Back to skill

Security audit

market

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent market-data tool, but it uses unauthenticated HTTP quote sources for integrity-sensitive financial data and can persist those results locally.

Review this before installing if you will use the output for financial decisions. The skill contacts third-party market-data providers, stores raw data and cache files locally, and some fallback quote paths use plaintext HTTP, so symbol queries and returned prices can be observed or tampered with on the network. Prefer authenticated data sources for trading-critical work and periodically clear the skill data directory if local query history or watchlists are sensitive.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/akshare_patch.py:193
Finding

Unauthenticated HTTP Market Data Ingestion

Content
View full analysis

Vulnerability Details

File Location: scripts/akshare_patch.py:193-194, 288-289; scripts/providers/yfinance_provider.py:67-69, 105-107
Vulnerability Type: Insecure transport of integrity-sensitive market data
Risk Level: Medium

Complete Code Snippets

From scripts/akshare_patch.py:193-194:

python
url = f"http://hq.sinajs.cn/list={symbol}"
r = original_get(url, headers={"Referer": "http://finance.sina.com.cn"}, timeout=5)

From scripts/akshare_patch.py:288-289:

python
url = f"http://hq.sinajs.cn/list={','.join(symbols)}"
r = original_get(url, headers={"Referer": "http://finance.sina.com.cn"}, timeout=5)

From scripts/providers/yfinance_provider.py:67-69:

python
url = f"http://hq.sinajs.cn/list=rt_hk{digits}"
req = urllib.request.Request(url, headers={"Referer": "https://finance.sina.com.cn"})
with urllib.request.urlopen(req, timeout=8) as resp:

From scripts/providers/yfinance_provider.py:105-107:

python
url = f"http://hq.sinajs.cn/list=gb_{clean}"
req = urllib.request.Request(url, headers={"Referer": "https://finance.sina.com.cn"})
with urllib.request.urlopen(req, timeout=8) as resp:

Technical Analysis

The Skill retrieves integrity-sensitive real-time market data over plaintext HTTP. HTTP does not authenticate the response origin or protect the response body against modification in transit. A network-path attacker can therefore alter Sina quote responses before they reach the Skill.

The affected response fields are parsed as authoritative market information, including security names, current and previous prices, price changes, highs, lows, volume, turnover, and timestamps. The A-share implementation also stores accepted results in the local cache through cache_db.set_cache, allowing manipulated values to persist until expiration.

The HK and US paths are fallback providers. They become reachable when the primary yfinance request doe ...[truncated 1515 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace every http://hq.sinajs.cn URL with an HTTPS endpoint that provides valid certificate verification.
  2. Do not disable TLS certificate or hostname verification.
  3. If the provider has no authenticated transport, remove the fallback or treat its response as untrusted and unavailable.
  4. Before caching or returning fallback data, verify critical fields against an independent provider reached over authenticated HTTPS.
  5. Record the actual provider and transport used in output metadata so downstream consumers can enforce data-integrity policies.
  6. Add tests that reject plaintext provider URLs and ensure fallback behavior fails closed when authenticated data cannot be obtained.
  7. Invalidate previously cached observations whose provenance indicates they were fetched over unauthenticated HTTP.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding points to local SQLite creation and durable storage of raw observations and revision history that are not clearly surfaced as a security-relevant behavior in the skill declaration. Persistent storage can accumulate sensitive or regulated data, increase forensic footprint, and expose later consumers to stale or tampered local state if not explicitly managed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding points to local SQLite creation and durable storage of raw observations and revision history that are not clearly surfaced as a security-relevant behavior in the skill declaration. Persistent storage can accumulate sensitive or regulated data, increase forensic footprint, and expose later consumers to stale or tampered local state if not explicitly managed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding points to local SQLite creation and durable storage of raw observations and revision history that are not clearly surfaced as a security-relevant behavior in the skill declaration. Persistent storage can accumulate sensitive or regulated data, increase forensic footprint, and expose later consumers to stale or tampered local state if not explicitly managed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding points to local SQLite creation and durable storage of raw observations and revision history that are not clearly surfaced as a security-relevant behavior in the skill declaration. Persistent storage can accumulate sensitive or regulated data, increase forensic footprint, and expose later consumers to stale or tampered local state if not explicitly managed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding points to local SQLite creation and durable storage of raw observations and revision history that are not clearly surfaced as a security-relevant behavior in the skill declaration. Persistent storage can accumulate sensitive or regulated data, increase forensic footprint, and expose later consumers to stale or tampered local state if not explicitly managed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding points to local SQLite creation and durable storage of raw observations and revision history that are not clearly surfaced as a security-relevant behavior in the skill declaration. Persistent storage can accumulate sensitive or regulated data, increase forensic footprint, and expose later consumers to stale or tampered local state if not explicitly managed.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
80% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/market_data.py (reported line 405)May include surrounding context.

