Back to skill

Security audit

股票雷达

Security checks for vulnerabilities and agentic risk

Overview

This is a financial stock-screening skill with mostly disclosed scripts, but it automatically uses unverified market data and expands into futures and other local skill workflows, so it deserves careful review before installation.

Install only if you are comfortable with a Chinese A-share trading workflow that makes many external market-data calls, may invoke other local trading skills, and stores alerts/journals/review files locally. Treat outputs as analysis only, verify any recommendation against trusted sources, and avoid relying on the plaintext lhb-api data for trading decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lhb.py:27
Finding

Unauthenticated HTTP Market Data Can Influence Stock Recommendations

Content
View full analysis

Vulnerability Details

File Location: scripts/lhb.py:27, 103-107; automatic invocation at scripts/radar_run.sh:112-117
Vulnerability Type: Unauthenticated external data source / data-integrity failure
Risk Level: Medium

Vulnerable Code

python
API = "http://fffy520.gicp.net:8003/api"
python
def cmd_api(a):
    date, note = auto_date(a.date)
    if note:
        print(note)
    try:
        rows = http_json("{}/lhb/daily?date={}".format(API, date)).get("data") or []
    except Exception as e:
        print("lhb-api 失败:{}".format(str(e)[:80])); return 1

The default orchestration automatically invokes this source:

bash
run x_lhb.log   python3 skills/trading-desk/scripts/lhb.py api
nonempty x_lhb.log && mark "↳ 龙虎榜/席位" "✅ 跑了" \
  "lhb-api 席位明细 见 x_lhb.log" || \
  mark "↳ 龙虎榜/席位" "🟡 无数据" "盘后17:30后才更新"

Technical Analysis

The lhb.py api command retrieves financial leaderboard and brokerage-seat information over plaintext HTTP. HTTP provides neither server authentication nor transport integrity, so an on-path attacker can modify or replace the JSON response.

The response is parsed directly and treated as valid market evidence. The orchestration considers the step successful when its output file is nonempty and does not authenticate the source, verify a signature, or corroborate each result against an authenticated independent source.

This path is reachable through the documented one-click workflow because radar_run.sh automatically invokes lhb.py api during its base analysis stage.

