Back to skill

Security audit

Hithink Astock Selector

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed A-share stock screening connector that sends user queries to 同花顺问财 using an API key, with no hidden persistence or unrelated local access found.

Before installing, confirm you trust the iwencai service and are comfortable providing an IWENCAI_API_KEY for stock queries. Prefer setting the key as an environment variable instead of passing it on the command line, since command-line secrets may be exposed through shell history or process listings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill requires network access and reads a sensitive API key from the environment, but the manifest shown in the documentation does not declare those capabilities explicitly. Undeclared privileges make it harder for a host platform or reviewer to enforce least privilege, and can lead to accidental overtrust or unsafe execution in environments that expect transparent permission disclosure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.