Back to skill

Security audit

Akshare Router Cn

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-market AKShare router that fetches public futures and options market data and computes simple indicators without hidden persistence or sensitive data access.

Install this only if you want an agent to answer Chinese-market futures and options questions using AKShare public data sources. Expect network requests to upstream market-data providers for the contracts, symbols, and dates you ask about, and verify financial calculations before using them for trading decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (16)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language content describing the skill is presented exclusively in Chinese, which effectively forces a specific language for users reading the skill documentation. The policy allows locale constraints only when user choice is offered or when the restriction is clearly documented and justified; neither is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The phrase "面向中文用户" states that the skill is intended for Chinese users, which is a natural-language locale/language restriction. The file does not indicate that users may choose another language or opt in to this constraint, so it appears to force a language/locale preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README content describing the skill is presented exclusively in Chinese, with no indication that users may choose another language or that the locale is required for a region-specific purpose. This can violate organizational language policy when a skill forces a specific language implicitly through its documentation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The keyword lists include broad triggers such as '最新', '当前', '历史', '从', and '到', which are likely to appear in ordinary financial conversation and can cause unintended routing or slot filling. In a routing map, this can let unrelated user input be misclassified as market-data or backtest intent, increasing the chance of wrong tool invocation, over-collection of parameters, or confusing downstream behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The fallback guidance allows route selection based on loose keywords like 'current/latest/intraday' and broad contract-shape heuristics when key attributes are missing. That can cause the system to misclassify user intent and invoke the wrong recipe, which is a security-relevant prompt-routing flaw if downstream recipes expose different tools, computations, or data scopes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's substantive instruction text is written in Chinese, which imposes a language/locale constraint on users and implementers without offering an alternative or opt-in. Under the policy, language-specific behavior should either provide user choice or clearly document a justified region-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill content is entirely written in Chinese and does not indicate that other languages are supported or that the user can opt into this locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's operational instructions and descriptions are written entirely in Chinese, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-language or region-specific audience. Under the policy, mandating a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The recipe’s headings, instructions, and examples are all presented in Chinese, which can amount to a language/locale constraint for users consuming the skill. The file does not indicate that the skill is intended only for a Chinese-language audience or offer any user opt-in or alternative language handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The recipe is written entirely in Chinese and frames all user interactions, examples, and outputs around Chinese-language usage, but it does not state that the skill is region-specific or offer any language/locale opt-in. Under the policy, forcing a specific language without user choice or clear justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content from the problem description through the operational notes is presented only in Chinese. This can violate language/locale policy when a skill implicitly forces a specific language without documenting user choice or a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all operational descriptions and guidance in Chinese, which effectively forces a specific language for users reading the skill references. The file does not indicate that language selection is optional or that the skill is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The comments describe the keyword normalization as Chinese-specific (“中文关键词归一化”), which signals a language constraint but does not mention user selection, fallback behavior, or a justified region-specific limitation. Under the policy, forcing a specific language without opt-in can be a natural-language policy issue unless clearly documented as intentionally locale-scoped.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file’s natural-language comments are written entirely in Chinese and present the routing rules as the authoritative source without offering any language or locale choice. This can be interpreted as a language policy constraint if the skill is expected to support broader organizational language preferences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's instructional content and field mappings are entirely specified in Chinese, including required field names and output expectations, with no indication that the user can choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script fetches futures data from an external service via ak.futures_zh_minute_sina(...), which is a network operation, but there is no confirmation prompt, logging, or explanatory comment/docstring disclosing that external data will be requested. For a code file, this matches the missing-warning criterion for network/HTTP calls that transmit request data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.