Attack Path

  1. A user or agent launches the documented radar_run.sh workflow.
  2. The script invokes lhb.py api.
  3. lhb.py sends a plaintext HTTP request to fffy520.gicp.net:8003.
  4. An attacker controlling an intervening network segment, proxy, DNS path, or gateway intercepts the request.
  5. The attacker returns syntactically valid JSON containing fab ...[truncated 893 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the plaintext endpoint with an HTTPS endpoint using normal certificate and hostname validation.
  2. If the provider does not support HTTPS, remove it from automatic execution and fail closed rather than treating its output as trustworthy.
  3. Corroborate every material record against an independent authenticated source before incorporating it into recommendations.
  4. Add schema and semantic validation, including expected date, stock-code format, numeric ranges, and duplicate detection. These checks supplement but do not replace transport authentication.
  5. Change orchestration success criteria so that a merely nonempty log is insufficient; require authenticated retrieval and successful validation.
  6. Clearly label unverifiable data as unavailable and prevent it from affecting candidate ranking or recommendation rationale.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a broad short-term A-share stock selection system with many distinct analytical and trading-support capabilities. The supplied code does only one narrow task: request historical money-flow data from Sina for given stock codes and summarize recent main-force net flow trends. While money-flow analysis is one component mentioned in the description, the actual code neither performs the overall stock-selection process nor implements most advertised functions. This is a material description-behavior mismatch in primary purpose and scope, though there is no obvious undeclared harmful capability beyond simple network access to Sina finance data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a broad end-to-end short-term A-share stock selection and trading-assistance system. In contrast, the supplied code is only a temporary helper script for checking volume expansion relative to a recent average for user-provided tickers. It accesses Sina quote/K-line endpoints and computes a simple volume ratio plus basic price stats. That can be a supporting component of a stock-picking workflow, but by itself it does not implement the claimed primary purpose or most of the listed capabilities. Therefore the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code only supports a relatively narrow stock screening workflow based on live market data fields: price change, turnover, main-force net inflow, and trading amount, with simple ranking outputs. That partially overlaps with the declared stock-picking theme, but the declared description promises a much broader decision system with market-environment judgment, sector rotation/leadership, auction analysis, event/risk checks, trading-plan outputs (stop-loss, position sizing, sell points), reminders, and journaling/statistics. None of those higher-level or auxiliary capabilities are implemented in the supplied code. Therefore the description materially overstates the actual behavior and should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a broad short-term A-share stock selection assistant with live/near-live decision support and risk management outputs. The supplied code chunk only implements one narrow analytical component: retrospective testing of four hard-coded chart patterns using historical daily OHLCV data. While this is loosely related to short-term trading pattern analysis, the primary purpose is materially different: measuring past pattern performance rather than selecting what to buy today/tomorrow and generating actionable trading plans. The code also relies only on public daily K-line endpoints from Sina/Tencent, not the richer data sources implied by the description (sentiment, sector flows,龙虎榜, auction data, announcements, reminders, etc.). Therefore the description substantially overstates and misrepresents what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose centers on short-term A-share stock picking and market analysis features such as sentiment judgment, sector leadership,资金流/龙虎榜/竞价 analysis, risk checks, position sizing, and producing candidate stocks with buy/sell guidance. The actual code does none of that. Instead, it processes a local broker CSV export, extracts buy/sell fills, performs FIFO matching to calculate realized profit/loss, prints performance breakdowns, and persists results into a journal file for later review. This is related only in the broad trading domain, but its primary purpose is post-trade import/accounting and review statistics, not pre-trade stock selection or radar scanning. No hidden prompt-injection-relevant instructions alter that conclusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a comprehensive A-share short-term stock selection assistant covering market emotion, sectors, leaders, capital flow, bidding, risk management, and trading plan output. The actual code does none of that. It fetches data from Eastmoney's RPT_FUTU_DAILYPOSITION endpoint for a futures contract, filters by trade date, aggregates top-20 long and short positions, and prints a simple bullish/bearish verdict based on net positioning. This is a materially different primary purpose and data domain (futures positioning leaderboard vs. A-share stock radar). There are no implemented capabilities related to stock screening, market sentiment cycle analysis, sector rotation, stop-loss/position calculations, alerts, logs, or review statistics. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a comprehensive A-share short-term stock-picking assistant focused on stock screening, market emotion analysis, sector leadership, capital flow interpretation, and trading-plan output. The supplied code does none of that. It simply maps futures names/codes, fetches real-time futures quotes from Sina or Eastmoney, parses the responses, and prints quote fields. This is a materially different primary purpose and asset class: futures rather than A-share stock selection. There is no implementation of stock radar logic, no screening criteria, no sentiment or sector analysis, no 龙虎榜/公告/竞价 handling, and no stop-loss or position-calculation engine. Therefore the description does not accurately represent the code behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a comprehensive short-term stock selection system with many market-wide, sector-level, flow-based, risk-management, and workflow features. The supplied code chunk implements only a small technical-analysis component: for user-supplied stock codes, it retrieves recent 30-minute bars and computes MA20-relative structure plus simple volume/price divergence. This is not merely an incomplete excerpt of the full advertised behavior in any visible sense; its primary purpose is much narrower and lacks most of the declared capabilities. Therefore the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared description promises a comprehensive A-share short-term trading assistant with multi-factor analysis and decision support. The actual code only downloads and displays recent daily K-line data with moving averages and a coarse bullish/bearish/sideways classification. Its primary purpose is data retrieval and simple trend display, not stock selection or trading workflow automation. Additionally, it supports indices and futures, which materially broadens behavior beyond the declared A-share short-line stock radar.