Back to skill

Security audit

Tushare Finance Jarvis

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Tushare financial-data helper, but users should handle the API token and dependency installation carefully.

Install only if you need Tushare-based market data, keep TUSHARE_TOKEN out of committed files and shell configs when possible, use a virtual environment with reviewed or pinned dependencies, and be aware that the bundled Tushare references cover some datasets beyond core financial markets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Package Updates

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2, SKILL.md:29-32, and README.md:29-32
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

Vulnerable Code

requirements.txt:1-2:

text
tushare>=1.2.60
pandas>=1.5.0

SKILL.md:29-32:

bash
如报错,安装依赖:
```bash
pip install tushare pandas
text

`README.md:29-32`:

```bash
git clone https://github.com/StanleyChanH/Tushare-Finance-Skill-for-Claude-Code.git
cd Tushare-Finance-Skill-for-Claude-Code
pip install -r requirements.txt

Technical Analysis

The dependency declarations provide only minimum versions and no upper bounds, exact pins, or cryptographic hashes. The fallback installation command in SKILL.md is even less constrained because it directly installs the latest available versions of tushare and pandas.

Package installation and import can execute code supplied by a dependency. Consequently, a future compromised, malicious, or unexpectedly incompatible release satisfying these constraints could run code that was not present during this audit. The package names are consistent with the Skill's declared functionality, and the audit found no evidence of typosquatting or an intentionally malicious current dependency. The risk arises from allowing mutable, unreviewed future versions.

Attack Path

  1. An attacker compromises the package publisher account, build infrastructure, or distribution channel for an allowed dependency.
  2. The attacker publishes a malicious version newer than the specified minimum.
  3. A user follows the documented installation instructions.
  4. pip resolves and installs the malicious release because it satisfies the open-ended version constraint.
  5. Malicious installation or runtime code executes with the privileges of the user running pip or invoking the Skill.

Impact Assessment

Successful exploitation could provide arbitrary co ...[truncated 444 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace minimum-only constraints with exact versions that have been reviewed and tested.

  2. Generate a lock file containing all transitive dependencies.

  3. Record and enforce package hashes, such as through:

    bash
    pip install --require-hashes -r requirements.txt
    
  4. Replace pip install tushare pandas in SKILL.md with installation from the reviewed lock file.

  5. Install dependencies in a dedicated virtual environment rather than the system Python environment.

  6. Use a trusted package index explicitly and prevent fallback to untrusted extra indexes.

  7. Add automated dependency vulnerability and integrity scanning to the release process.

  8. Review and deliberately update pinned versions on a controlled schedule.

T09 · Insecure Skill Coding Practices

Note
Location
README.md:41
Finding

API Token Is Persisted in Plaintext Shell Configuration

Content
View full analysis

Vulnerability Details

File Location: README.md:41-45
Vulnerability Type: Plaintext sensitive-data storage
Risk Level: Low

Vulnerable Code

bash
export TUSHARE_TOKEN="your_token_here"

# 或添加到 ~/.bashrc
echo 'export TUSHARE_TOKEN="your_token_here"' >> ~/.bashrc
source ~/.bashrc

Technical Analysis

The documentation recommends an optional configuration method that places the Tushare API token directly into ~/.bashrc. This stores the credential as plaintext in a long-lived shell startup file and exports it into the environment of subsequently launched shell processes.

The token may therefore be exposed through permissive file permissions, shell-configuration backups, support bundles, accidental publication of dotfiles, or another process capable of inspecting the user's environment. This is insecure credential persistence rather than malicious system persistence. The application itself reads only the specifically named TUSHARE_TOKEN variable, and no token exfiltration behavior was found in scripts/api_client.py.

Attack Path

  1. A user replaces the placeholder with a real Tushare token and appends the command to ~/.bashrc.
  2. The plaintext startup file is copied into a backup, published as part of a dotfiles repository, exposed through incorrect permissions, or read following local account compromise.
  3. An attacker extracts the token.
  4. The attacker authenticates to Tushare using the victim's credential and consumes APIs or account quotas available to that token.

Impact Assessment

The primary impact is unauthorized use of the victim's Tushare account, including consumption of API quotas and access to datasets permitted by that account. Exposure may also allow activity to be attributed to the victim's token.

The finding does not directly grant operating-system privileges, and the audited code does not transmit the token to an unrelated service. Broader impact would ...[truncated 72 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not recommend embedding the token directly in a shell startup file.

  2. Prefer an operating-system credential manager, managed secret store, or runtime secret injection mechanism.

  3. If a local secrets file is necessary, keep it separate from version-controlled configuration and restrict access:

    bash
    chmod 600 ~/.config/tushare/credentials
    
  4. Add explicit warnings not to commit, publish, log, or share the token.

  5. Document token revocation and rotation procedures.

  6. Advise users to rotate the token immediately if it has ever appeared in a public repository, backup, diagnostic output, or shared shell configuration.

