Back to skill

Security audit

A股模拟交易

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a coherent A-share paper-trading skill, but it has a real market-data integrity concern because a plaintext fallback feed can affect simulated fills and ledger records.

Install only if you are comfortable with a local paper-trading tool that writes a persistent SQLite ledger and fetches live China A-share data. Treat simulated fills and portfolio values as advisory, because one fallback quote path uses unencrypted HTTP and could be tampered with on the network; do not use its results as the sole basis for real-money trading decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/simtrade_core/market_data.py:72
Finding

Unauthenticated HTTP Order-Book Data Can Manipulate Simulated Trade Execution

Content
View full analysis

Vulnerability Details

File Location: scripts/simtrade_core/market_data.py:72-76
Vulnerability Type: Unauthenticated plaintext transport for execution-critical market data
Risk Level: Medium

python
response = requests.get(
    f"http://hq.sinajs.cn/list={symbol}",
    headers={"Referer": "http://finance.sina.com.cn"},
    timeout=5,
)

The affected request is used by the Sina fallback to obtain a five-level order book. That order book can subsequently determine simulated fill prices and quantities.

Technical Analysis

The fallback obtains market data over plaintext HTTP, which provides neither server authentication nor transport integrity. An attacker capable of intercepting or modifying network traffic can therefore alter the response.

The implementation compares Sina data with East Money using the security name, previous close, timestamp, and last price. However, it does not authenticate or independently compare the bid and ask levels. The schema validation only establishes that each order-book level has a positive price and quantity and that no side contains more than five levels.

The accepted bid and ask levels are consumed by the matching engine in scripts/simtrade_core/service.py:388-402, where they directly determine executable prices and fill quantities. Consequently, the cross-provider checks do not prevent a response from preserving validated metadata while supplying manipulated order-book levels.

Attack Path

  1. East Money reports a normal trading security but omits its order book, causing the Sina fallback to execute.
  2. An on-path attacker intercepts the plaintext request to hq.sinajs.cn.
  3. The attacker returns a syntactically valid response containing the expected symbol, security name, previous close, a current timestamp, and a last price within the permitted tolerance.
  4. The attacker substitutes chosen bid or ask prices and quantities that still satisfy the basic po ...[truncated 814 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the plaintext endpoint with an HTTPS endpoint that performs standard certificate and hostname verification.
  2. If Sina cannot provide authenticated transport, remove this fallback from execution-critical workflows and fail closed when East Money lacks an order book.
  3. Alternatively, obtain bid and ask levels from another independently authenticated provider and require cross-provider consistency before matching.
  4. Validate that bid and ask levels are correctly ordered, do not form an invalid spread, remain within authenticated daily price limits, and are reasonably consistent with the authenticated last price.
  5. Keep metadata comparison, but extend integrity checks to every execution-critical field, particularly order-book prices and quantities.
  6. Add tests that inject a response with valid metadata but manipulated book levels and verify that matching is rejected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is a deterministic paper-trading CLI, but the underlying behavior reportedly performs global monkey-patching of HTTP request handling and modifies AKShare request/retry functions across loaded modules. That creates hidden, process-wide side effects: other skills or components in the same runtime could have their network behavior altered, enabling data exfiltration, policy bypass, or integrity issues in unrelated operations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill declares no explicit tool or permission scope even though its behavior requires environment access, file reads, and network access. This weakens containment and reviewability: an agent may grant broader capabilities than users expect, increasing the risk of unintended data access or external communication during simulated trading operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description and scope explicitly constrain the skill to 'A股专用' and present all user-facing guidance in Chinese, without stating that this is an opt-in locale- or language-specific skill. Under the policy, forcing a specific language or locale without user choice can be a natural-language policy violation unless the constraint is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code forces the trading system to use "Asia/Shanghai" via a fixed timezone constant, which is a natural-language locale policy constraint embedded in code behavior. There is no visible option for the user to choose a different locale/time zone or any justification in this file that the skill is intentionally region-locked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The fallback quote fetch uses plain HTTP to Sina, so quote data and headers can be intercepted or modified by a network attacker. In a trading simulation skill, tampered market data can directly affect simulated order matching, account state, and audit records, making this more than a cosmetic transport issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code uses user-facing validation messages exclusively in Chinese, such as '必须是有效数字' and related error text, without indicating that the skill is China- or Chinese-locale-specific or offering a language choice. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code presents user-facing error messages exclusively in Chinese, such as the validation exceptions at L23 and L35. The policy allows locale-specific behavior only when the constraint is documented and justified or when users can opt in, neither of which is evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The validation exceptions in this block use only Chinese-language messages for quantity and price failures. In the absence of any opt-in, localization mechanism, or documented regional justification in this file, this appears to force a specific language on users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The error strings appended to issues and the final exception message are all Chinese-language strings. Because no language choice or explicit documented regional scope appears in this file, these natural-language messages violate the stated language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code fixes all time handling to Asia/Shanghai, which imposes a specific locale and trading-time interpretation on all consumers of the service. Under the policy, forcing a specific language or locale without user choice or clearly documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

TZ is fixed to Asia/Shanghai, which imposes a locale-specific behavior for time handling. Under the language/locale policy, forcing a specific locale without user opt-in or clear justification is a natural-language policy concern, especially since no comment or documentation explains why this regional constraint is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The DataUnavailable exception messages are written only in Chinese, which enforces a specific language for user-visible output. This is a language-policy issue unless the skill explicitly documents that it is Chinese-only or provides user opt-in for the locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The text explicitly requires use of Asia/Shanghai for placement and processing. Under the policy, forcing a locale/timezone is a natural-language policy concern unless the constraint is clearly documented and justified as region-specific; this line states the requirement but does not explain that justification in-policy or offer any opt-in/choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code creates parent directories and opens/initializes a SQLite database, which can modify the local filesystem. In this file there is no confirmation prompt, user-facing log/print, or explanatory comment/docstring disclosing that storage will be created and schema applied.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The exception message is written only in Chinese, which may force a specific language on users regardless of their preferences. The file does not indicate that this skill is intentionally region- or locale-specific, nor does it provide user opt-in or localization alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Several user-visible exception messages in this file are hardcoded in Chinese, while others are in English, which imposes a locale choice without any user opt-in or documented justification. This can violate language/locale policy when the skill is expected to serve users in different locales.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The trade-date retrieval path raises multiple hardcoded Chinese error messages, which are natural-language outputs visible to users or calling layers. Without explicit locale selection or documentation that this skill is region/language-specific, this is a language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The refresh method calls fetch_trade_dates() and then writes the returned data into the trading_calendar table, but the code provides no confirmation prompt, log message, or inline warning about these side effects. Because this combines network/data retrieval with persistent state changes, some form of visible disclosure would improve safety and transparency.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code fixes the timezone to Asia/Shanghai and later uses Chinese-language values such as the account name and security name, which reflects a specific language/locale assumption. Under the policy, locale-specific behavior should be optional or clearly justified; this test file does not document any such opt-in or regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.