Back to skill

Security audit

Hk Stock Radar

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a Hong Kong market-monitoring purpose, but it should be reviewed because it tells the agent to use a logged-in X/Twitter session and has financial-data reliability issues.

Install only if you are comfortable with the agent making external financial-data and news requests. Do not let it use a personal logged-in X/Twitter session unless you explicitly accept the privacy and account-context risk, and treat the southbound-flow output and plaintext-HTTP sector data as unverified financial signals rather than trading advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/southbound.py:3
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: scripts/southbound.py, lines 3-9
Vulnerability Type: Unpinned third-party dependencies and unsafe supply-chain guidance
Risk Level: Medium

Vulnerable Code Snippet

python
try:
    import akshare as ak
    import pandas as pd
except ImportError as e:
    print(f"Required dependency is missing: pip install akshare ({e})")

The source installation guidance instructs the user to run the following command without specifying a version, package hash, lockfile, or trusted package index:

bash
pip install akshare

Technical Analysis

The script depends on akshare and pandas, but the project contains no dependency lockfile, version constraint, package hash, or reproducible installation manifest. The runtime error guidance recommends installing the latest package selected by the user's configured Python package index.

Python package installation can execute package build and installation logic. An unpinned installation also permits the effective package and transitive dependency set to change after the Skill has been reviewed. This creates a supply-chain exposure if a package release, transitive dependency, package index, or locally configured index mirror is compromised.

This finding does not establish that the current akshare or pandas packages are malicious. The vulnerability is the project's uncontrolled dependency resolution and installation process.

Attack Path

  1. An attacker compromises a future package release, a transitive dependency, or a package index available through the user's pip configuration.
  2. The user runs the displayed pip install akshare command.
  3. Pip resolves the dependency without an approved version or hash.
  4. Malicious build, installation, or import-time code executes with the privileges of the user running pip or the Skill.
  5. The compromised dependency may then access files, environment variables, network resources, and other assets available to th ...[truncated 475 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add a reviewed dependency manifest containing exact versions for all direct and transitive dependencies.
  2. Generate and verify cryptographic hashes for each approved distribution.
  3. Install with hash enforcement, for example:
bash
python -m pip install --require-hashes -r requirements.txt
  1. Document the expected trusted package index and prevent unintended fallback to untrusted indexes or mirrors.
  2. Perform installation in a dedicated virtual environment with minimal operating-system privileges.
  3. Regularly scan locked dependencies for known vulnerabilities and update them through a controlled review process.
  4. Replace the unconstrained runtime installation message with instructions referencing the project's reviewed lockfile.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hk_sector.py:8
Finding

Unauthenticated Financial Market Data Retrieved over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/hk_sector.py, lines 8-19
Vulnerability Type: Plaintext HTTP transport for integrity-sensitive financial data
Risk Level: Medium

Vulnerable Code Snippet

python
url = "http://push2.eastmoney.com/api/qt/clist/get"
params = {
    "pn": 1, "pz": top, "po": 1, "np": 1,
    "fltt": 2, "invt": 2,
    "fid": "f3",
    "fs": "m:1+t:23",
    "fields": "f12,f14,f2,f3,f5,f6,f8"
}
headers = {"Referer": "http://quote.eastmoney.com/"}
r = requests.get(url, params=params, headers=headers, timeout=10)
r.raise_for_status()
diff = r.json()["data"]["diff"]

Technical Analysis

The sector-ranking endpoint uses plaintext HTTP. HTTP provides neither server authentication nor transport integrity, allowing an attacker with a suitable network position to observe or modify the response.

raise_for_status() only validates the HTTP status code. It does not authenticate the server or prove that the response body is genuine. The returned JSON is immediately parsed and later used to display sector names, percentage changes, and turnover values. There is no signature verification, trusted secondary-source comparison, or robust schema and plausibility validation.

Although the request does not appear to contain credentials or private user data, the response contains integrity-sensitive financial information. Consequently, the primary concern is manipulation rather than confidentiality.

