back to skill

Security audit

G2量化交易策略

Security checks for vulnerabilities and agentic risk

Overview

This is a China A-share stock-analysis skill with purpose-aligned market-data access and local analysis code, but users should treat its trading claims and database-writing helper cautiously.

Install only in an isolated, nonprivileged Python environment. Do not connect this to real trading or rely on the backtest claims without independent validation. Review the hard-coded database path and the table-dropping save helper before letting it write to any database you care about.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
stock_analysis_v5.py:343
Finding

Caller-Controlled SQL Identifier Enables Destructive Database Operations

Content
View full analysis
``` A caller that can invoke `save_to_db` and control `table_name` can select another valid table in the same SQLite database for deletion. Python's SQLite driver generally rejects multiple statements passed to a single `execute` call, which limits common stacked-query payloads, but does not prevent abuse of the intended `DROP TABLE` operation with an attacker-selected table name. The hard-coded database path under `/root/.openclaw/workspace-financemaster/` also creates a cross-workspace integrity concern. If the process has access to that path and the database is shared with other functionality, the operation may affect state beyond this package. ### Attack Path 1. An integration, wrapper, or other local calle ...[truncated 1235 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:102
Finding

Unpinned and Unbounded Third-Party Dependency Installation

Content
View full analysis
=3.8", "numpy": ">=1.20.0", "requests": ">=2.25.0" } ``` ### Technical Analysis The documented `pip install numpy requests` command resolves the latest versions available from the user's configured package index at installation time. No lock file, exact version, upper bound, package hash, or trusted index requirement is supplied. The named packages are conventional packages, and the reviewed project does not specify a suspicious repository or demonstrate that either dependency is currently malicious. The weakness is that installation is mutable and non-reproducible. A compromised package-index account, compromised index mirror, maliciously configured index, or incompatible future release could cause users to receive code that was not covered by this audit. Python packages may execute build-system or installation-related code, and imported dependencies run with the privileges of the invoking process. The exposure is amplified if users install or execute the package as a privileged account. The included Python script imports `requests` but does not import `numpy`, so the documented NumPy installation unnecessarily expands the dependency and supply-chain surface. ### Attack Path 1. A user follows the README and runs `pip install numpy requests`. 2. Pip queries the user's configured package index or mirror. 3. Because no exact versions or hashes are required, pip accepts whichever compatible distributions are s ...[truncated 1171 chars]
Remediation
View remediation
\ --hash=sha256: ``` 2. Install with hash enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Define reasonable upper bounds where exact locking is not used, and regularly test and review dependency updates. 4. Document a trusted Python package index explicitly and warn users not to install from untrusted mirrors. 5. Run installation and execution inside a dedicated virtual environment or container under a nonprivileged account. 6. Remove `numpy` from the installation instructions and metadata unless functionality that actually imports it is added. 7. Add automated dependency vulnerability and integrity checks to the release process, while manually reviewing lock-file changes before publishing. ]]>
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest presents the skill title, description, and keywords entirely in Chinese, indicating a fixed language/locale for user-facing metadata. There is no indication that users can choose another language or that the restriction is justified as a region-specific tool, which matches the policy-violation criterion for forced language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON manifest is written almost entirely in Chinese, including the top-level description, operational instructions, agent roles, and prompt keywords. Because the file provides no opt-in, locale selection, or documented region-specific justification, it presents a natural-language locale constraint that could conflict with organizational language-choice policy.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The configuration states in multiple places that stop-loss and take-profit decisions should use closing prices rather than intraday touches, including '收盘价判断' and the detailed note that intraday highs should not trigger exits. However, the highest-priority stop-loss rule says '亏损>=2% → 立即卖出', and monitoring logic says '触及-2%立即卖出', which contradicts the documented close-price-only principle for exit decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document title and the entire skill description are written exclusively in Chinese, with no indication that other languages are supported or that Chinese is a required locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and user-facing descriptions are entirely in Chinese, and the script's runtime messages are also presented only in Chinese. For a general-purpose skill, this imposes a specific language/locale without any visible opt-in or documented justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The scoring docstring states the v5.1 weighting as '位置(15%)', but the actual scoring block later labels position as '20%' and adds up to 20 points. This is an active contradiction between the documented scoring intent and the implemented logic, which could mislead users about how recommendations are derived.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function documentation explicitly enumerates six market warning factors and says it performs a '6大预警检查', yet the code only evaluates two conditions: high-volume decline and decline beyond 3%. This is more than incomplete documentation because it affirmatively claims broader protective logic than the function actually provides.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow and principles repeatedly describe concrete trading actions such as '尾盘买入确认' and an execution window for buying, implying live trade execution behavior. But the execution section explicitly sets 'simulation_only' to true, meaning the system is configured not to actually execute trades, which conflicts with the operational language elsewhere in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.