Back to skill

Security audit

股票全面分析

Security checks for vulnerabilities and agentic risk

Overview

This is broadly a stock-analysis skill, but it overstates its data sources and can produce trading guidance from simulated random prices.

Review this skill carefully before installing or relying on it for financial decisions. Its network access is expected for market data, but its advertised capabilities are overstated, and at least one report path can turn fabricated random data into investment guidance. Treat outputs as informational only, rotate/remove the bundled Finnhub token if publishing or using this code, and require real historical data before trusting technical indicators or recommendations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
analyze_stock.py:93
Finding

Hardcoded Finnhub API Credential Exposed Across Source Files

Content
View full analysis

Vulnerability Details

File Location: analyze_stock.py:93-101
Additional Locations: company_info.py:3-6, jd_logistics.py:4-7, report_v2.py:114-120, stock_analyst.py:39, stock_analyst.py:109-110, test_stock.py:5-9
Vulnerability Type: Hardcoded API credential and credential disclosure through URL query parameters
Risk Level: Medium

Vulnerable Code

python
def get_us_stock(code):
    """获取美股行情"""
    FINNHUB_KEY = 'd6nucg1r01qse5qn5e90d6nucg1r01qse5qn5e9g'
    
    code = code.strip().upper()
    url = f'https://finnhub.io/api/v1/quote?symbol={code}&token={FINNHUB_KEY}'
    
    try:
        r = requests.get(url, timeout=10).json()

The same credential is also embedded in other files. For example:

python
token = 'd6nucg1r01qse5qn5e90d6nucg1r01qse5qn5e9g'

company = requests.get(
    f'https://finnhub.io/api/v1/stock/profile2?symbol=JD&token={token}'
).json()
python
FINNHUB_KEY = os.environ.get(
    'FINNHUB_API_KEY',
    'd6nucg1r01qse5qn5e90d6nucg1r01qse5qn5e9g'
)

Technical Analysis

A reusable Finnhub API token is committed directly to multiple project files. The environment-variable implementation in stock_analyst.py does not resolve the exposure because it falls back to the same public credential whenever FINNHUB_API_KEY is absent.

The credential is also placed in URL query strings. Query strings may be retained by HTTP client diagnostics, reverse proxies, monitoring systems, browser history, or upstream service logs. Although HTTPS protects the request in transit, it does not prevent disclosure through source distribution or URL logging.

Anyone with access to the repository or distributed Skill package can recover and reuse the credential without authentication to the host system.

Attack Path

  1. An attacker downloads, clones, or otherwise obtains the project.
  2. The attacker searches the source tree for ...[truncated 858 chars]
Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed Finnhub token.

  2. Remove every hardcoded copy from:

    • analyze_stock.py
    • company_info.py
    • jd_logistics.py
    • report_v2.py
    • stock_analyst.py
    • test_stock.py
  3. Require the credential through a runtime secret source and fail closed when it is missing:

    python
    import os
    
    FINNHUB_KEY = os.environ.get("FINNHUB_API_KEY")
    if not FINNHUB_KEY:
        raise RuntimeError("FINNHUB_API_KEY is required")
    
  4. Do not retain a default or demonstration credential in production code.

  5. Use an authorization header rather than a query parameter if the service supports it. If Finnhub requires a query parameter, prevent full request URLs from being written to application, proxy, or diagnostic logs.

  6. Add .env and local secret files to .gitignore; provide a .env.example containing only placeholder values.

  7. Enable automated secret scanning in version control and CI.

  8. Review repository history and published artifacts because deleting the token from the latest revision does not remove it from earlier commits or forks.

  9. Apply provider-side rate limits, usage alerts, and any available token restrictions.

T09 · Insecure Skill Coding Practices

Warning
Location
report_v2.py:184
Finding

Fabricated Random Price History Influences Financial Recommendations

Content
View full analysis

Vulnerability Details

File Location: report_v2.py:184-199
Recommendation Logic: report_v2.py:217-275
Vulnerability Type: Untrusted synthetic data used as factual technical analysis
Risk Level: Medium

Vulnerable Code

python
# 3. 技术指标 (模拟数据)
print("\n2. 技术指标")

# 生成模拟历史数据进行计算
# 实际应该调用K线API获取真实历史数据
base_price = data['current']
prices = []
for i in range(30, 0, -1):
    # 模拟一些波动
    import random
    variation = random.uniform(-0.03, 0.03)
    prices.append(base_price * (1 + variation))
prices.append(base_price)

indicators = calculate_indicators(prices)

