T09 · Insecure Skill Coding Practices
- Location
scripts/akshare_patch.py:193- Finding
Unauthenticated HTTP Market Data Ingestion
- Content
View full analysis
Vulnerability Details
File Location:
scripts/akshare_patch.py:193-194, 288-289;scripts/providers/yfinance_provider.py:67-69, 105-107
Vulnerability Type: Insecure transport of integrity-sensitive market data
Risk Level: MediumComplete Code Snippets
From
scripts/akshare_patch.py:193-194:python url = f"http://hq.sinajs.cn/list={symbol}" r = original_get(url, headers={"Referer": "http://finance.sina.com.cn"}, timeout=5)From
scripts/akshare_patch.py:288-289:python url = f"http://hq.sinajs.cn/list={','.join(symbols)}" r = original_get(url, headers={"Referer": "http://finance.sina.com.cn"}, timeout=5)From
scripts/providers/yfinance_provider.py:67-69:python url = f"http://hq.sinajs.cn/list=rt_hk{digits}" req = urllib.request.Request(url, headers={"Referer": "https://finance.sina.com.cn"}) with urllib.request.urlopen(req, timeout=8) as resp:From
scripts/providers/yfinance_provider.py:105-107:python url = f"http://hq.sinajs.cn/list=gb_{clean}" req = urllib.request.Request(url, headers={"Referer": "https://finance.sina.com.cn"}) with urllib.request.urlopen(req, timeout=8) as resp:Technical Analysis
The Skill retrieves integrity-sensitive real-time market data over plaintext HTTP. HTTP does not authenticate the response origin or protect the response body against modification in transit. A network-path attacker can therefore alter Sina quote responses before they reach the Skill.
The affected response fields are parsed as authoritative market information, including security names, current and previous prices, price changes, highs, lows, volume, turnover, and timestamps. The A-share implementation also stores accepted results in the local cache through
cache_db.set_cache, allowing manipulated values to persist until expiration.The HK and US paths are fallback providers. They become reachable when the primary yfinance request doe ...[truncated 1515 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace every
http://hq.sinajs.cnURL with an HTTPS endpoint that provides valid certificate verification. - Do not disable TLS certificate or hostname verification.
- If the provider has no authenticated transport, remove the fallback or treat its response as untrusted and unavailable.
- Before caching or returning fallback data, verify critical fields against an independent provider reached over authenticated HTTPS.
- Record the actual provider and transport used in output metadata so downstream consumers can enforce data-integrity policies.
- Add tests that reject plaintext provider URLs and ensure fallback behavior fails closed when authenticated data cannot be obtained.
- Invalidate previously cached observations whose provenance indicates they were fetched over unauthenticated HTTP.
- Replace every
