Back to skill

Security audit

rqalpha

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent RQAlpha backtesting reference skill, with no evidence of hidden or malicious behavior, though users should treat trading examples and dependency installation carefully.

Install in an isolated virtual environment or container, prefer pinned and reviewed dependency versions, and treat all order-placement examples as backtest or simulation code unless you deliberately connect RQAlpha to a live broker and accept the financial risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Package Installation

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-3; installation instructions also appear in SKILL.md:16-20 and demo_project/README.md:7-10
Vulnerability Type: Supply-chain risk caused by unpinned dependencies and missing integrity verification
Risk Level: Medium

Vulnerable Code

requirements.txt:1-3:

text
rqalpha>=5.0.0
pandas>=1.5.0
numpy>=1.20.0

SKILL.md:16-20:

bash
pip install rqalpha

rqalpha download-bundle

demo_project/README.md:7-10:

bash
pip install -r ../requirements.txt

Technical Analysis

All declared Python packages use open-ended minimum-version constraints. The primary installation instructions are even less restrictive because pip install rqalpha requests the latest compatible release. The project does not provide a lockfile, exact version pins, package hashes, or an explicitly trusted package index.

Consequently, installations performed at different times can resolve to package versions that were never reviewed with this Skill. Python package installation can run package-controlled build logic, while imported dependencies execute with the privileges of the Python process. A compromised upstream release, compromised dependency account, malicious package served through a configured package mirror, or unsafe future transitive dependency could therefore introduce code that is absent from the audited project.

The rqalpha download-bundle command also performs declared external data retrieval, but the reviewed files do not show that it retrieves or executes code. The confirmed issue is limited to dependency installation without reproducible version and integrity controls.

Attack Path

  1. A user follows the documented command pip install rqalpha or installs requirements.txt.
  2. The package resolver queries the configured Python package index or mirror.
  3. Because the dependencies are not pinned, the resolver may sele ...[truncated 1132 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace minimum-version constraints with exact, reviewed versions, for example:

    text
    rqalpha==REVIEWED_VERSION
    pandas==REVIEWED_VERSION
    numpy==REVIEWED_VERSION
    
  2. Generate and commit a lockfile containing the complete transitive dependency graph.

  3. Require package hashes during installation, such as a hash-locked requirements file used with pip install --require-hashes.

  4. Configure an explicitly trusted package index instead of relying on arbitrary local pip configuration or untrusted mirrors.

  5. Install dependencies inside an isolated, non-privileged virtual environment or container. Do not use administrative installation unless strictly necessary.

  6. Scan locked direct and transitive dependencies for known vulnerabilities before release and in CI.

  7. Update the installation documentation to use the locked dependency file rather than pip install rqalpha.

  8. Review and deliberately regenerate pins and hashes whenever dependencies are upgraded.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (12)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes concrete order-placement examples such as buy, sell, target allocation, and full liquidation (清仓) commands. Under the markdown variant of SQP-2, behaviors that can affect user data, privacy, or system integrity should be accompanied by warnings; here, there is no caution that these commands place or simulate trades and can materially affect portfolio state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description and all usage guidance are presented in Chinese, starting with the title and introductory text, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This creates a natural-language locale policy concern because it implicitly enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes concrete buy, sell, rebalance, stop-loss, and futures order examples that affect portfolio positions, but it does not include an accompanying warning that these actions can execute trades or should be limited to backtesting/simulated environments. For markdown files, SQP-2 applies when the description omits warnings about behaviors that could affect user data, privacy, or system integrity; here the omitted warning is about potentially impactful trading behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill content appears to force a single language/locale for all users, and there is no visible opt-in, alternative language path, or justification that this is a region-specific document. Per SQP-3, natural-language policy violations include language or locale restrictions without user choice or documented rationale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses Chinese for core usage instructions and descriptions, which can constitute a language/locale policy issue when no user opt-in or alternative language option is provided. The policy specifically flags forced language choices in natural-language content across all file types.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill's user-facing messages are written exclusively in Chinese, including status and error output, with no indication that language is configurable or that the tool is intentionally limited to a Chinese-speaking audience. This creates a natural-language policy concern because it imposes a specific locale on all users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest uses Chinese exclusively in the description and tags, which can impose a specific language/locale on users without opt-in. The file does not indicate that the skill is region-specific or offer an alternative language choice, matching the language/locale policy concern.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency specification for rqalpha is unpinned and allows any future version at or above 5.0.0 to be installed. This weakens build reproducibility and increases supply-chain risk because a breaking, compromised, or vulnerable upstream release could be pulled in without review.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
rqalpha>=5.0.0
pandas>=1.5.0
numpy>=1.20.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The pandas requirement is specified as a minimum version only, so installs may resolve to different versions over time. That creates uncertainty around security posture and can expose consumers to newly introduced or still-unpatched issues depending on what gets installed.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
rqalpha>=5.0.0
pandas>=1.5.0
numpy>=1.20.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Because pandas is not pinned, it is impossible to determine from this manifest alone whether an affected version with a known advisory could be installed. Even though the cited CVE is disputed, the broader issue is that version ambiguity prevents reliable vulnerability assessment and can permit unsafe versions in some environments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The numpy dependency is unpinned, which means environments may install different releases at different times. This increases supply-chain and reproducibility risk and makes it harder to verify whether deployed versions contain known flaws.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
rqalpha>=5.0.0
pandas>=1.5.0
numpy>=1.20.0

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The manifest does not pin numpy, so security reviewers cannot verify whether installations will avoid versions associated with known advisories. In a computational framework, this is mainly a supply-chain hygiene issue rather than an immediately exploitable flaw in the file itself, but it still increases exposure and uncertainty.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.