  7. Keep logs free of credential values; the current client does not log the token and should retain that behavior.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (91)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 46)May include surrounding context.

bash
git clone https://github.com/StanleyChanH/Tushare-Finance-Skill-for-Claude-Code.git
cd Tushare-Finance-Skill-for-Claude-Code
pip install -r requirements.txt

🔑 配置

获取 Tushare Token

  1. 访问 Tushare Pro 注册账号
  2. 在个人中心获取 Token
  3. 配置环境变量:
bash
export TUSHARE_TOKEN="your_token_here"

# 或添加到 ~/.bashrc
echo 'export TUSHARE_TOKEN="your_token_here"' >> ~/.bashrc
source ~/.bashrc

🚀 快速开始

Python API

python
from scripts.api_client import TushareAPI

# 初始化客户端
api = TushareAPI()

# 查询股票日线行情
df = api.get_stock_daily("000001.SZ", "2024-01-01", "2024-12-31")
print(df.head())

# 查询公司基本信息
info = api.get_stock_info("000001.SZ")
print(info)

# 批量查询多只股票
stocks = ["000001.SZ", "000002.SZ", "600000.SH"]
data = api.batch_query(stocks, "2024-01-01", "2024-12-31")

命令行工具

bash
# 查询单只股票
python

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documentation forces a specific language presentation for the user-facing instructions and examples, with no opt-in or alternative language option. Under the policy, a language or locale constraint should not be imposed unless it is clearly documented and justified or the user is given a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to persist the Tushare token in ~/.bashrc and also shows plaintext token placement in configuration, which stores a credential unencrypted on disk. This is not malware, but it increases the chance of credential exposure through shell history, dotfile syncing, backups, screenshots, or accidental publication of config files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire skill document is written only in Chinese, with no indication that users may choose another language or that the locale restriction is required for a region-specific purpose. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents output fields including name, gender, nationality, birthday, and personal resume information for company managers. Under the markdown-specific warning rule, the description omits any warning that the interface returns personal data that may require careful handling for privacy or compliance purposes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented film_record endpoint exposes nationwide film script filing data, which is outside the skill's declared scope of financial market and macroeconomic data. This kind of scope expansion increases attack surface and can cause the agent to retrieve or process unrelated data, undermining least-privilege expectations and potentially enabling policy bypass or misuse of the skill for non-financial information gathering.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This document describes a television production filing data API that is unrelated to the skill’s declared finance, market, and macroeconomic scope. In an agent skill, out-of-scope capabilities increase the chance of unintended tool use, misleading user responses, and policy/safety bypass through capability creep, especially when the agent is expected to operate only on financial data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructional and interface documentation exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

文档前文明确说明本页描述的是可转债技术面因子接口 cb_factor_pro,但示例在“获取交易日期为20250724当天所有可转债的因子数据”处实际调用了 pro.hk_income(...)。hk_income 语义上是港股利润表接口,与可转债技术因子用途明显不一致,属于文档说明与示例代码直接冲突。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented cctv_news interface exposes state-news transcript content that falls outside the skill’s declared scope of financial-market and macroeconomic data. This scope expansion increases the chance the skill will be used to retrieve unrelated political or propaganda-style content, weakening least-privilege expectations and potentially enabling prompt/context abuse in downstream agent workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The text includes prescriptive political/ideological language without user opt-in, which is risky because documentation supplied to agents can act as indirect prompt material. If surfaced to a model or user, it may steer responses, create covert persuasion concerns, or cause the agent to prioritize political framing over the user’s financial request.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This document exposes a movie box office data API inside a skill whose stated purpose is Chinese financial market and macroeconomic data. That scope mismatch can cause the agent to invoke capabilities outside user expectations or governance boundaries, weakening least-privilege assumptions and increasing the chance of inappropriate data access or misuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for Chinese financial market data such as stocks, funds, futures, bonds, financial statements, and macroeconomic indicators. This file documents the bo_monthly interface for monthly movie box-office data, which is entertainment industry data rather than financial market or macroeconomic data, indicating the skill covers behavior beyond its stated description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented capability fetches monthly movie票房 data, with fields like film name, average ticket price, and monthly box office. Given the manifest’s stated purpose is to serve requests for stock prices, financial analysis, index quotes, and GDP/CPI-style macro data, this entertainment-data capability is contextually outside the declared use case.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes the skill as being used to obtain Chinese financial market and macroeconomic data, which implies data retrieval/query capabilities. The export_data method writes arbitrary output files in CSV, JSON, or Excel formats, introducing persistent file-output behavior that is not reflected in the stated description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill documentation advertises batch export and shows file output examples, including writing result files and per-stock CSVs, but gives no user-facing warning about local file creation or handling of exported data. For markdown files, omission of warnings about behaviors that affect user data or system integrity should be flagged when the behavior is material.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language description and tags are entirely in Chinese, with no indication that language is optional or that the skill is intended only for a Chinese-speaking audience. This can violate language/locale policy when a skill effectively forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest requires the TUSHARE_TOKEN environment variable, which is a sensitive credential, but the metadata shown provides no warning or disclosure about credential use, storage expectations, or privacy implications. For manifest/description content, users should be clearly warned when a skill depends on secrets or sensitive environment variables.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document title and descriptive text are entirely in Chinese, and the README does not mention that the skill is China-specific or offer an alternative language/locale option. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON reference file uses Chinese-only natural-language labels throughout, such as dataset names and categories, with no indication that language selection is optional or region-specific. That can violate a language/locale policy when a skill is expected to support user choice or document locale constraints explicitly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

该 Markdown 文档全文以中文编写,未说明是否支持其他语言,也未提供用户选择语言的机制。根据规则,若技能或文档强制特定语言且没有用户 opt-in,可能构成自然语言层面的组织策略违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown document is entirely written in Chinese and does not indicate that the language choice is optional, user-selectable, or justified as a region-specific requirement. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file is entirely written in Chinese and does not provide any language-selection or opt-in mechanism. Under the policy rule for natural-language violations, forcing a specific language without user choice can be considered a locale policy issue when no justification is stated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file presents the skill documentation entirely in Chinese and does not indicate that other languages are supported or that the language choice is intentional and opt-in. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.