Back to skill

Security audit

股票分析

Security checks for vulnerabilities and agentic risk

Overview

The skill mainly provides stock analysis, but it also requires automatic local file creation and a local HTTP server after every analysis without clear user consent or containment.

Review before installing. The stock-analysis instructions themselves are ordinary, but this skill should not automatically write reports, open a browser, or start a local HTTP server unless you explicitly want that behavior and can constrain where files are written and how the server is shut down.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:145
Finding

Mandatory Local Filesystem Access Without Runtime Authorization

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 145–158
Vulnerability Type: Unnecessary local file access and mandatory file creation
Risk Level: Medium

Complete Code Snippet:

text
## PDF Output (automatically generated after every analysis)

After completing the analysis, the report must be saved as a PDF file in the directory specified by the user:

1. Save location: D:\Downloads\
2. File naming format: {stock name} ({stock code}) YYYY year MM month DD day analysis report.pdf

Example: Shunwang Technology (300113) 2026-03-13 Analysis Report.pdf
3. HTML template: Refer to D:\Downloads\Shunwang_Technology_300113_Analysis_Report.html
4. Generation process:
   - First create an HTML file in the Downloads folder

Technical Analysis

The skill mandates access to a fixed local directory, reads a pre-existing local HTML template, and creates HTML and PDF files automatically after every stock analysis. These operations are not necessary to perform the skill's primary stock-analysis function.

The path is described as user-specified, but it is hardcoded and the workflow contains no requirement to obtain runtime consent, verify directory ownership, validate the generated filename, or prevent overwriting an existing file. Reading an external local template also places local content into the agent-controlled report-generation workflow without establishing that the file is trusted.

Attack Path

  1. A user requests an ordinary stock analysis.
  2. The skill automatically accesses the fixed D:\Downloads\ directory.
  3. It attempts to read the specified local HTML template.
  4. It constructs output filenames from stock-related values and creates HTML and PDF files without requesting confirmation.
  5. If an output filename already exists, the workflow provides no protection against replacement or corruption.

Impact Assessment

The skill can cause unintended reads and writes within the ...[truncated 545 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make PDF export optional rather than mandatory.
  2. Obtain explicit user confirmation before reading or writing local files.
  3. Ask the user to select an output directory at runtime instead of using a fixed path.
  4. Use a trusted template bundled with the skill rather than reading an arbitrary external local template.
  5. Canonicalize and validate the destination path before writing.
  6. Sanitize stock names and codes before incorporating them into filenames.
  7. Reject path separators, traversal sequences, reserved device names, and unsupported characters.
  8. Check whether the destination already exists and require confirmation before overwriting it.
  9. Restrict filesystem access to a dedicated export directory with minimum required permissions.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:156
Finding

Uncontrolled Python HTTP Server Startup During Report Generation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 156–163
Vulnerability Type: Insecure local HTTP server configuration and lifecycle management
Risk Level: Medium

Complete Code Snippet:

text
4. Generation process:
   - First create an HTML file in the Downloads folder
   - Start a Python HTTP server
   - Open the HTML using a browser
   - Invoke the browser PDF function to generate the PDF
   - Save the PDF in the Downloads folder

Note: After every stock analysis, the preceding process must be executed automatically to generate a PDF file.

Technical Analysis

The skill requires starting a Python HTTP server after every analysis but does not specify its bind address, document root, port-selection strategy, access controls, process lifetime, or shutdown procedure.

A Python HTTP server started with unsafe defaults or from the wrong working directory may expose every file below that directory. Binding to all network interfaces could make those files available to other hosts on the same network. The absence of mandatory cleanup can also leave server processes running after report generation, increasing the exposure period and consuming system resources.

The server is unnecessary if the browser or PDF renderer supports direct local-file input.

Attack Path

  1. A user requests a stock analysis.
  2. The skill creates an HTML report in the download directory.
  3. It starts a Python HTTP server without a defined loopback-only binding or dedicated document root.
  4. The server may expose the report and other files under its working directory to local or network clients.
  5. The browser retrieves the report and generates the PDF.
  6. Because shutdown and cleanup are unspecified, the server may continue running and serving files after the task completes.

Impact Assessment

If the server binds to a non-loopback interface, unauthenticated users with network reachability may be able ...[truncated 545 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer direct local-file rendering and eliminate the HTTP server entirely.
  2. If a server is essential, bind it explicitly to 127.0.0.1 or ::1.
  3. Serve only a newly created, dedicated temporary directory containing the single report asset.
  4. Never use the download directory, home directory, or project root as the document root.
  5. Select an ephemeral port and pass the exact generated URL directly to the browser.
  6. Start the server with directory listing disabled and reject requests for unexpected paths.
  7. Use a try/finally or equivalent lifecycle mechanism to terminate the server even if rendering fails.
  8. Wait for process termination, remove temporary content, and verify that no listener remains after completion.
  9. Require explicit user approval before starting any local network service.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Requiring the agent to start a Python HTTP server, open a browser, and invoke browser PDF export is not justified by the stated purpose of stock analysis. These actions execute local tooling and expose additional capabilities that could be abused for command execution, local service exposure, or unintended interaction with the user's environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill description and instructions are written to enforce Chinese output and do not indicate that the user may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as a stock analysis/advice tool, but it also mandates automatic creation of HTML/PDF files in a local Downloads directory after every use. This expands the skill from passive analysis into system-affecting behavior without necessity, increasing the attack surface and creating opportunities for unwanted filesystem modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs automatic writing of files to D:\Downloads\ without explicit user consent at execution time and without a clear warning about filesystem changes. Silent local writes are dangerous because they normalize side effects, may overwrite or clutter user files, and can be repurposed in more harmful variants of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatically launching a local HTTP server and browser constitutes system-affecting behavior that is not preceded by a safety warning or user opt-in. Even if intended for PDF generation, these actions can surprise users, expose local content, and create unnecessary execution pathways on the host system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.