Back to skill

Security audit

All-Market Financial Data Hub

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent finance-data query tool, but an undocumented Python endpoint override can expose the user's Eastmoney API key if invoked with an untrusted URL.

Install only if you trust the Eastmoney API workflow and can protect or revoke the EM_API_KEY. Use the documented CLI path, avoid passing custom API endpoint parameters, and prefer an isolated Python environment with reviewed dependency versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_data.py:671
Finding

API Credential Disclosure Through Unrestricted Endpoint Overrides

Content
View full analysis
Dict[str, Any]: output_dir = output_dir or _get_default_output_dir() output_dir = Path(output_dir) output_dir.mkdir(parents=True, exist_ok=True) url = api_base or DEFAULT_SEARCH_API_URL entity_api_url = entity_api_base or DEFAULT_ENTITY_API_URL result = _make_result_base(query) entity_tags: Optional[List[Dict[str, Any]]] = None try: api_key = EM_API_KEY async with httpx.AsyncClient(timeout=120.0) as client: recognized_tags = await _recognize_entities( client=client, query=query, api_key=api_key, entity_api_url=entity_api_url, ) recognized_count = len(recognized_tags) result["recognized_entity_count"] = recognized_count if recognized_count > DIRECT_QUERY_ENTITY_LIMIT: if not indicators or not indicators.strip(): result["error"] = ( "多实体查数(识别实体数 > 5)缺少 --indicators," "请从 query 中提取金融指标后传入,用于构造「选定实体的{indicators}」" ) return result entity_tags = recognized_tags result["use_entity_tags"] = True search_query = _build_multi_entity_query(indicators) result["indicators"] = indicators.strip() result["search_query"] = search_query else: result["use_entity_tags"] = False search_query = query if indica ...[truncated 2681 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:111
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires environment access, outbound network access, and writes output files, but it does not declare an explicit tool scope or permissions boundary. This can cause an agent platform to grant broader capabilities than users expect, increasing the risk of unintended data access, exfiltration, or filesystem side effects during execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is broadly worded as a general natural-language financial data query tool across many markets and use cases, without clear trigger constraints. In agent environments, this increases the chance of over-broad or unintended activation, which can lead to unnecessary transmission of user-provided financial queries and generation of files when the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The primary title and operational instructions are presented as a Chinese-only user-facing skill description, while the file does not explicitly offer the user a language choice or explain that the skill is limited to Chinese-language operation for compliance or regional reasons. This may violate language/locale policy if users are not given an opt-in or alternative locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring and all user-facing CLI descriptions are written solely in Chinese, indicating the skill is designed around a fixed language/locale without any opt-in or alternative. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.