The resulting indicators subsequently affect the score:

python
rsi = indicators.get('rsi', 50)
if rsi:
    if rsi > 70:
        score -= 10
        rsi_msg = "RSI超买,可能回调"
    elif rsi < 30:
        score += 10
        rsi_msg = "RSI超卖,可能反弹"
    else:
        rsi_msg = "RSI处于中性区间"

The score is then converted into a trading recommendation:

python
if score >= 70:
    recommendation = "建议买入"
    recommendation_reason = "多方力量较强"
elif score >= 50:
    recommendation = "可以持有"
    recommendation_reason = "走势平稳"
elif score >= 30:
    recommendation = "建议观望"
    recommendation_reason = "方向不明"
else:
    recommendation = "注意风险"
    recommendation_reason = "可能面临调整"

Technical Analysis

report_v2.py does not retrieve historical market prices for its technical analysis. Instead, it creates 30 random prices within approximately three percent of the current price and presents indicators calculated from that synthetic series as RSI and moving-average analysis.

These generated values are not labeled in the final recommendation as non-market demonstration data. The calculated RSI affects the aggregate score, and that score determines whether the report recommends buying, holding, observing, or treating the stock as risky.

Because random.uniform() is ...[truncated 1552 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove random price generation from all production report paths.
  2. Retrieve historical OHLC or closing-price candles from a documented market-data provider.
  3. Validate that candles:
    • Belong to the requested symbol and market.
    • Are ordered chronologically.
    • Cover enough sessions for every calculated indicator.
    • Contain valid numeric values.
    • Include a source timestamp and market timezone.
  4. Fail closed when historical data is unavailable. Do not calculate indicators or issue an indicator-derived recommendation.
  5. Clearly distinguish current quotes, historical observations, estimates, and simulations in report output.
  6. If synthetic data must remain for demonstrations or tests, isolate it behind an explicit test flag and prominently label all resulting output as simulated and unsuitable for financial decisions.
  7. Prevent simulated indicators from contributing to production scores or recommendations.
  8. Add deterministic unit tests using fixed historical fixtures and expected RSI and moving-average outputs.
  9. Record the data source, candle interval, observation period, and calculation method in every generated report.
  10. Add a financial-risk disclaimer, while recognizing that a disclaimer is not a substitute for removing fabricated analytical inputs.
Vulnerability Patterns
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (67)

Tainted flow: 'url' from os.environ.get (line 109, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · stock_analyst.py (reported line 60)May include surrounding context.

python
for hk_code in [f'hk{code}', f'hk0{code}', f'hk00{code}']:
        try:
            url = f'https://qt.gtimg.cn/q={hk_code}'
            r = requests.get(url, timeout=8)
            text = r.text.strip()
            
            if 'none_match' in text:

Tainted flow: 'url' from os.environ.get (line 109, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The request embeds FINNHUB_KEY directly into the URL query string, causing the API token to be transmitted in a way that is more likely to be exposed via logs, proxies, monitoring systems, exception traces, or upstream telemetry. Even though sending a token to the intended API is expected, placing secrets in URLs increases accidental disclosure risk compared with safer header-based authentication.

Content

Scanner excerpt · stock_analyst.py (reported line 110)May include surrounding context.

python
try:
        url = f'https://finnhub.io/api/v1/quote?symbol={code}&token={FINNHUB_KEY}'
        r = requests.get(url, timeout=10).json()
        
        if r.get('c'):  # current price
            return {

Tainted flow: 'url' from os.environ.get (line 109, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · stock_analyst.py (reported line 134)May include surrounding context.

python
"""获取财经新闻"""
    try:
        url = 'https://ai.6551.io/open/free_hot?category=macro'
        r = requests.get(url, timeout=15)
        data = r.json()
        
        if data.get('success'):

Tainted flow: 'headers' from os.environ.get (line 9, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · test_longbridge.py (reported line 20)May include surrounding context.

python
for sym in symbols:
    url = f'https://api.longbridgeapp.com/v1/quote/quotes?symbol={sym}'
    try:
        r = requests.get(url, headers=headers, timeout=10)
        print(f"=== {sym} ===")
        print(r.status_code)
        print(r.text[:500])

