Back to skill

Security audit

Wyckoff Stock Diagnosis (A股诊股工具)

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language A-share stock analysis skill that fetches market data and prints technical analysis, with no evidence of hidden access, persistence, or destructive behavior.

Install only if you want a Chinese-language A-share technical analysis helper. Treat its stock output as informational, not investment advice, and install efinance in a virtual environment with a pinned version if possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
SKILL.md:100
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:100
Vulnerability Type: Unpinned third-party dependency
Risk Level: Low

Vulnerable Code

markdown
- `efinance` - A-share market data retrieval (`pip install efinance`)

The dependency is imported by the application at scripts/diagnose.py:7:

python
import efinance as ef

Technical Analysis

The installation instructions direct users to install the latest package resolved under the efinance name without specifying an audited version, package hash, lockfile, or trusted package index. The imported dependency executes within the Skill process and handles network-backed market-data retrieval.

This creates supply-chain exposure because installation results can change after the Skill has been audited. A malicious or compromised package release—or an unsafe transitive dependency introduced by a later release—could execute code during installation or when imported. The project contains no evidence that the current efinance package is malicious; the finding concerns the absence of dependency integrity and reproducibility controls.

Attack Path

  1. An attacker compromises a future efinance release or one of its transitive dependencies.
  2. A user follows the documented pip install efinance instruction.
  3. The package resolver downloads the attacker-controlled version because no version or hash is pinned.
  4. Malicious package code executes during installation or when diagnose.py imports efinance.
  5. The payload runs with the privileges of the user invoking pip or the Skill.

Impact Assessment

Successful exploitation could permit arbitrary code execution within the installation or Skill runtime environment. The attacker could access files, environment variables, network resources, and other data available to the invoking user. The impact is limited by that user's operating-system privileges and any process or container iso ...[truncated 16 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin efinance to a reviewed exact version in a dependency manifest.
  2. Generate and enforce cryptographic hashes, for example with a hash-locked requirements file and pip install --require-hashes.
  3. Lock all transitive dependencies to produce reproducible installations.
  4. Explicitly configure and document the trusted package index.
  5. Regularly scan locked dependencies for known vulnerabilities and review updates before changing the lockfile.
  6. Install and run the Skill in an isolated virtual environment or restricted container under a least-privileged account.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest sets the skill language to "zh", and the description is also written in Chinese, but there is no indication that users can choose another language or that this locale restriction is optional. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing descriptions and output entirely in Chinese, including the module description, status messages, report text, and CLI usage. Under the policy rule for language/locale, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is described entirely around A股 analysis and uses Chinese-only invocation examples such as “诊股 <股票代码>”. While region-specific scope can be acceptable, the file does not explicitly frame this as a locale-limited skill choice or offer alternatives, which can be a natural-language locale policy issue under the stated rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.