T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_stock_data.py:13- Finding
Undocumented hard-coded proxy redirects process-wide network traffic
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stock-report purpose, but it silently forces network traffic through an undocumented hard-coded proxy while handling external market-data requests and a Tushare token.
Review before installing. The core functionality is coherent, but remove or explicitly configure the hard-coded proxy before running it, pin dependencies or use a skill-specific environment, and avoid entering sensitive portfolio details unless you are comfortable sending ticker-related requests to Yahoo Finance or Tushare.
scripts/fetch_stock_data.py:13Undocumented hard-coded proxy redirects process-wide network traffic
SKILL.md:33Open-ended dependency versions permit installation of unreviewed releases
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The code generally aligns with the data-source portion of the description: it supports US/HK via Yahoo Finance and CN via Tushare, and accepts stock tickers like PDD/KC. However, the declared purpose emphasizes automatic generation of a structured Markdown deep financial analysis report, while this code chunk is only a data-fetching module. It retrieves info, historical prices, and some financial statement or indicator data, then prints serialized data. There is no report construction, Markdown formatting, or analysis logic. Additionally, the CN/Tushare implementation fetches basic info, financial indicators, and daily prices, but not full financial statements in the same way the description suggests. Therefore the description materially overstates what this code chunk actually does.
The skill declares use of environment variables, including a TUSHARE_TOKEN, but does not define any explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can lead to broader-than-necessary access to secrets or runtime capabilities, increasing the chance of accidental secret exposure or unauthorized external use.
Overly broad triggers such as generic stock-analysis phrases can cause the skill to activate in unintended contexts, leading to unsolicited external requests or processing of user data. In an agent environment, ambiguous activation increases the risk of misuse, accidental invocation, and surprise transmission of queried tickers or portfolio-related inputs to third-party providers.
The module unconditionally sets global HTTP_PROXY and HTTPS_PROXY environment variables for the entire process, affecting all subsequent network traffic made by this skill and any imported libraries. In the context of a data-fetching tool, this can silently reroute requests through an unexpected proxy, exposing market queries, authentication headers, or future requests to interception or manipulation if the proxy is untrusted or misconfigured.
This codebase presents its purpose, CLI description, and generated report content in Chinese only, including the main docstring and all report sections. The policy requires flagging language or locale constraints when a skill forces a specific language without explicit user opt-in or choice.
The script unconditionally sets global HTTP_PROXY and HTTPS_PROXY environment variables to a hard-coded internal proxy address, affecting all subsequent network traffic in the process. This can silently redirect stock data requests and any other HTTP(S) communications through an unrelated intermediary, enabling traffic inspection, manipulation, data leakage, or unexpected outbound routing that is not necessary for report generation.
The skill sends stock queries to Yahoo Finance or Tushare but does not prominently warn users that their requested tickers or holding-related inputs may be transmitted to external services. This is a privacy and transparency issue that becomes more relevant when users provide portfolio cost basis or market-specific identifiers tied to their investments.
This markdown file presents all instructions and evaluation guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy concern.
The top-level natural-language documentation and inline user-visible error strings are in Chinese only, which imposes a specific language without any opt-in or documented locale constraint. Under the policy, language-specific behavior should either offer user choice or clearly justify the locale restriction.
This code reads the TUSHARE_TOKEN environment variable to authenticate with Tushare, which is a sensitive credential access path. Although the module raises an error if the token is missing, there is no user-facing warning, logging, or comment near the access explaining that the skill consumes a credential.
No suspicious patterns detected.