Back to skill

Security audit

cn-hk-dividend-fhpg-api

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only stock dividend data skill with some accuracy and data-integrity caveats, but no hidden execution, persistence, credential use, or destructive behavior.

Install only if you are comfortable using an external stock-data service for public dividend information. Prefer configuring a verified HTTPS API base URL, and treat results as historical reference data rather than investment advice or full financial analysis.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:48
Finding

Plaintext HTTP Endpoint Permits Financial Data Tampering

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 48–49
Vulnerability Type: Insecure plaintext transport configuration
Risk Level: Medium

Vulnerable Code

markdown
> Base URL:`http://vi-money.com/`(需确认是否为实际对外地址;如未确认,调用方必须先核验协议/端口)
> 建议通过环境变量 `STOCK_API_BASE_URL` 覆盖该地址,避免硬编码。

Technical Analysis

The Skill specifies an unauthenticated external REST API over plaintext HTTP as its default data source. HTTP does not provide confidentiality, server authentication, or response integrity. Consequently, a network-positioned attacker could intercept requests and modify API responses before they reach the Agent.

Allowing STOCK_API_BASE_URL to override the endpoint does not secure the default behavior. The documented instructions do not require HTTPS, validate the configured URL scheme, restrict trusted hosts, or authenticate response content.

Although the queried stock information is generally public and requests do not contain documented credentials, integrity remains security-sensitive because the Agent is instructed to use the returned records to produce financial summaries.

Attack Path

  1. A user asks the Agent to analyze A-share or Hong Kong dividend information.
  2. The Skill directs the Agent to request data from http://vi-money.com/.
  3. An attacker with a network interception position, such as a compromised gateway or hostile wireless access point, intercepts the plaintext request.
  4. The attacker returns modified dividend records, yields, dates, company names, or API status fields.
  5. The Agent treats the manipulated response as authoritative and incorporates it into its financial analysis.
  6. The user receives inaccurate or attacker-controlled financial information.

Impact Assessment

Exploitation does not directly grant local code execution, filesystem access, elevated system privileges, or persistence. Its scope is the confidentiality and integrity of requests and resp ...[truncated 371 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the plaintext base URL with an HTTPS endpoint whose certificate is valid and issued for the expected hostname.
  2. Remove the HTTP endpoint as a fallback; fail closed when a secure endpoint is unavailable.
  3. Validate STOCK_API_BASE_URL before use:
    • Require the https scheme.
    • Restrict the hostname to an explicit allowlist.
    • Reject embedded credentials, unexpected ports, URL fragments, and malformed values.
  4. Keep TLS certificate and hostname verification enabled. Do not permit insecure verification bypasses.
  5. Consider authenticating responses or using signed data if the integrity of financial information is especially important.
  6. Clearly identify the external data provider and document its trust boundary, availability expectations, and data-validation requirements.
  7. Validate API response schemas, field types, plausible numeric ranges, and date formats before using returned values in financial analysis.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation claims example outputs can summarize revenue, net profit, ROE, and debt ratio, while other sections explicitly state the skill does not implement financial statement interfaces. This mismatch can cause the agent to fabricate unsupported financial analysis or mislead users into trusting conclusions not grounded in available data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example dialogue is framed as comparing a company's financials and dividends, but the documented implementation only calls the dividend/allotment detail endpoint. This can induce the agent to answer financial-performance questions without supporting data, increasing the risk of hallucinated analysis presented as factual investment information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown instructs the agent to '优先使用中文', which is a natural-language locale preference applied by default. Under the policy, forcing or preferring a specific language without offering user choice can be a locale-policy violation unless clearly opt-in or region-justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.