Back to skill

Security audit

stock-market-hotspot-discovery

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently uses an EastMoney API key to fetch stock-market hotspot reports and optionally save them locally, with no evidence of hidden or destructive behavior.

Install only if you trust EastMoney with your API key and the hotspot queries you submit. Treat generated stock-market content as informational, not investment advice, and prefer a revocable API key with limited scope where available.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tainted flow: 'req' from os.environ.get (line 161, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/get_data.py (reported line 172)May include surrounding context.

python
)

    try:
        with urllib_request.urlopen(req, timeout=TIMEOUT_SECONDS) as resp:
            raw_body = resp.read().decode("utf-8", errors="replace")
    except urllib_error.HTTPError as exc:
        err_body = exc.read().decode("utf-8", errors="replace") if exc.fp else ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires an environment secret, performs network access to a third-party API, and can write files, but it does not declare any explicit tool scope or permissions boundary. This creates a least-privilege and reviewability problem: an agent/runtime may grant broader capabilities than necessary, making secret exposure, unintended outbound requests, or unsafe file writes harder to govern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function sends arbitrary user-provided question content to a third-party remote API without any explicit notice or consent mechanism at the function interface or call site. In a skill handling free-form user queries, this can expose sensitive personal, financial, or proprietary text that users may not realize is leaving the local/runtime boundary, making it a real privacy and data-governance issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.