Back to skill

Security audit

Akshare Cn Market

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently provides Chinese market and macroeconomic data access through AKShare, with no evidence of hidden control, credential access, persistence, or destructive behavior.

Install this only if you are comfortable with AKShare contacting public finance data providers and with pip resolving current package versions. For safer use, install in a virtual environment, avoid elevated privileges, and pin reviewed dependency versions. Treat outputs as research data, not investment advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-13
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
pip install akshare pandas
# Verify
python3 -c "import akshare; print(akshare.__version__)"

Technical Analysis

The documented installation command retrieves mutable, unpinned versions of akshare, pandas, and their transitive dependencies from the configured Python package index. The project does not provide a dependency lockfile, exact version constraints, or cryptographic hashes.

The subsequent verification command only imports AKShare and prints its reported version. It does not validate the package's integrity, provenance, expected version, or file hashes. Importing a compromised dependency may itself execute attacker-controlled module initialization code.

This creates a supply-chain exposure in which a compromised package release, transitive dependency, or configured package repository could introduce malicious code after the project has been reviewed.

Attack Path

  1. An operator follows the installation instructions in SKILL.md.
  2. pip resolves the latest available versions of the named packages and their transitive dependencies from its configured index.
  3. An attacker compromises an upstream release, one of its dependencies, or the package-index path used by the environment.
  4. pip downloads and installs the attacker-controlled component.
  5. Malicious code executes during package installation or when AKShare is imported by the verification command or project scripts.

Impact Assessment

Malicious dependency code would generally execute with the privileges of the user running pip or the scripts. Depending on that user's permissions and environment, it could read or modify accessible files, access environment variables and credentials, make network requests, tamper with Python packages, or execute arbitrary local commands.

The potential scope ...[truncated 191 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin all direct dependencies to reviewed, exact versions rather than installing unconstrained latest releases.

  2. Generate and commit a lockfile that records all transitive dependencies.

  3. Record cryptographic hashes and enforce them during installation, for example:

    bash
    python3 -m pip install --require-hashes -r requirements.lock
    
  4. Configure an explicit trusted package index or a controlled internal package mirror.

  5. Perform installation inside an isolated virtual environment and avoid running pip with administrator or root privileges.

  6. Add automated dependency vulnerability and provenance scanning to the release process.

  7. Replace the current version-printing check with validation against the expected locked version and package hashes.

  8. Periodically update dependencies through a controlled review process rather than resolving mutable versions during normal installation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code’s implemented behavior is a subset of the declared description. It does correctly provide several declared macro features: GDP, CPI, PMI, M0/M1/M2 money supply, and China-US treasury yields. However, the description also claims A-share market capabilities including individual stock K-line data, market index data, and financial summaries, none of which appear in this code chunk. There are no suspicious undeclared behaviors or extra permissions, but the declared description materially overstates the functionality present in the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code is aligned with part of the description: it uses AKShare and supports individual stock K-line data, index daily data, and financial summaries. However, a substantial portion of the declared functionality—macroeconomic indicators and China/US bond yields—is absent from this code chunk. There are no undeclared risky capabilities or unrelated behaviors; the issue is that the description overstates implemented features. Therefore this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description promises a general A-share行情与宏观经济数据工具 with multiple data-retrieval features across equities, indices, financials, and macro indicators. The supplied code does not implement those functions. Instead, it only loads A-share trading dates from AKShare and exposes CLI commands for checking trade-day status, finding previous/next trade days, and enumerating trade days in a range. This is a materially different and much narrower primary purpose than the declared description, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language strings such as the module docstring, argument descriptions, and help text only in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's user-facing description, help text, and error messages are all presented only in Chinese. Under the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation unless the locale restriction is clearly documented as intentional and region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The module docstring explicitly presents the skill as Chinese-only ("中国宏观经济数据 - 基于 AKShare"), and the command descriptions and output labels are also entirely in Chinese. For a general-purpose skill file, this constitutes a language/locale restriction without an explicit user opt-in or documented policy justification in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code file makes a remote data call via AKShare to fetch Sina Finance trading calendar data, which is a network operation covered by the warning requirement. Although the module docstring mentions AKShare and Sina Finance, there is no explicit runtime notice, confirmation, or comment warning the user that executing the tool contacts an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.