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The primary domain is consistent—this is indeed a stock analysis tool covering A股/港股/美股. However, the declared description materially overstates and misstates how it works. Most notably, it does not use Futu as the data source at all; instead it queries Tencent for A/HK quotes and Finnhub for US quotes. It also does not implement a robust 'comprehensive report(7大板块)' or meaningful technical indicator suite; the output is a basic printed report with simple calculations from a single quote snapshot. There are no obvious unrelated or dangerous undeclared capabilities beyond external market-data access, but the description does not accurately represent the actual data sources and depth of analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description promises a broad stock analysis tool covering multiple markets (HK/U.S./A-shares), specifically mentioning Futu as the data source and a comprehensive seven-part report. The actual code is much narrower: it calls Finnhub endpoints, not Futu; it is hardcoded to JD; and it only outputs company info, a basic 30-day price summary with MA5/MA20 crossover, and analyst recommendations. While this is related to stock analysis and includes some technical indicators, it materially underdelivers on the declared scope and uses an inconsistent resource, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a broad stock-analysis capability across multiple markets with Futu as the data source, technical indicators, and a structured comprehensive report. The supplied code does none of that: it is a narrow debugging utility that requests one fixed Hong Kong ticker from a Tencent quote API, prints raw data, and parses fields for inspection. This is a materially different primary purpose and uses an inconsistent external resource, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a full-featured stock analysis capability covering HK/U.S./A-share markets, based on Futu data and technical indicators, with broad stock-analysis triggers. The supplied code does none of that. It only requests technology hot news from https://ai.6551.io/open/free_hot?category=tech and prints the result. This is a materially different primary purpose and uses a resource inconsistent with the declared stock-analysis function. Therefore, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a broad, feature-rich stock analysis tool covering HK/US/A-share markets, using a specific data source (Futu), technical indicators, and a structured comprehensive report. The actual code only retrieves simple real-time quote fields for one hardcoded Hong Kong stock plus several preset Hong Kong peers via qt.gtimg.cn, then prints basic market stats. There is no evidence of user input handling, multi-market support, technical analysis, report composition, holdings analysis, or use of the declared Futu source. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a full-featured stock analysis capability across multiple markets (HK/US/A), specifically mentioning Futu as the data source, technical indicators, and a comprehensive report. The provided code does none of that. Instead, it performs narrow debugging/testing behavior: it queries Tencent's quote API with several hardcoded HK stock code variants and calls Eastmoney's suggestion API to search for the term '京东物流'. This is materially different in primary purpose and resource usage from the declared functionality. While remote market-data access is broadly related to stocks, the actual code is only a code-format/search experiment, not a stock analysis engine.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a full-featured stock analysis capability across multiple markets, based on Futu data, with technical indicators and a multi-section report. The supplied code does none of that. It only probes several possible Tencent-format ticker codes for a single stock name and prints raw response snippets. This is a materially different primary purpose and uses an inconsistent external resource versus the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose promises a full-featured stock analysis skill covering multiple markets (HK/US/A-shares), technical indicators, and a comprehensive report. The provided code chunk is much narrower: it normalizes a Hong Kong stock code, builds a Futu URL, prints instructions for the user to visit the page, and contains a simple text parser for a price and percentage change. No actual data fetching, no multi-market support, no technical analysis, and no report generation are present. The primary purpose of the code is effectively a Hong Kong Futu URL helper, not a comprehensive stock analysis engine.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a broad, comprehensive stock analysis tool covering Hong Kong, U.S., and A-share markets, specifically using a Futu data source, technical indicators, and a structured 7-part report. The supplied code does not implement those capabilities. It only retrieves quote data from Tencent Finance for five hardcoded Hong Kong symbols and prints basic market fields plus a simple intraday change calculation. This is a materially narrower and different behavior than the declared purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a broad, reusable stock analysis capability across Hong Kong, U.S., and A-share markets, specifically using 富途/Futu data, technical indicators, and a comprehensive multi-section report. The supplied code does something much narrower: it queries Finnhub endpoints for quote, company profile, and recommendation data for a single hardcoded Hong Kong ticker and prints the results. While the general domain is still stock information, the primary behavior is materially less comprehensive and relies on a different data source than declared. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a broad stock analysis skill covering multiple markets, Futu data integration, technical indicators, and a structured comprehensive report. The code instead performs a very limited task: it retrieves tech news from an external news endpoint, filters for JD Logistics-related articles, and prints hardcoded company background for a single Hong Kong stock. It does not analyze stock prices, holdings, technical indicators, or generate any 7-part report, and it explicitly states that real-time HK quote data cannot be obtained. This is a material purpose and capability mismatch, not merely an implementation detail difference.