python
if _PROVIDER_CONTEXT and _PROVIDER_CONTEXT.get("enabled") and _PROVIDER_CONTEXT.get("used"):
            names = {item["name"] for item in failed}
            error_type = (ProviderCompletenessError if any(
                token in name for name in names for token in ("coverage", "rows", "length", "freshness")
            ) else ProviderSchemaError)
            raise error_type(f"{dataset} 数据校验失败:{messages}")
        raise DataError(f"{dataset} 数据校验失败:{messages}")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares executable capabilities and operational instructions that imply shell execution, network access, filesystem reads/writes, and environment use, but it does not explicitly scope or constrain those powers via a permissions or allowed-tools declaration. This increases the blast radius if the skill is invoked unexpectedly or modified later, because callers cannot easily enforce least privilege from the manifest alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown content appears to enforce a single language for skill guidance, which can violate language or locale policy when no user opt-in or rationale is provided. The file does not indicate that Chinese is optional, selectable, or required for a specific regional compliance context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/cache_db.py (reported line 163)May include surrounding context.

python
def get_cache(key: str):
    """
    Retrieve value from cache if it exists and is not expired.
    Automatically deletes the key if expired.
    """
    init_db()
    now_str = datetime.now().strftime("%Y-%m-%d %H:%M:%S")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file includes many natural-language strings presented to users in Chinese, such as error messages and CLI help text, while the module description does not offer a language/locale choice. Under the policy, forcing a specific language without user opt-in is a violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest presents the skill as a market-data retrieval capability, but the implementation also persists fetched results to local JSON snapshot files and to a local raw store database. These write-side storage operations are not mentioned in the manifest and go beyond a straightforward query/return behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for validated A-share/HK/US stock quotes, K-lines, technical indicators, limit-up/down pools, fund flows, chip distribution, financial statements, and news. The code additionally exposes commodity market data, overnight macro context using US indices/A50/USD-CNY, and local watchlist reporting, which are separate capabilities not stated in the manifest and broaden the functional scope of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file defines user-visible labels such as "道琼斯", "标普500", and later returns data frames with Chinese column names like "日期" and "最新价". That forces a specific locale/language in outputs without any opt-in or documented justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly states that raw market details are written to local files/databases, but it does not present this as a clear user warning or consent point. In agent contexts, undisclosed persistence is risky because users may expect transient processing, while the skill actually leaves durable artifacts that can contain query history, provider data, or news content.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specifier yfinance>=1.7.0 is not pinned to a specific version, so builds may resolve to different releases over time. This weakens reproducibility and can unexpectedly introduce breaking changes or a vulnerable upstream release into a skill that fetches external market data, increasing supply-chain risk.

Content

Scanner excerpt · requirements.txt (reported line 5)May include surrounding context.

text
pandas==2.3.3
requests==2.34.2
curl_cffi==0.16.0
yfinance>=1.7.0

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code sends stock symbols to Sina over plain HTTP, which lacks transport encryption. Even if the queried data is not highly sensitive, network observers or attackers on the path can see or tamper with requested symbols and returned quote data, creating privacy and integrity risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The batch quote function transmits multiple user-supplied stock codes to an external Sina endpoint over plain HTTP, increasing both disclosure and tampering exposure. In this market-data skill, requested symbols may reveal user interests or trading intent, and unencrypted transport also permits modification of quote responses in transit.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames this skill as a stock market data query tool triggered by requests such as quotes, K-lines, indicators, flows, and financials. Reading a local watchlist file and producing portfolio-style multi-stock monitoring output is an extra capability not implied by those stated purposes or trigger phrases.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code performs outbound HTTP requests to Sina at multiple points, beginning with the quote fetch logic here, but the file provides no confirmation prompt, logging, or user-facing warning that requests and query parameters will be sent to third-party services. Because the skill transmits user-supplied stock symbols and contacts external providers, a minimal disclosure would improve transparency.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.