Back to skill

Security audit

Tickflow Realtime

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does the advertised TickFlow market-data lookups, but a command option can send the TickFlow API key to an arbitrary server.

Install only if you trust the publisher and will use the default TickFlow endpoint. Do not run commands that include --base-url unless you fully control the destination and are using a non-production key; consider removing or allowlisting that option before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tickflow_common.py:69
Finding

API Key Disclosure Through an Unrestricted Network Destination

Content
View full analysis
dict: params = { "symbol": args.symbol, "period": args.period, "count": args.count, "start_time": args.start_time, "end_time": args.end_time, "adjust": args.adjust, } payload = request_json( "GET", "/v1/klines", api_key, base_url=args.base_url, params=params, timeout=args.timeout, ) payload = ensure_dict(payload, name="response") payload["data ...[truncated 4315 chars]
Remediation
View remediation
str: parsed = urlparse(value) if parsed.scheme != "https": raise TickFlowError("The API endpoint must use HTTPS.") if parsed.hostname != "api.tickflow.org": raise TickFlowError("Unapproved TickFlow API hostname.") if parsed.username or parsed.password: raise TickFlowError("Embedded URL credentials are not allowed.") if parsed.port not in (None, 443): raise TickFlowError("Unapproved API endpoint port.") return "https://api.tickflow.org" ``` 3. **Separate production and test authentication** If custom endpoints are needed for testing, require an explicit development mode and use a non-production test credential. Production `TICKFLOW_API_KEY` values should never be attached to arbitrary test servers. 4. **Restrict redirect behavior** Reject cross-origin redirects for authenticated requests. Do not forward `x-api-key` when the redirect changes the scheme, hostname, or port. 5. **Enforce TLS** Reject plaintext HTTP even in development unless a clearly isolated test credential is used. Certificate verification should remain enabled. 6. **Rotate potentially exposed credentials** If the scripts have previously been run with untrusted `--base-url` values, revoke and rotate the affected TickFlow API keys and review API usage logs for unauthorized activity. 7. **Add securi ...[truncated 317 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码的核心功能与声明中的“实时行情”部分一致:它解析 symbols/universes,选择 GET 或 POST 调用 /v1/quotes,并格式化输出 last_price、change、volume、session、timestamp 等字段。但声明还明确包含‘日K数据’、‘最近N根K线’、‘复权K线’等能力,而当前代码中没有任何 K 线相关参数、端点、数据结构或渲染逻辑。因此描述显著夸大了该代码块的实际能力,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill requires access to environment variables and outbound network calls, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege enforcement and makes the actual runtime capabilities less transparent to reviewers and policy controls, increasing the risk of unintended secret access or external data exfiltration if the skill is modified or misused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and all user-facing guidance in SKILL.md are exclusively in Chinese. Under the stated policy, forcing a specific language without offering a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This reference file uses Chinese throughout, which can amount to a language-policy violation when a skill implicitly forces a specific language for operators or maintainers. The file does not indicate that Chinese is optional, configurable, or required for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 6)May include surrounding context.

md
本文件只保留实现这个 skill 需要的最小事实,来源是:

- 官网文档页
- `https://api.tickflow.org/openapi.json`

## 认证

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The output contract is written entirely in Chinese and defines the response structure in that language, with no indication that users may choose another language or that the skill is limited to a Chinese-specific context. This creates a natural-language locale policy concern because it appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This code performs outbound network requests and includes an API key in request headers, but the function has no docstring, comment, logging, or other visible user-facing disclosure describing that data will be transmitted to a remote service. For code files, network calls that transmit user or system data should have some form of disclosure unless the warning is provided elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.