Back to skill

Security audit

China Stock Toolkit

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent market-data dashboard, but its HTML dashboard unsafely renders remote news content in a way that could let compromised or malicious news data run script in the browser.

Review before installing. The core behavior is purpose-aligned, but avoid exposing or relying on the news dashboard until remote news fields are rendered with textContent or sanitized HTML and links are validated. Prefer a pinned installer version, and remember market/news queries are sent to third-party data providers.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/dashboard.html:798
Finding

Remote News Content Is Rendered Through Unsafe innerHTML

Content
View full analysis
`
${n.title} ${n.sentiment}
📰 ${n.source} 🕐 ${n.pub_time} ${n.sentiment_score ? `得分: ${n.sentiment_score}` : ''}
${n.url ? `查看详情 →` : ''}
`).join(''); ``` ### Technical Analysis The dashboard interpolates news properties directly into an HTML template and assigns the result to `innerHTML`. The properties `title`, `source`, `pub_time`, `sentiment`, and `url` originate from external Eastmoney, Sina, or CLS responses and are not HTML-escaped before rendering. Because `innerHTML` invokes the browser's HTML parser, a malicious or compromised news provider can supply markup containing event handlers or other executable HTML. The `url` property is also placed directly ...[truncated 1895 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:10
Finding

Installation Documentation Executes an Unpinned Latest npm Package

Content
View full analysis
Remediation
View remediation
install china-stock-toolkit ``` 2. Document the expected npm publisher, registry, and package provenance. 3. Verify package integrity or signatures where the package manager and release process support them. 4. Publish and verify reproducible release artifacts when possible. 5. Prefer an already installed, trusted installer instead of downloading executable code during each installation. 6. Advise users not to run the installer with administrative privileges unless explicitly required. 7. Establish a release review process before updating the documented pinned version. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/dashboard.html (reported line 255)May include surrounding context.

html
</head>
<body>
    <div class="container">
        <!-- Header -->
        <div class="header">
            <h1>🌍 全球市场实时仪表盘</h1>
            <div class="time" id="updateTime">更新时间:--</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/dashboard.html (reported line 255)May include surrounding context.

html
</head>
<body>
    <div class="container">
        <!-- Header -->
        <div class="header">
            <h1>🌍 全球市场实时仪表盘</h1>
            <div class="time" id="updateTime">更新时间:--</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/dashboard.html (reported line 403)May include surrounding context.

html
</div>
        </div>
        
        <!-- 免责声明 -->
        <div class="disclaimer">
            <strong>⚠️ 免责声明</strong><br>
            本工具仅供学习和技术研究使用,不构成任何投资建议。数据可能存在延迟,不应作为交易决策依据。投资有风险,入市需谨慎。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/dashboard.html (reported line 403)May include surrounding context.

html
</div>
        </div>
        
        <!-- 免责声明 -->
        <div class="disclaimer">
            <strong>⚠️ 免责声明</strong><br>
            本工具仅供学习和技术研究使用,不构成任何投资建议。数据可能存在延迟,不应作为交易决策依据。投资有风险,入市需谨慎。

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run npx clawhub@latest install ..., which pulls and executes the latest package version at install time rather than a pinned, reviewed release. If the upstream package, dependency chain, or publisher account is compromised, users could execute attacker-controlled code simply by following the documentation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text is very broad, covering many common finance-related intents such as stocks, forex, metals, news, sentiment, and taxes. In an agent ecosystem, this can cause the skill to activate for a wide range of ordinary user queries, increasing the chance of unintended routing, unnecessary external data access, or the skill overshadowing more appropriate tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
72% confidence
Finding

The skill name and description are bilingual, but the activation condition and the rest of the skill instructions are written to operate in Chinese-market terminology and Chinese prompts, with no statement that users may choose another language. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN", and the UI logic also formats time and numbers using the zh-CN locale, making the skill effectively Chinese-only. Under SQP-3, forcing a specific language or locale without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code explicitly uses toLocaleString('zh-CN') for timestamps and numeric formatting, reinforcing a fixed Chinese locale for all users. Because no alternative locale choice or user preference handling is present, this conflicts with the policy against forcing a specific language/locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing descriptions and CLI messages entirely in Chinese, starting with the module docstring and continuing throughout the interface. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is documented and justified, which it is not here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings that set expectations and usage entirely in Chinese, including the module description and command help. Under the policy rule, forcing a specific language without opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings that force a specific language/locale for documentation and interaction. Under the policy, hard-coding a language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring presents the skill as a market data dashboard and multi-source aggregation engine. However, the executable interface later adds stock/sector/policy news retrieval and market sentiment analysis actions via NewsAggregator, which is a materially different capability from the stated documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module description, CLI help strings, and user-facing error/output messages are consistently presented in Chinese, which imposes a specific language on users without offering a locale or language selection. This is a natural-language policy concern because the skill does not document that it is region/language-specific or provide an opt-in choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This function makes outbound HTTP requests to a third-party market data provider, but there is no confirmation prompt, user-facing print/log message, or warning comment/docstring explaining that external network access occurs. The same undisclosed behavior is repeated across other fetch functions in the file, which means user or system query data may be transmitted off-host without explicit notice in the code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description, headings, and example prompts are presented entirely in Chinese, and the example invocation phrases assume Chinese-only usage. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language choice or opt-in is documented.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The inline comment at L726 presents this as an added 'news analysis section', implying it is part of the dashboard UI. In reality, the entire section and its script are appended after the document has already been closed at L723-L724, so the documented intent of being an integrated dashboard section diverges from the actual document structure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This HTML/JS file sends user-provided stock codes or sector names to backend API endpoints via fetch, but the UI does not disclose that entered queries will be transmitted to the server for processing. For code files, SQP-2 applies when network calls that transmit user data lack any visible disclosure, and no nearby comment or user-facing warning covers this behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The configuration loader reads API keys and proxy settings from environment variables, but the code provides no user-facing notice or comment about handling credentials or proxy-derived network behavior. Under this rule, access to sensitive environment variables should include some disclosure so users understand that secrets and proxy configuration may affect execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.