Back to skill

Security audit

Czsc Thinking

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it gives actionable stock-trading guidance while also asking users to pass an API token on the command line and install unpinned packages.

Review before installing. Use this only as educational market-analysis support, not as authoritative investment advice. If running the scripts, avoid putting a real Tushare token directly on the command line, use an isolated environment, pin and verify dependencies yourself, and check outputs independently before making any trading decision.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_market_data.py:106
Finding

Tushare API token exposed through command-line arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/README.md:209
Finding

Unpinned and unverifiable third-party dependency installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明的核心能力是“分析与教学”,尤其是基于缠论进行交易机会研判;而代码的核心功能仅是获取和导出市场数据,属于数据采集工具。它没有实现任何分析逻辑、信号识别、策略制定、风险控制推理或教学内容生成。虽然市场数据获取可作为分析的前置支持步骤,但这里代码的主要目的与声明的主要用途存在明显偏离。此外,代码还包含对外部 Tushare API 的访问以及可选 CSV 文件输出,这些都未在描述中体现为主要能力。因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description is broad enough to trigger on many generic finance-related requests, which can cause the agent to apply domain-specific trading guidance in contexts where the user did not explicitly ask for speculative market analysis. In a finance setting, overbroad routing increases the chance of unsolicited or inappropriate decision support that may influence real financial actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions encourage concrete trading actions such as entry/exit levels, position sizing, stop-losses, and target prices without a user-facing warning about financial risk or limitations. This is dangerous because users may treat the output as authoritative investment advice and act on it, potentially causing financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This document gives concrete trading guidance, market-timing concepts, and buy/sell decision heuristics without any warning that the content is educational only and may cause financial loss if followed blindly. In the context of an agent skill meant to guide stock analysis and strategy formulation, omission of risk disclaimers can lead users to treat the material as actionable financial advice, increasing the chance of harmful decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest frames the skill as a reasoning aid for analyzing trading opportunities and strategy using 缠论 thinking. This file instead initializes a remote Tushare client, fetches external stock data, and later supports saving results to disk, which is a materially different operational behavior from pure analytical guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script emits concrete action-oriented financial guidance such as buy, sell, or hold suggestions without an explicit disclaimer, confidence bounds, or warning that outputs are informational only. In a trading-analysis skill, this increases the risk that users will treat heuristic output as authoritative advice and make financially harmful decisions, especially because the tool presents the result as structured analysis rather than speculation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill name, tagline, description, and tags are entirely presented in Chinese and describe the skill in a way that implies a fixed Chinese-language interaction model. The file does not indicate that users may choose another language or that the locale restriction is optional, which can conflict with language/locale choice policies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructions, examples, and outputs exclusively in Chinese, and nowhere indicates that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire file is presented only in Chinese, with no indication that users may select another language or that the Chinese-only format is required by a documented regional constraint. SQP-3 applies to natural-language policy violations where a specific language is imposed without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring, usage instructions, and help text are written in Chinese, which imposes a specific language on users. The policy allows locale constraints only when clearly justified or when the user is offered a choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The argparse description and argument help messages are user-facing natural language and are only provided in Chinese. This is a language policy issue because the script does not document a justified locale restriction or offer an alternative language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

Fetching all stock basic information is a data-discovery utility rather than an obvious requirement of a skill whose declared purpose is to teach or apply a specific analytical mindset for buy/sell points, market judgment, strategy, and risk control. This broadens the capability from analysis assistance into general market data catalog access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language text in the module docstring, CLI argument descriptions, and runtime output is consistently Chinese-only. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The help text and status message imply that the user can choose an analysis period via --freq, but convert_to_raw_bars hardcodes freq=Freq.D and CZSC is created from those daily bars only. This is an intent/documentation mismatch in the file's own interface because the documented option does not affect behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.