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is broadly aligned with the declared stock-analysis purpose: it analyzes A-shares, Hong Kong stocks, and U.S. stocks, includes quote data, technical indicators, news, and a synthesized recommendation. However, there are material description/behavior mismatches. Most notably, the declared description explicitly claims a Futu data source, but the code actually calls Tencent quote APIs for A/HK stocks and Finnhub for U.S. stocks. Also, the technical indicator portion is not based on real historical market/K-line data; it uses randomly generated simulated prices, which materially weakens the claimed analytical capability. Finally, the description promises a 7-section comprehensive report, while the code prints only 5 numbered sections. These are significant enough to classify as a mismatch, even though the overall domain and high-level purpose are similar.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The declared description overstates and misrepresents the implementation. The code does perform stock analysis-related behavior, so it is in the same general domain, but several material details do not match: there is no A-share support, no Futu data source, no evidence of a structured 7-part comprehensive report, and no portfolio/holding analysis. The implemented behavior is limited to fetching a single HK or US stock's quote, computing simple same-day metrics, and showing general macro news.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a full-featured stock analysis tool covering multiple markets, relying on Futu data, technical indicators, and a structured report. The provided code does none of that: it is only a connectivity/data-fetch test for a single hardcoded symbol, querying Tencent and Sina finance APIs and printing raw responses. This is a materially different primary purpose and uses inconsistent resources versus the description, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a broad stock analysis capability with Futu as the data source, technical indicators, and a structured comprehensive report across multiple markets. The supplied code does not perform analysis at all; it is a narrow diagnostic/test script that calls the Longbridge quote API for several fixed HK symbols and prints raw responses. This is a materially different primary purpose and uses an inconsistent resource provider. The token-based API access and hardcoded symbol testing are not merely implementation details; they show the code is a connectivity/quote retrieval test rather than the described analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a broad, comprehensive stock-analysis skill with Futu as the data source, support for Hong Kong/US/A-share markets, technical indicators, and a structured multi-section report. The supplied code only performs two simple HTTP GET requests: one to Finnhub for a quote on a hardcoded ticker (JD) and one to a macro-news endpoint, then prints a few fields. This is a materially narrower and different behavior than declared. The triggers are broadly stock-related, but the code itself does not implement general user-driven stock analysis functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a full-featured stock analysis tool covering multiple markets (Hong Kong, US, A-shares), using Futu as the data source, technical indicators, and a structured comprehensive report. The supplied code does something much narrower: it is a test script that fetches raw quote data from Tencent Finance for a few predefined Hong Kong tickers and prints truncated responses. There is no evidence of Futu integration, no technical analysis, no report generation, and no support for US or A-share markets. This is a material description-behavior mismatch in both primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The description promises a broad stock-analysis capability across multiple markets with a specific data source (Futu), technical indicators, and a comprehensive report. The supplied code only covers a narrow technical-analysis module: RSI, moving averages, EMA, and a simplified MACD, followed by simple heuristic commentary. Although there is a get_kline_data function, it does not actually fetch usable historical price series and instead returns None; it also points to a Tencent endpoint rather than Futu. There is no evidence here of portfolio/holding analysis, market-wide quote handling beyond symbol formatting, or generation of a 7-part comprehensive report. Therefore the code behavior materially underdelivers relative to the declared description, making this a mismatch.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a broad stock-analysis skill covering HK/US/A-shares, Futu data, technical indicators, and a 7-section comprehensive report. This file only retrieves a generic tech-news feed, filters for JD Logistics mentions, and prints fixed descriptive text about one stock without any market analysis, technical indicators, or comprehensive reporting behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code and comments indicate historical prices should be used for technical indicators, but the implementation instead relies on simulated/random prices. Because the resulting indicators are then presented as if they were meaningful analysis, users may treat fabricated signals as real market insight, which is especially dangerous in an investment-advice workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section explicitly generates random price variations and feeds them into indicator calculations that later influence investor-facing recommendations such as buy/hold/watch. Producing actionable financial guidance from fabricated data is a serious integrity flaw that can directly mislead users into harmful trading decisions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.