Back to skill

Security audit

Position Risk Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed stock position-risk advisory tool with optional market-price lookup, but users should treat its trading guidance as educational and be careful with the unpinned dependency install suggestion.

Install only if you are comfortable using a Chinese-language stock risk-management helper that may give concrete buy/sell percentage and price suggestions. Do not treat its output as personalized financial advice, verify any market data independently, and install optional Python dependencies in a virtual environment with reviewed or pinned versions rather than blindly running the upgrade command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/position_calculator.py:14
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis

Vulnerability Details

File Location: scripts/position_calculator.py, lines 14-19
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: Medium

Vulnerable Code

python
try:
    import akshare as ak
    HAS_AKSHARE = True
except ImportError:
    HAS_AKSHARE = False
    print("⚠️ AKShare 未安装,请运行:pip3 install akshare pandas -U")

Technical Analysis

When AKShare is unavailable, the script instructs the user to install or upgrade akshare and pandas from the configured Python package index. The command uses neither exact version constraints nor package hashes:

bash
pip3 install akshare pandas -U

The -U option requests the latest available releases. Consequently, the installed artifacts and transitive dependency versions may change after the project has been audited. No lockfile, hash-verified requirements file, or trusted index configuration is included to provide reproducible dependency resolution.

Python package installation can execute package build logic under the privileges of the user running pip. Imported package code subsequently runs with the privileges of the Python process. A compromised upstream release, compromised transitive dependency, or unsafe package source could therefore result in arbitrary local code execution.

This is supply-chain exposure rather than evidence that the named packages are currently malicious.

Attack Path

  1. The user runs the script in an environment where akshare is not installed.
  2. The import fails, and the script displays the unpinned installation command.
  3. The user executes pip3 install akshare pandas -U.
  4. The configured package index resolves mutable latest releases and their transitive dependencies.
  5. If an upstream artifact, dependency, or configured package source has been compromised, malicious build or installation logic executes with the user's privileges.
  6. Malicious runtime code may also execute when the script later impo ...[truncated 588 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a dependency manifest containing reviewed, exact versions of all direct dependencies.

  2. Generate and commit a lockfile that also fixes transitive dependency versions.

  3. Record package hashes and require hash verification during installation, for example:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  4. Remove -U from user-facing installation guidance so normal execution does not implicitly request unreviewed upgrades.

  5. Use a dedicated virtual environment and install packages without administrative privileges.

  6. Configure an approved package index or an internally controlled artifact mirror.

  7. Add automated dependency vulnerability and integrity scanning to the release process.

  8. Periodically update dependencies through a controlled review process, regenerate hashes, and test the resulting locked environment before release.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is entirely written as Chinese-only user-facing guidance and presents itself as the operative description of the skill without any indication that other languages are supported. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all operational guidance in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. The policy explicitly calls for flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file provides explicit trading psychology and behavior-shaping guidance that can materially influence users' financial decisions, but it contains no disclaimer that the content is educational only and not personalized financial advice. In the context of a position-risk-management skill, the content is especially likely to be acted upon during stressful gain/loss situations, increasing the risk of user harm from overreliance on the guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire document is written in Chinese and does not indicate that the language is optional, selectable, or limited to a justified region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code presents the skill as a Chinese-only expert and all user-facing descriptions, prompts, and output are written in Chinese. The file does not offer opt-in language selection or state that the skill is intentionally limited to a Chinese-speaking or region-specific context, which matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The broader skill context says the skill is not responsible for stock selection and focuses on position management, rebalancing, and risk-control advice. In _meta.json, the description adds implementation-level capabilities ('支持 AKShare 获取股价,缓存机制') that extend beyond pure advisory scope into market-data acquisition and stateful caching behavior, which are not part of the stated user-facing purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest emphasizes providing仓位管理、止盈/止损、调仓和风控建议 for existing holdings, and does not mention external行情抓取 as part of the skill's behavior. The code adds a concrete external data acquisition path via AKShare, which expands behavior beyond purely analyzing user-supplied position inputs, even though it remains related to the domain.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.