Back to skill

Security audit

A Stock Market Review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward A-share market recap tool that fetches public Eastmoney data and prints a report, with some install and transport-security cautions.

Install in an isolated Python environment, avoid using the report as investment advice, and prefer a version that switches Eastmoney calls to HTTPS and pins dependencies. The skill does not appear to access private files, credentials, or persistent system settings.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/a_stock_market_review.py:21
Finding

Market data retrieved over unencrypted HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/a_stock_market_review.py, line 21
Vulnerability Type: Unencrypted external API communication
Risk Level: Medium

Vulnerable Code:

python
BASE_URL = "http://push2.eastmoney.com/api/qt"

Technical Analysis

All market-data requests are constructed from a plaintext HTTP base URL. HTTP provides neither server authentication nor transport integrity. An attacker with a network interception position can observe requests, impersonate the API endpoint, modify JSON responses, or redirect traffic.

The application parses the received JSON without cryptographic verification and incorporates its values directly into the generated financial report. While no remote response is executed as code and no credentials are transmitted, forged prices, percentage changes, sector rankings, or stock selections could be presented as legitimate market information.

Attack Path

  1. A user runs the market-review script on a network controlled or observed by an attacker.
  2. The script sends requests to http://push2.eastmoney.com/api/qt/....
  3. The attacker intercepts the plaintext HTTP connection through a malicious access point, compromised router, proxy, or equivalent man-in-the-middle position.
  4. The attacker returns syntactically valid but manipulated Eastmoney JSON data.
  5. The _get method accepts and parses the response.
  6. The modified figures are inserted into the report and displayed to the user as market data.

Impact Assessment

This issue does not grant the attacker local code execution, filesystem access, elevated privileges, or persistence. Its scope is limited primarily to the confidentiality and integrity of API traffic and the resulting report. However, manipulated financial information could mislead users and influence investment-related analysis or decisions.

Remediation
View remediation

Remediation Suggestions

  • Replace the base URL with the HTTPS endpoint:

    python
    BASE_URL = "https://push2.eastmoney.com/api/qt"
    
  • Keep TLS certificate verification enabled; do not use verify=False.

  • Restrict redirects or verify that the final response host remains an approved Eastmoney domain.

  • Validate the response content type, expected schema, and reasonable numeric ranges before using returned values.

  • Fail closed when transport validation or response validation fails rather than presenting untrusted values as valid market data.

T08 · Insecure Dependencies

Note
Location
README.md:10
Finding

Third-party dependency installed without version or integrity constraints

Content
View full analysis

Vulnerability Details

File Location: README.md, line 10; also present in SKILL.md, line 108
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Low

Vulnerable Installation Instruction:

bash
pip install requests

Technical Analysis

The documented installation command resolves requests and its transitive dependencies without fixed versions or package hashes. Consequently, installations performed at different times may retrieve different code, making the environment non-reproducible and preventing users from verifying that installed artifacts match versions reviewed by the project maintainers.

The package name is legitimate and no dependency confusion or typosquatting is directly present in the project. Exploitation therefore depends on a future compromise of the package distribution channel, a malicious dependency release, unsafe package-index configuration, or an incompatible release being selected.

Attack Path

  1. A user follows the documented pip install requests instruction.
  2. pip resolves the current package version and transitive dependencies from its configured package index.
  3. If the index, selected package release, or a transitive dependency has been compromised, malicious or altered package content is downloaded.
  4. Package installation behavior or imported runtime code executes in the user's Python environment.
  5. The malicious dependency operates with the permissions of the user running pip or the market-review script.

Impact Assessment

The vulnerable project code itself does not obtain additional privileges. In a successful supply-chain compromise, dependency code could obtain the same privileges as the installing or executing user, including access to that user's files, environment variables, network connectivity, and Python environment. System-wide impact would be possible if installation or execution were performed with administra ...[truncated 93 chars]

Remediation
View remediation

Remediation Suggestions

  • Add a reviewed dependency manifest or lock file with an explicitly tested requests version and pinned transitive dependencies.

  • Include cryptographic hashes and install with hash verification, for example:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  • Use an isolated virtual environment rather than installing packages globally.

  • Avoid running package installation as an administrator or root user.

  • Use a trusted package index configured over HTTPS.

  • Periodically review and update pinned dependencies to incorporate security fixes.

  • Apply the corrected installation instructions consistently in both README.md and SKILL.md.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description, examples, and user-facing output are entirely in Chinese, including the title, instructions, and generated report format. Under the policy rule, a skill that effectively mandates a specific language should either provide user opt-in/choice or clearly justify the locale restriction; this README does neither.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents and relies on outbound network access to Eastmoney APIs, but it does not declare any explicit tool scope such as allowed-tools or permissions. That creates a least-privilege gap: an agent/runtime may grant broader network capability than intended, making it harder to audit or restrict what external hosts the skill can contact. In this context the skill appears data-retrieval only, so the issue is configuration weakness rather than overtly malicious behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file-level docstring and all generated report content are written exclusively in Chinese, indicating the skill is designed to operate in a single language. The policy explicitly flags language or locale constraints when they are imposed without user opt-in or a documented, justified regional limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.