T09 · Insecure Skill Coding Practices
- Location
function.py:38- Finding
Remote MySQL Connection Does Not Enforce TLS or Server Authentication
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This finance-analysis skill mostly matches its stated purpose, but it needs review because it handles remote database and proxy credentials with weak safeguards.
Install only after review. Use a dedicated, least-privilege database password that is not shared with production systems, avoid running it with proxy environment variables that contain credentials, and treat returned financial/news analysis as third-party data for reference rather than verified investment advice.
function.py:38Remote MySQL Connection Does Not Enforce TLS or Server Authentication
function.py:209Credential-Bearing Proxy Environment Variables Are Written to Logs
function.py:127Remote Database Value Is Interpolated as an Unvalidated SQL Identifier
The skill description understates the breadth of behavior: beyond strategy lookup it indicates external data scraping/search, news sentiment collection, prospectus analysis, investment recommendation generation, and credential-backed remote database access. This mismatch is dangerous because reviewers or users may authorize the skill for a narrower purpose while it actually performs broader external communications and sensitive-data handling.
The skill advertises capabilities that imply reading environment variables and likely local files/configuration, but it does not declare an explicit tool scope or permission boundary. In an agent environment, missing scope declarations can cause users and orchestrators to underestimate what the skill may access, increasing the risk of unintended secret access or data exposure.
The skill requires a database password for a remote MySQL server and names the host, user, and database, but does not prominently warn that the credential is sensitive or that it will be transmitted to an external service. In this context, the skill is explicitly built around remote access, so insufficient disclosure raises the risk of secret misuse, accidental credential sharing, or users supplying production credentials without understanding the exposure.
The manifest describes a strategy search and stock analysis skill connected to a remote strategy database, which justifies database access, but this code also pulls a password from the process environment via DB_PASSWORD. Accessing runtime environment secrets is a broader capability than ordinary search/analysis behavior and is not stated in the manifest description.
The skill fetches and returns third-party news content and URLs from external services without any disclosure, trust labeling, or sanitization boundary. In an agent setting, this can expose users to untrusted remote content, misinformation, or prompt-injection-laden text that may later be consumed by downstream LLM components as if it were trusted data.
The class and method documentation repeatedly describe a '招股说明书分析引擎' and '招股说明书/上市分析', implying analysis of prospectus content. In practice, the implementation fetches listing metadata via AKShare, performs a web search for related news, and repackages existing financial-analysis output; it does not retrieve or parse any prospectus document or PDF.
The skill's interactive questions are presented only in Chinese, and the rest of the file contains many hard-coded Chinese user-facing messages and labels. There is no mechanism for language selection or documented justification that the skill is intentionally limited to Chinese-speaking users.
The pipeline logs raw user input verbatim, which can capture sensitive investment preferences, identifiers, or other private data without notice or minimization. If logs are retained, shared, or centrally aggregated, this becomes a privacy and data-handling risk that may expose user queries beyond their expected audience.
All headings, instructions, output labels, and user interaction templates are written exclusively in Chinese, which effectively constrains the skill to a specific language. The file does not provide any opt-in, fallback, or multilingual alternative, and no region-specific justification is stated.
The manifest promises quantitative strategy search and deep individual-stock analysis, but this module adds a distinct 'Prospectus Analyzer' focused on IPO/prospectus and listing-history interpretation. That is adjacent to equity analysis, but it is a separate analytic domain not reflected in the manifest description.
The dependency is specified with a lower bound only, so builds may resolve to different versions over time. This weakens supply-chain control and makes it harder to ensure vulnerable or incompatible releases are excluded, especially for a skill that connects to remote databases and external data sources.
pymysql>=1.1.0
akshare>=1.14.0
baostock>=0.8.8
requests>=2.31.0
PyMySQL has known advisories, and because the manifest does not pin a version, there is no assurance that deployed environments will avoid affected releases. In a skill described as connecting to remote strategy databases, a potentially vulnerable database client increases concern because database interaction is central to the skill's operation.
Using an unpinned akshare version allows future installs to pull arbitrary newer releases, reducing reproducibility and increasing supply-chain risk. In a financial-analysis skill that depends on remote data behavior, unexpected package changes can affect integrity and security assumptions.
pymysql>=1.1.0
akshare>=1.14.0
baostock>=0.8.8
requests>=2.31.0
pydantic>=2.5.0
The baostock dependency is not pinned, so deployments may silently install different versions over time. This creates avoidable supply-chain exposure and makes security review and incident response harder because the effective installed version is not deterministic.
pymysql>=1.1.0
akshare>=1.14.0
baostock>=0.8.8
requests>=2.31.0
pydantic>=2.5.0
pyyaml>=6.0
Requests is a network-facing library with a long advisory history, and specifying only a minimum version leaves room for installs of versions with different security properties. In a skill that connects to remote services, this raises practical risk because HTTP behavior directly affects transport security, redirects, auth handling, and data exposure.
pymysql>=1.1.0
akshare>=1.14.0
baostock>=0.8.8
requests>=2.31.0
pydantic>=2.5.0
pyyaml>=6.0
Requests has multiple known advisories, and the absence of version pinning makes the dependency's security posture unverifiable at install time. Because this skill communicates with remote services, a vulnerable HTTP client could contribute to credential leakage, transport-security bypasses, or mishandling of attacker-controlled URLs.
Pydantic is unpinned, so dependency resolution may select changing versions with different validation behavior or disclosed flaws. While not inherently exploitable from this file alone, the lack of version control increases operational and security uncertainty.
akshare>=1.14.0
baostock>=0.8.8
requests>=2.31.0
pydantic>=2.5.0
pyyaml>=6.0
Pydantic has published advisories, and without pinning there is no reliable way to know whether an affected version will be installed. This is primarily a supply-chain assurance problem here, though it could become more significant if untrusted input is heavily validated by the application.
PyYAML has a notable history of unsafe deserialization issues, and an unpinned requirement makes it unclear which release will actually be installed. Given the skill may ingest configuration or remote content, package-version ambiguity makes this dependency more dangerous than a purely local utility.
baostock>=0.8.8
requests>=2.31.0
pydantic>=2.5.0
pyyaml>=6.0
PyYAML has several well-known security advisories, including unsafe parsing concerns, and the unpinned manifest leaves the deployed version unknown. In a data-driven agent skill, that uncertainty materially increases risk if YAML is used anywhere for configuration or remote content handling.
No suspicious patterns detected.