Back to skill

Security audit

tushare

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Tushare financial-data helper, with ordinary package-install and API-token handling risks but no hidden or destructive behavior found.

Install this in a virtual environment, avoid `--upgrade` during routine use, pin reviewed dependency versions where possible, and keep the Tushare token in an environment variable or local secret store rather than committed code.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Allow Unreviewed Package Code

Content
View full analysis
=1.3.0 pandas>=1.5.0 ``` `SKILL.md:16-18` ```bash ## 安装 ```bash pip install tushare --upgrade ``` ``` `README.md:18-20` ```bash ## 📥 安装 ```bash pip install tushare --upgrade ``` ``` `demo_project/README.md:6-10` ```bash 1. 确保已经安装依赖: ```bash pip install -r ../requirements.txt ``` ``` ### Technical Analysis The project instructs users to install third-party Python packages using `--upgrade` or lower-bound-only version constraints. Neither exact versions nor package hashes are provided, and no lock file records reviewed transitive dependencies. The constraints therefore permit pip to select future releases that were not available or reviewed when this Skill was published. The `--upgrade` option makes this behavior explicit by requesting a newer eligible release. If an allowed direct or transitive dependency is compromised, a malicious source distribution could execute code through its build backend during installation. A malicious installed package could also execute when imported at runtime. This is a supply-chain and reproducibility weakness. The audit did not find evidence that the currently named packages are malicious; the risk arises from allowing mutable, unverified future package versions. ### Attack Path 1. An attacker compromises the publication account or release process of an allowed direct or transitive dependency. 2. The attacker publishes a malicious version satisfying `tushare>=1.3.0`, `pandas>=1.5.0`, or an unrestricted transitive dependency constraint. 3. A user follows the documented `pip install tushare --upgrade` command or installs `requirements.txt`. 4. Pip resolves and downloads the attacker-controlled release becaus ...[truncated 1093 chars]
Remediation
View remediation
pandas== ``` 2. Generate and commit a lock file that records exact versions of all direct and transitive dependencies. 3. Use package integrity hashes and enforce them during installation: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Remove `--upgrade` from normal installation instructions. Perform upgrades through a controlled dependency-review process instead. 5. Configure a trusted package index explicitly and prevent unintended fallback to untrusted or internal-looking package sources. 6. Review release provenance, signatures, and package metadata before updating locked versions. 7. Run dependency installation and the demo in an isolated virtual environment or container under a non-privileged account. 8. Add automated dependency scanning and scheduled review of pinned versions so security updates can be adopted without accepting arbitrary future releases. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language content forces a specific language for all users and does not provide an opt-in, alternative language, or explanation that the skill is intentionally limited to a Chinese-speaking or China-specific audience. Under the policy, fixed language constraints without user choice or documented justification should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The AI-agent guidance and support sections are written entirely in Chinese and address agent behavior directly, but do not indicate that Chinese is optional or that another language may be used. This creates a language/locale constraint in the skill's natural-language instructions without user opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file forces a specific language for all instructions and examples, and there is no indication that the user can select another language or that the Chinese-only format is a justified regional requirement. Under the stated policy, language-specific documentation without opt-in or justification is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file includes a code example that sets an API token directly, but the surrounding documentation does not warn users that the token is a sensitive credential. Because the file is instructional markdown, a brief disclosure about keeping tokens out of shared files or source control would better satisfy user-warning expectations for credential-related behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README demonstrates setting a Tushare token directly in code and mentions an environment variable, but it does not explicitly warn users not to hardcode real credentials in committed or shared files. This can lead to accidental token leakage through source control, screenshots, notebooks, or logs, especially because users often copy examples verbatim.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing instructions and descriptions are written entirely in Chinese, and the file does not offer any language choice or explain that the skill is intended only for a Chinese-speaking or region-specific audience. This creates a natural-language locale constraint without opt-in, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s user-facing print messages are all written in Chinese, which imposes a specific language on users without any opt-in or alternative locale selection. This matches the policy category for language or locale constraints expressed in natural-language strings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest text is entirely in Chinese, including the user-facing description and tags, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking or China-specific audience. This can violate language/locale policy when a skill implicitly forces a language without opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specification uses a lower-bound only constraint for tushare, which permits installation of any newer release, including versions with breaking changes or newly introduced security issues. This weakens supply-chain control and harms reproducibility, even though the file itself does not show active exploitation.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
tushare>=1.3.0
pandas>=1.5.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The pandas requirement is also unpinned, allowing the environment to resolve to different versions over time. In a data-processing skill that may handle external financial data, this increases supply-chain risk and makes it harder to ensure that only reviewed, non-vulnerable versions are installed.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
tushare>=1.3.0
pandas>=1.5.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.