Back to skill

Security audit

Intelligent Stocks Screener

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Eastmoney stock-screening skill, but its CSV export can preserve untrusted spreadsheet formulas from remote data, which users should review before installing.

Install only if you trust the Eastmoney API service and are comfortable providing EM_API_KEY. Treat generated CSV files as untrusted data: open them with formula execution disabled or inspect them first, especially before sharing or using them in Excel. Prefer installing dependencies in an isolated environment with pinned versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_data.py:320
Finding

CSV Formula Injection in Exported Screening Results

Content
View full analysis

Vulnerability Details

File Location: scripts/get_data.py, lines 320-323
Vulnerability Type: CSV formula injection caused by unsanitized remote data
Risk Level: Medium

Vulnerable Code

python
with open(csv_path, "w", newline="", encoding="utf-8") as f:
    writer = csv.DictWriter(f, fieldnames=fieldnames, extrasaction="ignore")
    writer.writeheader()
    for row in rows:
        writer.writerow(row)

Technical Analysis

The application writes column names and values derived from the remote MCP response directly to a CSV file. It does not neutralize strings beginning with spreadsheet formula indicators such as =, +, -, or @. Leading tab or carriage-return characters can also be used to conceal formula prefixes from simplistic validation.

CSV quoting performed by csv.DictWriter does not prevent Microsoft Excel or another spreadsheet application from interpreting a cell as a formula. The documentation explicitly states that generated CSV files can be opened with Excel, making spreadsheet evaluation part of the expected usage.

An attacker able to influence the East Money API response, including through compromise of the remote service or its upstream data, could return a value such as a formula that initiates an external request when the CSV is opened. The same issue applies to remotely derived column headers because writer.writeheader() writes them without sanitization.

Attack Path

  1. An attacker gains the ability to influence a value or column name returned by the configured MCP endpoint.
  2. The attacker supplies content beginning with a spreadsheet formula prefix.
  3. _datalist_to_rows converts the value to a string without neutralizing formula syntax.
  4. csv.DictWriter writes the attacker-controlled content unchanged into the generated CSV file.
  5. The user opens the CSV file in Excel or another formula-evaluating spreadsheet application.
  6. The spreadsheet inter ...[truncated 931 chars]
Remediation
View remediation

Remediation Suggestions

Sanitize every remotely derived CSV value and header before writing it:

  1. Treat values as potentially dangerous if, after applicable normalization, they begin with =, +, -, @, tab, or carriage return.
  2. Prefix dangerous values with an apostrophe or another spreadsheet-compatible text marker.
  3. Apply the same protection to fieldnames before calling writeheader().
  4. Preserve the original untrusted value separately only if required; do not place it directly in formula-evaluating cells.
  5. Consider generating a spreadsheet format that supports explicit text cell types rather than relying on CSV.
  6. Document that exported data is untrusted and should not be opened with formula execution enabled.
  7. Add tests covering malicious headers and values beginning with =, +, -, @, tab, and carriage return.
  8. Test values containing leading whitespace or control characters to ensure normalization cannot bypass the protection.

A centralized sanitizer should be applied immediately before CSV serialization so that both dataList and partialResults output paths receive identical protection.

T08 · Insecure Dependencies

Note
Location
SKILL.md:97
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 97
Vulnerability Type: Unpinned dependency and missing integrity verification
Risk Level: Low

Vulnerable Code

bash
pip3 install httpx --user

Technical Analysis

The installation instruction retrieves the latest version of httpx accepted by the package resolver without specifying a reviewed version or verifying an integrity hash. Consequently, two installations performed at different times may resolve to different package versions and dependency trees.

The package name corresponds to the legitimate httpx project, and the audit found no evidence of typosquatting, dependency confusion, or an intentionally malicious dependency. The concern is that an unpinned installation unnecessarily expands exposure to future compromised releases, malicious transitive dependencies, or newly introduced vulnerabilities.

The --user option limits installation to the invoking user's package environment but still permits installed package code to execute with that user's privileges when imported or during package installation processes.

Attack Path

  1. A package release or transitive dependency available from the configured Python package index is compromised or contains malicious code.
  2. A user follows the documented unpinned installation command.
  3. The package resolver selects the affected release because no approved version or hash is enforced.
  4. Installation-time behavior, or later import and execution by scripts/get_data.py, runs the affected package code.
  5. The malicious code executes with the permissions of the user running the installation or Skill.

This path depends on compromise or malicious publication in the dependency supply chain; the reviewed project itself does not provide evidence that the current httpx package is malicious.

Impact Assessment

If the dependency supply chain were compromised, package code could access ...[truncated 320 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin httpx and its transitive dependencies to reviewed versions.
  2. Maintain dependencies in a lock file generated by a trusted dependency-management tool.
  3. Require package hashes during installation, such as with a hash-locked requirements file and pip install --require-hashes.
  4. Review and update pinned versions through a controlled dependency-update process.
  5. Run vulnerability and provenance checks against each proposed update.
  6. Use an explicitly trusted package index rather than inheriting arbitrary index configuration where operationally possible.
  7. Perform installation in an isolated virtual environment instead of the general user package environment.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill requires an API key, performs network access, and writes output files, but does not declare any explicit tool scope or permission boundaries. This weakens least-privilege controls because a host may grant broader capabilities than users expect, increasing the risk of unauthorized network use, secret handling mistakes, or unintended file writes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring states the tool converts output to Chinese column names and describes the skill entirely in Chinese, which communicates a fixed language behavior. There is no indication that users can opt into another language or that the Chinese-only output is required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The main description is presented in both Chinese and English inline, and the rest of the document is primarily Chinese, but the skill does not state whether users can choose their preferred language or locale. Under the policy for natural-language issues, forcing or assuming a language without explicit user opt-in can be a locale-policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.