Back to skill

Security audit

股票简单查询

Security checks for vulnerabilities and agentic risk

Overview

This stock lookup skill largely does what it claims, but it ships a reusable Finnhub API key and uses overly broad triggers that warrant review before installation.

Review this skill before installing. It appears limited to stock quote lookup, but it makes outbound requests to third-party finance APIs, may activate on broad everyday phrases, and includes a public Finnhub API key that should be removed or replaced with a user-provided environment secret.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
simple_stock.py:71
Finding

Hard-Coded Finnhub API Credential

Content
View full analysis

Vulnerability Details

File Location: simple_stock.py:71-72
Vulnerability Type: Hard-coded API credential
Risk Level: Medium

Vulnerable Code

python
FINNHUB_KEY = 'd6nucg1r01qse5qn5e90d6nucg1r01qse5qn5e9g'
url = f'https://finnhub.io/api/v1/quote?symbol={code.upper()}&token={FINNHUB_KEY}'

Technical Analysis

A reusable Finnhub API token is embedded directly in the distributed source code. Any user who can access the project can retrieve this credential without authentication. The token is also placed in the URL query string, which may expose it through application logs, HTTP client diagnostics, monitoring systems, proxy logs, or request histories.

Although the request uses HTTPS and therefore protects the URL in transit from passive network observers, HTTPS does not prevent disclosure through source distribution or endpoint-side logging.

Attack Path

  1. An attacker downloads or otherwise obtains access to the Skill package.
  2. The attacker opens simple_stock.py and extracts the value assigned to FINNHUB_KEY.
  3. The attacker submits arbitrary requests to the Finnhub API using the exposed token.
  4. The requests consume the token owner's API quota and may cause throttling or service interruption for legitimate users.
  5. If the associated Finnhub account has paid usage or additional API permissions, the attacker may also create billing exposure or access any data authorized to that token.

Impact Assessment

Exploitation does not grant local system privileges or code-execution capabilities. Its scope is limited to the Finnhub account and API permissions associated with the exposed token. Potential consequences include unauthorized API use, quota exhaustion, rate limiting, loss of service availability, and possible billing impact. The exact account-level impact depends on the privileges and subscription attached to the token.

Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed Finnhub token.
  2. Remove the credential from source code and repository history.
  3. Read the token from an environment variable or protected secret store, for example:
    python
    import os
    
    finnhub_key = os.environ.get("FINNHUB_API_KEY")
    if not finnhub_key:
        raise RuntimeError("FINNHUB_API_KEY is not configured")
    
  4. Prevent secret files such as .env from being committed through .gitignore and repository secret-scanning controls.
  5. Use an authorization header instead of a query parameter if supported by the service. If the API requires a query parameter, ensure HTTP diagnostics and proxy logs redact it.
  6. Apply token restrictions, usage limits, and billing alerts where Finnhub supports them.
  7. Add automated secret scanning to the development and release process.

T08 · Insecure Dependencies

Note
Location
README.md:6
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: README.md:6-10
Vulnerability Type: Unpinned dependency resolution
Risk Level: Low

Vulnerable Code

markdown
## 安装

```bash
pip install requests
text

### Technical Analysis

The installation instructions resolve `requests` without specifying a reviewed version or cryptographic hashes. Consequently, the installed package and its transitive dependencies can vary over time and across package indexes. This weakens build reproducibility and allows an unexpectedly compromised or incompatible future release to enter the runtime environment.

The reviewed instructions use the correct package name and do not specify an untrusted package index. Therefore, this is a dependency-integrity hardening issue rather than evidence that a malicious dependency is currently included.

### Attack Path

1. A user follows the documented command in an environment configured to use PyPI or another package index.
2. `pip` resolves whichever eligible version is available at installation time, together with unpinned transitive dependencies.
3. If a resolved release or configured index is compromised, attacker-controlled package installation code may run during installation or malicious code may run when the application imports the package.
4. Such code would execute with the privileges of the user or automation account running `pip` or the application.

This path depends on an external package or package index being compromised; the audited project itself does not demonstrate such a compromise.

### Impact Assessment

In a successful supply-chain compromise, malicious dependency code could obtain the privileges of the process installing or running the application. Depending on that account's access, this could expose local files and environment credentials, alter user-owned data, or execute arbitrary commands. The practical likelihood is reduced because the documented package is the leg
...[truncated 92 chars]
Remediation
View remediation

Remediation Suggestions

  1. Define dependencies in a dedicated requirements or lock file rather than relying only on an installation command in documentation.
  2. Pin requests and all transitive dependencies to reviewed versions.
  3. Generate and verify cryptographic hashes, such as by using a hash-locked requirements file and pip install --require-hashes.
  4. Configure installations to use an approved package index over HTTPS and avoid untrusted extra indexes.
  5. Use automated dependency scanning and regularly update pins after security review.
  6. Perform dependency installation in an isolated virtual environment under a non-privileged account.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill appears to rely on external market data APIs, which implies network access, but it does not declare any explicit tool scope such as permissions or allowed-tools. Undeclared network capability weakens sandboxing and reviewability, making it harder to enforce least privilege and easier for future changes to introduce unexpected outbound requests or data exfiltration paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger set includes highly generic phrases that can overlap with normal conversation, increasing the chance of accidental invocation. Unintended activation can cause unexpected network access, confusing behavior, or disclosure of user-provided text to external services when the user did not intend to use the stock skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module description and all user-facing strings are fixed in Chinese, with no indication that users may choose another language or locale. That creates a natural-language policy concern when the skill is used in broader contexts where language choice should be user-driven.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing documentation is written entirely in Chinese, including headings and usage context, with no indication that other languages are supported or that the Chinese-only presentation is intentional and region-specific. Under the policy for natural-language violations, forcing a specific language without user opt-in should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language description, trigger phrases, tags, and usage examples are all exclusively in Chinese, with no indication that users may interact in another language. This can violate a language/locale policy when the skill implicitly requires a specific language without documenting user choice or regional limitation.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
95% confidence
Finding

The trigger '看看' is extremely short and common in everyday speech, making false activations very likely. In the context of a network-enabled skill, this broad trigger increases the risk of unintended execution and unnecessary outbound requests, even though the direct impact is limited to a stock-query workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code performs external HTTP requests to quote providers, including a U.S. stock query that sends the user-supplied symbol to Finnhub, but there is no user-facing notice that network calls will be made. The surrounding docstrings describe stock lookup generally, yet they do not disclose outbound transmission to third-party services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.