Back to skill

Security audit

stock-hot-zh

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the advertised market scan, but an undocumented setting can redirect its credential-bearing API request to another server.

Review this before installing if you use a real AISA key. Keep AISA_BASE_URL unset unless you intentionally trust the alternate endpoint, use a narrowly scoped key with spending limits, and treat any run from an untrusted shell, wrapper, or CI environment as capable of exposing that key.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hot_scanner.py:111
Finding

Authenticated API Requests Can Be Redirected to an Arbitrary Endpoint

Content
View full analysis

Vulnerability Details

File Location: scripts/hot_scanner.py, lines 106–112 and 152–160
Vulnerability Type: Unrestricted authenticated endpoint configuration
Risk Level: Medium

Vulnerable Code

python
def get_client() -> OpenAI:
    api_key = os.environ.get("AISA_API_KEY")
    if not api_key:
        print("❌ Error: AISA_API_KEY environment variable is not set.", file=sys.stderr)
        print("   Set it with: export AISA_API_KEY=your_key_here", file=sys.stderr)
        sys.exit(1)
    base_url = os.environ.get("AISA_BASE_URL", "https://api.aisa.one/v1")
    return OpenAI(api_key=api_key, base_url=base_url)

The resulting client is subsequently used to issue an authenticated request:

python
try:
    response = client.chat.completions.create(
        model=model,
        messages=[
            {"role": "system", "content": SYSTEM_PROMPT},
            {"role": "user", "content": prompt},
        ],
        temperature=0.2,
    )

Technical Analysis

The AISA_BASE_URL environment variable fully controls the destination of the OpenAI-compatible client. The value is not validated against an allowlist, is not restricted to HTTPS, and is not documented as a required configuration option in SKILL.md.

When client.chat.completions.create() is called, the client sends the AISA_API_KEY as authentication material to the configured endpoint. Consequently, an attacker who can influence the process environment can redirect the authenticated request to an attacker-controlled server and capture the credential.

Allowing arbitrary endpoint selection exceeds the minimum privilege required for the declared functionality, which only needs to communicate with the AISA API at https://api.aisa.one/v1. Transmission of the key to that default service is necessary and expected; the vulnerability is the unrestricted ability to change the credential recipient.

Attack Path

  1. An attacker compromises a launcher, wrapper script, shell pr ...[truncated 1486 chars]
Remediation
View remediation

Remediation Suggestions

  1. Use a fixed production endpoint

    python
    return OpenAI(
        api_key=api_key,
        base_url="https://api.aisa.one/v1",
    )
    

    This is the safest option when alternate endpoints are not required.

  2. Apply a strict allowlist if endpoint customization is necessary

    • Parse the URL with urllib.parse.urlparse.
    • Require the https scheme.
    • Require an exact approved hostname, such as api.aisa.one.
    • Reject embedded credentials, unexpected ports, fragments, and malformed URLs.
    • Avoid suffix-only hostname checks that could accept domains such as api.aisa.one.attacker.example.
  3. Make endpoint overrides explicit

    • Prefer a documented command-line or configuration option over an undocumented environment variable.
    • Display the selected non-default endpoint and require explicit user confirmation before sending credentials.
  4. Control redirect behavior

    • Ensure authorization headers are never forwarded when a redirect changes the origin.
    • Reject redirects to hosts outside the allowlist.
  5. Reduce credential exposure

    • Use a narrowly scoped API key with minimal permissions and spending limits.
    • Rotate the key if execution with an untrusted AISA_BASE_URL may already have occurred.
    • Avoid logging authorization headers or including keys in exception output.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill name and all user-facing documentation are presented only in Chinese, indicating a language-specific experience without any stated user opt-in or explanation that the skill is intended exclusively for a Chinese-speaking context. Under the stated policy, forcing a specific language without choice or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description says to use the skill whenever a user wants to know 'what is hottest now,' 'what is moving a lot,' or 'how market momentum is,' which are broad natural-language conditions rather than specific invocation boundaries. Although the file includes a couple of negative cases, it does not clearly constrain trigger scope enough to prevent unintended invocation for general finance questions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest sets the skill language to "zh" with no indication that users can opt into another language or that the skill is restricted to a China-specific or Chinese-only context. This creates a natural-language policy concern because it imposes a locale/language constraint without visible user choice or justification in the file.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 125)May include surrounding context.

python
print("❌ Error: AISA_API_KEY environment variable is not set.", file=sys.stderr)
        print("   Set it with: export AISA_API_KEY=your_key_here", file=sys.stderr)
        sys.exit(1)
    base_url = os.environ.get("AISA_BASE_URL", "https://api.aisa.one/v1")
    return OpenAI(api_key=api_key, base_url=base_url)

Static analysis

No suspicious patterns detected.