Back to skill

Security audit

tushare股票数据源

Security checks for vulnerabilities and agentic risk

Overview

This stock-data skill does what it claims, but it embeds and silently uses a real Tushare API token.

Review this carefully before installing. The stock lookup behavior is coherent, but the publisher should remove and rotate the embedded Tushare token, require users to provide their own token through a secret or environment variable, and document the outbound Tushare dependency.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
main.py:7
Finding

Hard-Coded Tushare API Token

Content
View full analysis

Vulnerability Details

File Location: main.py, line 7
Vulnerability Type: Hard-coded API credential
Risk Level: High

Vulnerable Code

python
ts.set_token("885cd28a17a52b35e5da6abb8ac11e20e85483affa4c4de8a9e6a928")

Technical Analysis

A reusable Tushare API token is embedded directly in the source code. Anyone who can read the project files, source repository, distributed package, build artifacts, or logs containing this code can recover the credential without authentication.

Because the token is passed to ts.set_token, it is used as the credential for subsequent Tushare API requests. An attacker can copy it into an independent Tushare client and make requests outside the intended skill. The source also lacks a secure runtime secret-loading mechanism.

Attack Path

  1. Obtain read access to the project, repository, package, or another artifact containing main.py.
  2. Read line 7 and extract the embedded token.
  3. Configure a separate Tushare client with the exposed token.
  4. Submit API requests under the token owner's identity until the token is revoked or restricted.
  5. Consume available quota or access any Tushare operations and data authorized for that credential.

Impact Assessment

Exploitation grants the attacker the API privileges associated with the exposed Tushare token; it does not, based on the audited code, directly grant host operating-system privileges. Potential consequences include unauthorized API usage, account or quota abuse, service disruption through quota exhaustion, and access to API functionality available to the token owner. The exact scope depends on the token's server-side permissions and account plan.

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed token immediately; removing it from the current source alone does not invalidate copies.

  2. Remove the token from source code and repository history, including prior commits, release archives, caches, and build artifacts where feasible.

  3. Load the token at runtime from a protected environment variable or secret-management service, for example:

    python
    import os
    import tushare as ts
    
    token = os.environ.get("TUSHARE_TOKEN")
    if not token:
        raise RuntimeError("TUSHARE_TOKEN is not configured")
    
    ts.set_token(token)
    
  4. Ensure secret values are never included in logs, exceptions, return data, documentation, or test fixtures.

  5. Apply least-privilege restrictions and usage limits to the replacement credential where supported.

  6. Add secret scanning to version-control and CI workflows to prevent future credential commits.

  7. Document the external Tushare dependency and secure credential configuration requirement in SKILL.md without including a real token.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill contains a hardcoded Tushare API token directly in source code, which exposes a live credential to anyone who can read, copy, or reuse the skill. This enables unauthorized use of the account, quota theft, possible billing or service abuse, and makes credential rotation difficult once the code has been shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code configures and uses a credentialed token without any user-facing disclosure, which obscures that the skill is operating with external authenticated access. This increases risk because users and operators may not realize the skill depends on a third-party account or that its execution may consume private quotas and interact with external services under stored credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill performs a network request to an external stock-data service based on user input, but there is no disclosure, consent, or policy boundary around that outbound access. In an agent environment, silent external calls can leak usage patterns and input-derived data to third parties and may violate user expectations or platform restrictions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.