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad end-to-end short-term stock selection and trading assistant for A-shares, including market environment judgment, sector/theme filtering, technical/fund-flow evaluation, candidate generation with stop-loss and position sizing, and follow-up workflow features such as reminders and review. The supplied code does something much narrower: it is a standalone CLI script that queries and prints 龙虎榜-related datasets (daily list, stock-specific records, seat history, and capital-type classifications) from Eastmoney, a third-party lhb-api server, and Niuguwang. While 龙虎榜/席位/资金性质 are mentioned in the description as part of the larger skill, the code chunk itself only implements that data-fetching slice and none of the broader stock-picking, risk-management, alerting, or review capabilities. This is a material description-behavior mismatch in primary scope and implemented capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a comprehensive short-term A-share stock-selection assistant covering market-wide analysis, sector rotation, leader selection, risk controls, reminders, and post-trade review. The supplied code does not perform stock selection at all; it only analyzes capital-flow data for a user-supplied single ticker and prints simple textual interpretations. While money flow is one component mentioned in the description, the actual code's primary purpose is much narrower and materially different from the advertised end-to-end stock radar workflow. Resource access is also limited to Eastmoney and Sina quote endpoints for flow/quote retrieval, not the broader data sources implied by 龙虎榜, announcements, or market sentiment tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a broad short-term A-share stock radar system with many analytical and monitoring capabilities across selection, sentiment, funds flow, event risk, execution timing, and post-trade review. The actual code chunk does not perform any of those core functions. It only automates position sizing based on capital, entry, stop, maximum risk percent, and maximum position percent, plus optional profit calculations for target prices. While position sizing is mentioned in the declared description as one component, the code’s primary and sole behavior is much narrower than the declared skill purpose. Therefore, the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a comprehensive short-term A-share stock-selection and trading-assistant skill. By contrast, this code only retrieves and prints real-time资金流/大单 data from public endpoints. While real-time capital flow is one component mentioned in the description, the code chunk does not implement the stated end-to-end radar behavior or most of the promised capabilities. Its primary purpose is specifically real-time money-flow inspection, which is materially narrower than the declared stock-picking, risk-control, and review workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向A股短线交易决策的“股票雷达”系统,核心能力应是盘前/盘中分析并筛选标的、给出交易计划和风险控制建议。实际代码仅实现了复盘闭环中的统计分析部分:基于历史成交记录计算分形态胜率和期望值,生成Markdown复盘报告,并支持从券商CSV导入历史成交记录。虽然声明中提到“交易日志与复盘统计”,这与代码有部分重合,但该代码块的主要用途明显不是选股雷达,而是事后复盘分析,且缺失声明中的大部分关键能力。因此属于明显的描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a comprehensive short-term A-share stock selection assistant with extensive decision-making, risk control, alerting, and review capabilities. The supplied code only retrieves and displays sector and board constituent market/flow data from Eastmoney via HTTP. While sector capital flow is one supporting component of the declared system, this code chunk does not implement the main promised behaviors such as selecting stocks, scoring sentiment, generating buy/sell plans, calculating positions, setting stop-losses, monitoring auctions, checking announcements, or maintaining logs/statistics. Therefore the actual behavior is materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code implements only one sub-function hinted at in the description: sector capital 'relay' analysis based on today's, 5-day, and 10-day net inflows for industries/concepts. The declared description presents a much broader end-user capability centered on short-term stock selection and trading decision support, including stock candidate outputs and risk-management/tracking functions. Because the actual code chunk is materially narrower and does not perform the primary promised behaviors, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description promises a full short-term stock-picking and market-analysis assistant for A-shares, including selecting candidates, evaluating sentiment cycles, identifying leading sectors/stocks, analyzing funds flow and auction data, generating stop-loss-based candidate lists, and providing reminders/review workflows. The actual code chunk only implements a local trading journal CLI: add stores an entry record, close records exit and computes P&L, list displays records, and stats reports overall counts and win rate. While trade logs and review statistics are mentioned in the declared description as part of a broader system, this specific code chunk’s actual purpose is much narrower and materially different from the declared primary capability. Therefore this chunk does not accurately represent the described skill behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises and invokes local scripts that imply shell, file, environment, and network capabilities, but it does not declare any explicit tool scope or permissions boundaries. In an agent ecosystem, this increases the risk of over-privileged execution, unintended file access, or uncontrolled outbound requests if the runtime grants defaults broader than necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad, common terms such as '选股', '买点', '卖点', and '复盘', which can cause the skill to activate in contexts broader than intended. In combination with shell/network-capable workflows, overbroad invocation can lead to unintended script execution, unnecessary data fetching, or user confusion about why a high-impact financial skill was engaged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all instructional content are written exclusively in Chinese, which functions as a language constraint for users consuming the skill guidance. The policy requires flagging language or locale restrictions unless the file offers an opt-in choice or clearly documents a justified regional constraint, which this document does not.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill manifest describes an A-share short-term stock radar, but the playbook includes substantial futures trading guidance and intraday futures tactics. This scope expansion can cause the agent to provide advice for leveraged instruments the user did not request, increasing financial risk and weakening safety boundaries, especially because futures require different suitability, risk, and compliance controls than cash equities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document is framed entirely as a Chinese SOP with a fixed named workflow, and it does not indicate that users may choose another language or locale. Because this file is natural-language guidance applicable to all invocations of the skill, it effectively imposes a language preference without explicit user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language description and usage text are entirely in Chinese, including the title, purpose, flags, and output expectations, with no indication that another language is supported or that the locale is intentional and limited. Under the stated policy, forcing a specific language without user opt-in is a locale-policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a stock-selection/radar skill focused on market sentiment, sector leadership, candidate screening, risk sizing, alerts, and review. This file instead performs offline broker statement ingestion and bookkeeping by transforming historical execution records into trading/journal/trades.json, which is a portfolio record-management capability rather than stock radar or candidate generation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This script implements futures-position leaderboard retrieval, which is outside the declared A-share stock radar scope. Scope drift is a security and governance problem because users and higher-level agents may grant trust, permissions, or make decisions based on the manifest, while the skill actually processes a broader asset class than advertised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.