Back to skill

Security audit

QMT

Security checks for vulnerabilities and agentic risk

Overview

This QMT trading skill matches its stated purpose, but it needs Review because its examples can place real trades and move bank funds while handling passwords and account data without clear safeguards.

Install only if you intentionally want an AI-assisted reference for a live QMT/miniQMT trading environment. Treat all order, bank transfer, and algorithmic order snippets as capable of affecting real money; test in simulation first, require explicit human confirmation before live trades or transfers, never hardcode bank or fund passwords, redact logs, and pin/review dependencies before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Allow Unreviewed Package Updates

Content
View full analysis
=1.0.0 numpy>=1.20.0 ``` `README.md:21`: ```bash pip install xtquant ``` `demo_project/README.md:9`: ```bash pip install -r ../requirements.txt ``` ### Technical Analysis The project permits any current or future version of `xtquant` and `numpy` above the stated minimum versions. The direct installation command for `xtquant` has no version constraint at all. No lock file, package hashes, trusted package index, or integrity-verification procedure is provided. Consequently, dependency resolution can install package releases that were not reviewed when this project was audited. Python packages can execute code during installation in some distribution workflows and can always execute package-level code when imported. The demonstration imports `xtquant` at `demo_project/demo.py:6`, making a compromised installed release reachable during normal use. This finding does not establish that the named packages are currently malicious. It identifies a supply-chain weakness through which a compromised future release, package-index compromise, or unsafe index configuration could introduce executable code into the trading environment. ### Attack Path 1. An attacker compromises a permitted dependency release or the package source used by the victim. 2. The attacker publishes a version satisfying `xtquant>=1.0.0` or `numpy>=1.20.0`. 3. A user follows the documented `pip install` instructions without a reviewed lock file or hash verification. 4. The package manager resolves and installs the attacker-controlled release. 5. Malicious code executes during installation or when the package is imported. 6. The code runs with ...[truncated 875 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation includes credential-bearing bank transfer operations with example account numbers and password parameters, but no privacy or operational safety warning. In a financial trading context, this is high risk because developers may embed real credentials in source code, logs, notebooks, or shared scripts, enabling credential leakage and unauthorized fund transfers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation includes direct buy/sell order examples for a real trading terminal without any visible warning that these APIs may affect a live brokerage account and execute real-money trades. In the context of a quant trading skill, this increases the chance that a user copies the snippet into a live strategy or connected environment and unintentionally places orders.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README includes a concrete live-trading example that places an order (order_shares) but does not prominently warn that the example can trigger real-money trades on a broker-linked account. In the context of a quantitative trading skill, this is especially risky because users may copy-paste sample code into a live QMT environment and unintentionally submit market-impacting orders.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes concrete order placement examples for a live trading platform, but does not place an immediate, prominent warning near those examples that they may execute real trades and affect actual funds. In an AI-agent context, this increases the risk that examples are copied, adapted, or operationalized without sufficient human review, potentially causing unauthorized or unintended financial transactions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

At L1121, the '释义' for remove_stock_from_sector(sector_name, stock_list) states '创建板块' (create sector), which directly contradicts the function name and parameter semantics indicating removal of constituent stocks. This is an active intent/documentation contradiction, not merely an omission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The quick-start examples immediately demonstrate live order placement and cancellation in a real trading terminal without prominent safety warnings, simulation guidance, or guardrails. In a trading skill, that omission is more dangerous because users may copy-paste code into production and trigger unintended market actions or financial loss.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The section is titled and parameterized as an external transaction import API (sync_transaction_from_external), but the 释义 states 通用数据导出 instead. This is an active contradiction in the inline documentation that could mislead developers about whether the call imports/modifies trading data or only exports data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples include plaintext sample credentials and encourage printing bank-transfer-related results, normalizing unsafe handling of sensitive financial information. Even if the sample values are placeholders, this pattern teaches developers to expose secrets and banking metadata in code and logs, increasing the chance of credential compromise or privacy leakage.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The section header and function name are ctp_transfer_future_to_option, but the 释义 says CTP资金内转(期权转期货). This directly reverses the transfer direction and can cause developers to misunderstand a money-movement operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

query_data is documented as exporting account data to a filesystem path and then deleting it, but the documentation omits the transient data-exposure risk. In this financial context, writing trades or holdings to disk can leak sensitive records through weak file permissions, backups, endpoint monitoring, temp-file recovery, or deletion failure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

query_bank_amount is documented as 银行转账流水查询, but the function name and returned fields (balance, enable_balance) clearly indicate a bank balance/amount query rather than transfer history. This is a direct documentation contradiction, not just an omission.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The bank balance query example passes a literal bank password and then iterates over returned fields for printing, which can expose banking and account data to logs, consoles, or monitoring systems. In a brokerage/banking integration, this materially increases the likelihood of credential mishandling and unauthorized disclosure of financial information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill content and instructional text are fully presented in Chinese, and the document does not indicate that the language choice is optional or region-specific. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill documentation is entirely in Chinese and does not provide any language-selection option or note that the skill is intentionally limited to Chinese-speaking users for a documented regional reason. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README presents the skill instructions in Chinese and does not indicate that users may choose another language or that the locale is required for a region-specific purpose. This is a natural-language policy concern because it imposes a language preference without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description is written entirely in Chinese and presents the skill as generally applicable, but the metadata does not state that the skill is China-specific or that language is selectable. This can violate language/locale policy when a skill implicitly assumes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency xtquant is specified with a lower-bound version only, which allows future unreviewed releases to be installed. This creates supply-chain risk because builds are not reproducible and a compromised or breaking upstream release could be pulled into a trading-related environment without explicit approval.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
xtquant>=1.0.0
numpy>=1.20.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

numpy>=1.20.0 is unpinned, so dependency resolution may select different versions over time, including releases with security defects or incompatible behavior. In a quant trading skill, non-reproducible environments increase both supply-chain exposure and operational risk.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
xtquant>=1.0.0
numpy>=1.20.0

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest references numpy without pinning an exact version, while known advisories exist across some NumPy releases. Because the selected installed version is unconstrained beyond a minimum, it is impossible to verify from this file alone whether deployment will avoid vulnerable versions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all skill instructions and API descriptions exclusively in Chinese, with no opt-in or alternative language path. Under the language/locale policy, forcing a single language without user choice can be a natural-language policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes a quantitative trading terminal centered on Python strategy development, backtesting, and live trading, which naturally justifies market data access. However, this file also documents sector taxonomy administration features such as creating folders/sectors, adding/removing constituents, resetting sectors, and downloading index weight metadata, which are more like platform data-management utilities than core trading-terminal behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.