Back to skill

Security audit

A股龙虎榜市场数据API接口

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Chinese A-share market data client, with the main risk being that it uses an unencrypted HTTP API endpoint for financial data.

Before installing, understand that this client sends stock codes and dates to a third-party HTTP endpoint, so queries and returned market data could be observed or modified on the network. Avoid using it for high-integrity trading automation unless the provider offers HTTPS or another integrity protection, and do not send API keys or sensitive credentials through the current HTTP endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/client.py:26
Finding

Cleartext HTTP Used for External Market Data API

Content
View full analysis

Vulnerability Details

File Location: scripts/client.py:26-48
Additional Locations: SKILL.md:4, SKILL.md:30, SKILL.md:52, SKILL.md:111, SKILL.md:125
Vulnerability Type: Cleartext transmission and unauthenticated transport
Risk Level: Medium

python
def __init__(self, base_url: str = "http://fffy520.gicp.net:8003"):
    self.base_url = base_url.rstrip("/")

def _request(self, path: str, params: dict = None) -> dict:
    url = f"{self.base_url}{path}"
    if params:
        url += "?" + urllib.parse.urlencode(
            {k: v for k, v in params.items() if v is not None}
        )
    try:
        with urllib.request.urlopen(urllib.request.Request(url), timeout=30) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        body = e.read().decode("utf-8", errors="ignore")
        try:
            return json.loads(body)
        except json.JSONDecodeError:
            return {"code": e.code, "error": body}
    except Exception as e:
        return {"code": 500, "error": str(e)}

The documentation also consistently directs users to the same cleartext endpoint, for example:

text
curl "http://fffy520.gicp.net:8003/api/moneyflow?code=600519&trade_date=20260513"

Technical Analysis

The default client endpoint and every documented API example use HTTP rather than HTTPS. HTTP provides no server authentication, transport encryption, or integrity protection. A party capable of observing or modifying network traffic can therefore inspect query parameters and replace API responses before the client parses them.

The client directly decodes and returns received JSON without any application-level signature verification. Consequently, syntactically valid JSON injected by an intermediary is treated as a legitimate response. Configurability of base_url does not mitigate the vulnerable default, and the cl ...[truncated 1353 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the default endpoint with an HTTPS URL served using a valid certificate:

    python
    def __init__(self, base_url: str = "https://api.example.com"):
        parsed = urllib.parse.urlparse(base_url)
        if parsed.scheme != "https":
            raise ValueError("The API endpoint must use HTTPS")
        self.base_url = base_url.rstrip("/")
    
  2. Configure the API service on a stable, controlled domain with a certificate issued by a trusted certificate authority.

  3. Update every URL and curl example in SKILL.md to use the authenticated HTTPS endpoint.

  4. Do not silently fall back to HTTP when TLS negotiation or certificate validation fails.

  5. Never transmit API keys, session tokens, or other credentials through the current HTTP endpoint.

  6. For high-integrity financial workflows, consider signed API responses or certificate pinning where operationally appropriate, while maintaining a secure certificate-rotation process.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The client defaults to plain HTTP and sends requests to a remote host without transport encryption, allowing network attackers to observe or tamper with responses. Because this code consumes JSON from that endpoint and presents it as trusted market data, a man-in-the-middle could alter data integrity or mislead downstream users and systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstrings and CLI output are entirely in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.