Back to skill

Security audit

joinquant

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its JoinQuant trading purpose, but it deserves review because it teaches authenticated order and liquidation operations without strong safety scoping or secret-handling guidance.

Review this skill before installing if you may use it with real credentials or any environment connected to account state. Keep JoinQuant credentials out of source code and logs, run examples only in backtest or simulation until verified, require explicit approval before any order or liquidation action, and consider using a virtual environment with pinned, reviewed dependency versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unverified Third-Party Python Dependencies

Content
View full analysis
=1.8.0 pandas>=1.5.0 ``` `metadata.json:18-23`: ```json "dependencies": { "python": ">=3.8", "packages": [ "jqdatasdk>=1.8.0", "pandas>=1.5.0" ] } ``` `README.md:16-20`: ```markdown ## 📥 安装 ```bash pip install jqdatasdk ``` ``` `SKILL.md:15-19`: ```markdown ## 安装 (Local Data SDK) ```bash pip install jqdatasdk ``` ``` `demo_project/README.md:7-10`: ```markdown 1. 确保已经安装依赖: ```bash pip install -r ../requirements.txt ``` ``` `demo_project/demo.py:3-4`: ```python try: from jqdatasdk import auth, get_price ``` ### Technical Analysis The project specifies `jqdatasdk` and `pandas` using open-ended minimum-version constraints. It does not provide exact version pins, package hashes, or a lock file. The direct `pip install jqdatasdk` instructions are even less restrictive and allow the package resolver to select the latest compatible release available at installation time. Consequently, installations are not reproducible, and the code ultimately imported by the demonstration can differ from the code reviewed during this audit. If a dependency publisher account, package repository, release process, or transitive dependency is compromised, a later package version could introduce malicious behavior without requiring changes to this project. The package names are consistent with the declared JoinQuant functionality, and the audited repository contains no evidence that either dependency is currently malicious. The vulnerability is the absence of controls that prevent an unreviewed future release from being installed and importe ...[truncated 1828 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The order examples demonstrate buy/sell and target allocation functions without any warning that these APIs may place trades or materially alter portfolio positions in trading-like environments. In a quant trading skill, readers may copy these snippets into live, paper, or connected brokerage contexts, causing unintended orders and financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation shows direct username/password authentication in source code without any warning about secret handling, which can lead users to hardcode real credentials into scripts, notebooks, or repositories. In a developer-facing quick reference, this pattern materially increases the chance of credential leakage through version control, logs, screenshots, or shared research environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The markdown advertises cloud backtesting and simulated live trading, and later provides a strategy example that issues trading orders. The skill description does not warn users that strategies can place simulated orders or affect platform/account state, which is relevant to user data and system integrity expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file instructs users to export JQ_USERNAME and JQ_PASSWORD and pass them into jq.auth(...), which involves sensitive credentials. The description does not include any warning about protecting these secrets, avoiding committing them to source control, or the fact that they authenticate against an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation instructs users to authenticate with a raw username and password in code without any guidance on secure secret handling. This encourages embedding credentials in scripts, notebooks, logs, or agent contexts, increasing the risk of credential leakage, account compromise, and unauthorized access to trading or market-data resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes concrete order-placement and liquidation examples that can be mistaken for safe demo-only code, yet it does not clearly warn that similar APIs may execute real or simulated trades depending on environment. In a financial-trading context, an agent or user could translate these snippets into real transactions, causing unintended asset purchases, sales, or liquidation with direct monetary loss.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest describes a JoinQuant skill for market data, backtesting, research, and simulated trading on the JoinQuant platform. The AI-agent guidance explicitly instructs agents to combine it with '其他数据源或工具', which introduces a broader orchestration capability not justified by the stated single-platform purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The manifest focuses on providing financial data queries, event-driven strategy backtesting, online research, and simulated live trading. The additional instruction to '定期拉取数据并建立监控机制' and '触发预警' adds an alerting/monitoring capability that is adjacent but not explicitly part of the declared purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file uses Chinese throughout the user-facing instructions, which can impose a language preference without user opt-in. The policy allows locale constraints only when they are optional or clearly justified, but no such choice or justification is present here.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency specification for jqdatasdk uses a lower-bound constraint only, which allows future unreviewed versions to be installed. This weakens build reproducibility and can introduce supply-chain risk if a later release contains malicious code, breaking changes, or newly introduced vulnerabilities.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
jqdatasdk>=1.8.0
pandas>=1.5.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The pandas dependency is also unpinned, so installations may resolve to different versions over time. In a data and trading-related skill, this can affect reproducibility and may expose the environment to supply-chain or compatibility issues if an unsafe or incompatible release is fetched.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
jqdatasdk>=1.8.0
pandas>=1.5.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.