Back to skill

Security audit

Akshare Finance

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward AKShare financial data helper that fetches public market data, with dependency and localization caveats but no hidden or destructive behavior found.

Install this in a virtual environment, understand that it queries external financial-data services, and consider pinning akshare and pandas versions if you need reproducible or higher-assurance use. Treat outputs as market-data assistance, not investment advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned and Unverified Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md, lines 8–16
  • SKILL.md, line 31
  • references/README.md, line 6

Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable code snippets:

SKILL.md, lines 8–16:

yaml
"requires": { "pip": ["akshare>=1.12", "pandas>=1.5"] },
"install":
  [
    {
      "id": "pip-install",
      "kind": "pip",
      "packages": ["akshare>=1.12", "pandas>=1.5"],
      "label": "安装AKShare依赖"
    }
  ]

SKILL.md, line 31:

bash
pip install akshare pandas

references/README.md, line 6:

bash
pip install akshare pandas

Technical Analysis

The Skill installs AKShare and pandas using open-ended version constraints or no version constraints. It does not provide a lock file, exact reviewed versions, cryptographic hashes, or an explicitly trusted package index.

The >= constraints allow pip to select any future package release satisfying the minimum version. The documentation commands select the latest compatible releases available when installation occurs. Consequently, the dependency code installed by users can differ from the code that existed when this Skill was audited.

Python packages may execute package-controlled code during installation, import, or normal use. If an upstream package, maintainer account, distribution artifact, or transitive dependency is compromised, malicious code could execute under the identity of the user or Agent installing and running the Skill. Unreviewed future releases could also introduce vulnerabilities or silently alter financial-data processing.

No evidence shows that the currently named packages are malicious. The finding concerns the mutable and unverified dependency installation process.

Attack Path

  1. An attacker compromises an allowed future release of akshare, pandas, or one of their transitive dependencies, or compromises the corresponding package publication channel.
  2. A user or Agent follows t ...[truncated 1308 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an exact, reviewed version rather than using minimum-version constraints:
text
akshare==REVIEWED_VERSION
pandas==REVIEWED_VERSION
  1. Generate and commit a lock file that fixes all transitive dependency versions. Regenerate it only through a controlled dependency-review process.

  2. Record cryptographic hashes for every resolved distribution and enforce them during installation:

bash
python -m pip install --require-hashes -r requirements.txt
  1. Explicitly use the official PyPI HTTPS index or an organization-controlled package mirror. Disable untrusted additional package indexes to reduce dependency-confusion risk.

  2. Prefer installation in an isolated virtual environment or restricted container under a non-privileged account.

  3. Add automated vulnerability, provenance, and unexpected-update checks for direct and transitive dependencies.

  4. Review release notes and package artifacts before updating pinned versions. Test updates in an isolated environment before deployment.

  5. Update both SKILL.md and references/README.md so their installation commands use the same locked, hash-verified requirements file.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s description and surrounding user-facing documentation are presented exclusively in Chinese, which can impose a specific language on users without explicit opt-in. The policy for natural-language violations calls for flagging language or locale constraints unless the skill offers a choice or clearly documents a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings and docstrings are exclusively in Chinese, including the usage/help text and error-related descriptions, with no indication that users may opt into another language. This can violate language/locale policy where a skill must not force a specific language without user choice or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language docstrings and labels are entirely in Chinese, and the script presents output names such as "CPI通胀" and "PMI采购经理指数" without offering any language or locale selection. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's natural-language docstrings and usage-related text are written exclusively in Chinese, with no indication that users may select another language or locale. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code fetches cryptocurrency data from external akshare/Binance-backed interfaces, which implies outbound network access, but the script provides no confirmation prompt, logging, or explanatory warning to the user about making remote requests. The docstrings only describe the function purpose and do not disclose the external data access behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The k-line path invokes an akshare function that retrieves remote market data, but there is no confirmation, logging, or warning indicating that the script will contact an external service. For code files, safety-relevant network transmission should have some form of user disclosure unless already clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This Python file invokes AkShare data-fetching functions, which perform network access to retrieve macroeconomic data, but the script provides no comment, docstring warning, or user-facing message indicating that external requests will be made. For code files, outbound data/network activity can warrant a warning when there is no visible disclosure at all.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code makes an external data request via akshare to retrieve stock K-line data, but there is no user-facing print/log message or explicit disclosure at the call site that a network request will be performed. For a code file, network operations should have some visible warning or explanation unless clearly disclosed elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The call to ak.stock_zh_a_spot_em() retrieves external market data, which implies a network operation, but the script provides no user-facing disclosure such as a log/print statement or explicit warning. Under the code-file criteria, network calls that transmit or retrieve data should have some visible explanation unless already documented elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.