Back to skill

Security audit

Stock Monitor Pro

Security checks for vulnerabilities and agentic risk

Overview

This stock-alert skill is mostly related to its stated purpose, but users should review it because it runs continuously, scrapes market-data providers, uses plaintext HTTP fallback data, and can produce investment advice.

Install only if you are comfortable with a Chinese-market stock monitor that runs as a background process and repeatedly queries third-party data providers. Treat its trading suggestions as informational, verify data independently, avoid relying on plaintext-source alerts for financial decisions, and review or remove proxy/scraping behavior before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/monitor_v2.py:330
Finding

Unauthenticated HTTP Transport for Technical Market Data

Content
View full analysis
= 20: self._mark_source_success(source_name) return klines, None ``` ### Technical Analysis The 10jqka fallback endpoint uses plaintext HTTP. HTTP provides neither server authentication nor transport integrity, allowing a network-positioned attacker to observe and modify the response. The returned JSONP content is parsed as trusted market data and passed to `calculate_indicators()`. That method calculates moving averages, RSI, volume ratios, golden crosses, and death crosses. These values are then used to produce user-facing financial alerts. The implementation does not authenticate the response, verify its origin, enforce HTTPS, or cross-check fallback data against an independent source. It also does not call `raise_for_status()` before parsing the response. ### Attack Path 1. The preferred Eastmoney source fails or becomes unavailable. 2. The application falls back to the plaintext 10jqka endpoint. 3. An attacker with control over a network gateway, local wireless network, DNS path, or upstream proxy intercepts the HTTP request. 4. The attacker returns syntactically valid JSONP containing fabricated closing prices or volume data. 5. The application accept ...[truncated 931 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyser.py:123
Finding

Plaintext HTTP Used for Eastmoney Market-Ranking Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The documented purpose is end-user monitoring/alerts, but the analyzed behavior reportedly corresponds to automated testing and integration-style external fetching rather than the declared production functionality. This discrepancy undermines trust and can conceal what code will actually run when the skill is invoked, which is a supply-chain and reviewability concern.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose is end-user monitoring/alerts, but the analyzed behavior reportedly corresponds to automated testing and integration-style external fetching rather than the declared production functionality. This discrepancy undermines trust and can conceal what code will actually run when the skill is invoked, which is a supply-chain and reviewability concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language policy violations include forcing a specific language without user opt-in. This file's user-facing instructions and feature descriptions are written in Chinese only, with no note that the language is optional or that alternatives are available.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documentation describes functionality that inherently relies on external market data and anti-scraping/network access, but the manifest does not declare any tool scope or permissions. This creates a transparency and governance gap: the agent may invoke network-capable components without explicit user-visible scoping, making review, sandboxing, and policy enforcement harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation description is broad enough to match many ordinary stock-related requests, which can cause the skill to trigger in contexts where the user did not intend specialized monitoring or external-data behavior. Overbroad matching increases the chance of unnecessary activation, surprise network access, and user confusion about why this skill was selected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is framed as a monitoring/alert tool, but it also markets itself as an 'intelligent investment advisory system' and provides trading suggestions. That role expansion can mislead users and routing systems into trusting it for financial advice beyond its declared scope, increasing the risk of inappropriate recommendations or compliance issues.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes a stock monitoring and alerting system focused on price/indicator alerts, daily reports, and trading notifications. This file explicitly adds broader intelligence functions—news sentiment, fund-flow data, 龙虎榜 scraping, and macro gold-correlation analysis—which go beyond the stated monitoring/alert use case and expand the skill into discretionary market research.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module title, docstrings, and generated user-facing content are written exclusively in Chinese, which effectively fixes the interaction language without giving users a choice. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing strings are entirely in Chinese, including status, warnings, and usage output. This imposes a specific language on all users without opt-in or explanation, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/control.sh (reported line 17)May include surrounding context.

sh
echo "🚀 启动 Stock Monitor 后台进程..."
        mkdir -p "$LOG_DIR"
        nohup python3 "$SCRIPT_DIR/monitor_v2.py" > "$LOG_DIR/monitor.log" 2>&1 &
        echo $! > "$PID_FILE"
        echo "✅ 已启动 (PID: $!)"
        echo "📋 日志: $LOG_DIR/monitor.log"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring explicitly states support for '国际现货黄金 (伦敦金)', and the code contains dedicated weekend/night scheduling and a Sina hf_XAU data path for London gold. The manifest description and usage guidance describe the skill as for stock monitoring for A-shares and ETFs, so adding international spot-gold monitoring exceeds the stated behavior scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring and user-facing descriptions are entirely in Chinese and describe China-specific market conventions, but the file does not indicate that the skill is limited to Chinese-speaking users or provide any language opt-in. Under the policy, forcing a specific language or locale without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Multiple watchlist entries set 'trailing_stop': False, implying dynamic trailing-stop behavior is turned off. But the trailing-stop logic in check_alerts runs whenever cost > 0 and profit_pct >= 10, without checking the configuration flag, so the implementation contradicts the stated per-stock intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scheduling comments and returns say weekends and nights monitor only London gold, filtering WATCHLIST entries where market == 'fx'. However, the provided WATCHLIST contains only 'sz' ETF entries, so those modes actually monitor nothing, contradicting the documented intent rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and operational log messages are written in Chinese, which imposes a specific language on users and operators. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale, which conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code deliberately rotates realistic browser User-Agent strings and sets a fuller browser-like header set to mimic human browsing behavior against third-party market-data providers. In the context of a stock-monitoring skill, this crosses into anti-scraping evasion and can facilitate unauthorized collection from providers that rely on access controls or rate-limiting, increasing legal/compliance and abuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill silently makes outbound HTTP requests to multiple third-party market-data providers without any user-facing consent, disclosure, or configuration boundary. While not directly code-execution dangerous, this creates privacy, compliance, and transparency risks because users may not realize stock symbols, timing patterns, and network metadata are being sent to external services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The error-notification text explicitly suggests deploying a WARP proxy or changing request frequency to work around blocking by upstream data sources. Guidance that helps bypass provider-imposed restrictions is outside ordinary stock monitoring and can enable continued access after a service has attempted to deny or throttle automated collection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language descriptions and console output entirely in Chinese, beginning with the top-level docstring and continuing throughout the test suite. Under the policy, forcing a specific language without user opt-in is a locale-policy violation unless the constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file includes setup steps that direct the user to create and populate a local configuration file with portfolio information, but it provides no warning about the sensitivity of that data or safe storage practices. For markdown files, missing user-facing warnings about behaviors that could affect privacy or user data should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description states that the skill '符合中国投资者习惯(红涨绿跌),' which imposes a locale-specific presentation convention. The file does not indicate that users can opt into or change this locale behavior, so it may conflict with language/locale choice policy.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The changelog claims support for news and sentiment analysis, but that capability is not reflected in the stated manifest/capabilities. Even in documentation, undeclared feature creep is risky because it can hide additional data ingestion, external calls, or recommendation logic from reviewers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code issues network requests to third-party services using the provided stock name and symbol, including query parameters derived from user-controlled inputs. Although the methods have brief docstrings, there is no explicit user-facing warning, confirmation, or logging that stock queries will be sent to external providers.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring says the function '获取新浪财经个股新闻', implying it retrieves actual stock news. In practice, after making a request, the code ignores the response content and returns a fabricated example item, which contradicts the documented behavior rather than merely omitting details.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstrings for fetch_fund_flow and fetch_northbound_flow state that they obtain actual market flow data. However, both functions discard the HTTP response and return static placeholder strings like '数据获取中...' rather than parsed flow metrics, which directly conflicts with the stated function intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.