Back to skill

Security audit

China Stock Sentiment

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a stock-sentiment purpose, but its report command can write files outside its intended folder and its documentation overstates live monitoring capabilities.

Review this skill before installing. It does not show malicious exfiltration or install-time persistence, but only run reports with trusted stock names, do not rely on generated reports as live market analysis unless the publisher fixes the mock-data behavior, and treat locally saved reports as potentially sensitive financial-interest data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:205
Finding

Path Traversal Through Unsanitized Stock Name

Content
View full analysis
`- ${r}`).join('\n')} --- *报告由 China Stock Sentiment 技能生成* `; fs.writeFileSync(outputPath, markdown, 'utf8'); console.log(`报告已保存至:${outputPath}`); } ``` ```js } else if (command === 'report' && args[1]) { const stockName = args[1]; // 模拟新闻数据 const mockNews = [ { title: `${stockName}业绩超预期,净利润增长 50%`, content: '公司发布财报...' }, { title: `${stockName}获得大额订单`, content: '与某知名企业签订合作协议...' }, { title: `分析师看好${stockName}后市表现`, content: '多家券商给出买入评级...' } ]; const report = generateReport(stockName, mockNews); const outputPath = path.join(process.cwd(), 'memory', 'stock-sentiment', 'reports', `${stockName}-${Date.now()}.md`); saveReport(report, outputPath); ``` ### Technical Analysis The CLI accepts `stockName` directly from `process.argv` and embeds it into the report filename without validation. An attacker can include directory traversal components such as `../` in this value. Although `path.join()` constructs the path, it also normalizes traversal components. It does not verify that the normalized destination remains under the intended `memory/stock-sentiment/reports` directory. The resulting path is passed to `saveReport()`, which recursively creates its ...[truncated 2041 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README presents very broad natural-language invocation phrases like '查看今天 A 股市场舆情' and '生成本周股市舆情报告' without documenting activation boundaries, confirmation requirements, or when the skill should refuse. In an agent ecosystem, overly generic triggers can cause unintended invocation or over-broad handling of user requests, especially in finance-related contexts where accidental analysis or action could influence decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises API-based sentiment access and shows bearer-token usage, but it does not warn about secure transport, API key storage, logging exposure, or transmission of potentially sensitive usage patterns. Even though the example targets localhost, users may replicate the pattern in real deployments and expose tokens or sentiment query data through insecure handling.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 68)May include surrounding context.

支持通过 API 获取舆情数据:

bash
curl -X POST http://localhost:8080/api/sentiment \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{"stock": "600519", "type": "daily"}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad terms such as '股票', '投资', 'stock', and 'sentiment', which are common in ordinary finance conversations and can cause the skill to activate unintentionally. In a finance context, accidental invocation is riskier because the skill may perform web fetching, sentiment analysis, and generate investment-oriented outputs when the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that sentiment data and generated reports are stored in local Markdown files, but it does not disclose retention behavior, access controls, or obtain user consent for persistence. Because the data may include tracked securities, monitoring preferences, and generated investment reports, silent storage can expose sensitive financial interests or behavioral data to other local users, tools, or future sessions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module header describes the skill as performing real-time monitoring of market sentiment, hot sectors, and stock public opinion. However, the CLI report flow constructs a report from fixed mockNews entries rather than live market or news inputs, so the documented intent materially overstates what the code actually does.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function comment says it obtains Baidu hot stock topics, implying a direct data retrieval operation. In reality, it invokes openclaw skill run baidu-hot-cn via child_process.execSync, delegating to another skill and introducing command-execution behavior not reflected in the documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The report timestamp is explicitly formatted with the 'zh-CN' locale, and the CLI/help/report strings throughout the skill are Chinese-only. This imposes a specific language/locale on users without offering opt-in or documenting a justified region-only constraint, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README content, usage examples, and support details are entirely in Chinese, which effectively enforces a single language for users without opt-in or alternative language guidance. Under the language/locale policy criterion, this is a natural-language policy issue unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill content, trigger phrases, and usage examples are predominantly presented in Chinese, which can functionally force a specific language for users without any explicit opt-in. The file does not state that the skill is intentionally limited to Chinese-speaking users or the China A-share market as a documented locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:58