Attack Path

  1. The user runs hk_sector.py or invokes it through dashboard.py.
  2. The script sends a plaintext HTTP request to the Eastmoney endpoint.
  3. An attacker controlling or observing a network intermediary, malicious access point, proxy, or compromised routing component intercepts the request.
  4. The attacker returns forged JSON with manipulated sector names, prices, percentage changes, or turnover values.
  5. The script accepts the response because it has a successful status code and syntactically valid JSON.
  6. The m ...[truncated 609 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the endpoint with the provider's supported HTTPS equivalent:
python
url = "https://push2.eastmoney.com/api/qt/clist/get"
  1. Use an HTTPS value for the Referer header when supported.
  2. Keep TLS certificate verification enabled and do not introduce verify=False.
  3. Validate the response content type, JSON structure, required fields, and expected numeric types before processing it.
  4. Enforce reasonable bounds for percentages, prices, and turnover values to reject clearly malformed responses.
  5. For integrity-sensitive use cases, compare critical values with an independent HTTPS-protected market-data source.
  6. Fail closed and clearly report an integrity or validation error rather than displaying incomplete or implausible data.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code only orchestrates execution of three local scripts: hk_index.py, hk_quote.py for four fixed tickers, and hk_sector.py. That aligns partially with a Hong Kong market dashboard, but it does not demonstrate several prominently declared capabilities: sentiment monitoring from Google News RSS or X/Twitter, southbound funds monitoring, or the stated multiple quote data sources. Because the declared description emphasizes a broader行情与舆情监控 tool while this chunk is just a dashboard wrapper for limited market data views, the description is not an accurate representation of this code chunk on its own.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The supplied code is limited to a single function that queries Sina's Hong Kong quote API for three specific indices and computes price change/percentage change. This is only a subset of the declared description. While using Sina Finance is consistent with part of the description, the stated capabilities around Eastmoney, Yahoo Finance, Google News RSS, X/Twitter sentiment monitoring, and southbound-funds monitoring are not present in this code chunk. Because the actual behavior is materially narrower than the declared purpose, this should be flagged as a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a multi-source Hong Kong market and sentiment monitoring tool covering quotes, indexes, southbound flows, and news/social sentiment. The supplied code chunk only implements one narrow capability: querying Sina Finance for explicitly provided Hong Kong stock codes via CLI. While Sina Finance support is indeed present and consistent with part of the description, most of the described functionality is absent in this code: there is no Eastmoney or Yahoo integration, no Google News or X/Twitter monitoring, and no logic for market-wide monitoring or southbound fund tracking. Therefore the description materially overstates the behavior of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description is much broader than the supplied code. This code accesses only one Eastmoney endpoint for Hong Kong industry/sector boards (港股行业板块), sorts by percentage change, and formats a gainers/losers list. It does not fetch Hang Seng Index data, individual HK stock quotes, southbound funds, Sina/Yahoo data, or any sentiment sources such as Google News RSS or X/Twitter. While sector ranking is related to HK market monitoring, the actual behavior of this chunk is materially narrower than the declared purpose, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad Hong Kong stock行情与舆情监控工具 covering multiple data providers and sentiment sources. The supplied code chunk does not implement that scope. It only defines get_southbound(), which retrieves historical southbound/net flow-style data via ak.stock_hsgt_north_net_flow_em() and, on failure, queries a single Eastmoney endpoint. There is no code for HK quotes, Hang Seng Index tracking, news/RSS ingestion, social-media monitoring, or use of Sina/Yahoo APIs. Although '南向资金' is mentioned in the description, the actual code is only a small subset of the declared functionality, making the description materially broader than the code's real behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill includes instructions and sample commands that use both network access and shell execution, but it declares no explicit tool scope or permission boundaries. In an agent environment, this increases the chance of over-broad execution or unintended tool use because the runtime cannot constrain the skill to only the minimal capabilities it actually needs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are extremely broad and overlap with common user market questions, which can cause the skill to activate in contexts where the user did not intend financial scraping, external browsing, or social-media monitoring. Over-broad invocation expands the skill's operational footprint and can lead to unnecessary outbound requests or unintended use of privileged tools.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function is labeled as retrieving southbound capital flow, but the code calls an interface named for northbound net flow and even comments '北向资金'. In a financial-monitoring skill, this data-direction confusion can produce materially wrong analysis or trading signals, causing users to act on inverted market intelligence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to use a logged-in X/Twitter account for monitoring without warning the user that authenticated browsing may expose account context, personalized data, or cause actions to be attributable to that account. In an agent setting, use of a logged-in session materially raises privacy and account-safety risks, especially if the browser tool carries cookies, identity, or elevated access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and user-facing text are entirely in Chinese, including the title and usage description, with no indication that language selection is optional. The policy requires flagging language or locale constraints when a skill forces a specific language without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/dashboard.py (reported line 16)May include surrounding context.

python
print("=" * 50)

print("\n>>> 恒生指数")
subprocess.run([sys.executable, os.path.join(base, "hk_index.py")])

print("\n>>> 港股科技四巨头 (腾讯/阿里/美团/小米)")
subprocess.run([sys.executable, os.path.join(base, "hk_quote.py"),

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/dashboard.py (reported line 19)May include surrounding context.

python
subprocess.run([sys.executable, os.path.join(base, "hk_index.py")])

print("\n>>> 港股科技四巨头 (腾讯/阿里/美团/小米)")
subprocess.run([sys.executable, os.path.join(base, "hk_quote.py"),
                "hk00700", "hk09988", "hk03690", "hk01810"])

print("\n>>> 港股板块涨跌TOP10")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/dashboard.py (reported line 23)May include surrounding context.

python
"hk00700", "hk09988", "hk03690", "hk01810"])

print("\n>>> 港股板块涨跌TOP10")
subprocess.run([sys.executable, os.path.join(base, "hk_sector.py"), "30"])

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and all user-visible output are fixed in Chinese, with no indication that the skill is region-specific or that users can opt into another language. This can violate language/locale policy when a skill imposes a language without explicit user choice or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script makes an outbound HTTP request to a third-party service and includes a Referer header, but there is no comment, docstring detail, or user-facing notice explaining that external network access occurs. For a code file, this is a safety-relevant operation that should be disclosed unless clearly documented as part of the skill's stated behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.