Back to skill

Security audit

aa

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stock-report purpose, but it silently forces network traffic through an undocumented hard-coded proxy while handling external market-data requests and a Tushare token.

Review before installing. The core functionality is coherent, but remove or explicitly configure the hard-coded proxy before running it, pin dependencies or use a skill-specific environment, and avoid entering sensitive portfolio details unless you are comfortable sending ticker-related requests to Yahoo Finance or Tushare.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_stock_data.py:13
Finding

Undocumented hard-coded proxy redirects process-wide network traffic

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:33
Finding

Open-ended dependency versions permit installation of unreviewed releases

Content
View full analysis
=0.2.40 --python ./bin/python3 # 验证 ~/.hermes/hermes-agent/venv/bin/python3 -c "import yfinance; print('OK:', yfinance.__version__)" ``` ```bash cd ~/.hermes/hermes-agent/venv uv pip install tushare>=1.2.80 --python ./bin/python3 ``` ### Technical Analysis The documented installation commands use open-ended lower bounds rather than exact, reviewed versions. Consequently, installation may retrieve any future release satisfying `yfinance>=0.2.40` or `tushare>=1.2.80`, along with mutable transitive dependencies. The commands also install packages into the Hermes Agent virtual environment rather than a Skill-specific isolated environment. This increases the potential effect of dependency changes because package upgrades or resolver decisions may alter components used by unrelated Agent functionality. No malicious or typosquatted package is present in the reviewed project, and the package names shown are consistent with the declared functionality. The risk arises from the inability to reproduce and verify the precise dependency set that will execute in the future. ### Attack Path 1. A user follows the installation instructions in `SKILL.md`. 2. The package resolver selects the newest available versions satisfying the open-ended constraints. 3. A selected direct or transitive dependency contains a compromised release, malicious installation behavior, or an incompatible security regression. 4. Package installation or subsequent import executes that dependency’s code with the permissions of the Agent user. 5. Because installation occurs in a shared Agent virtual environment, the affected package may also influence unrelated Skills or later Agent sessions that use the same environment. ### Impact As ...[truncated 637 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code generally aligns with the data-source portion of the description: it supports US/HK via Yahoo Finance and CN via Tushare, and accepts stock tickers like PDD/KC. However, the declared purpose emphasizes automatic generation of a structured Markdown deep financial analysis report, while this code chunk is only a data-fetching module. It retrieves info, historical prices, and some financial statement or indicator data, then prints serialized data. There is no report construction, Markdown formatting, or analysis logic. Additionally, the CN/Tushare implementation fetches basic info, financial indicators, and daily prices, but not full financial statements in the same way the description suggests. Therefore the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares use of environment variables, including a TUSHARE_TOKEN, but does not define any explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can lead to broader-than-necessary access to secrets or runtime capabilities, increasing the chance of accidental secret exposure or unauthorized external use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Overly broad triggers such as generic stock-analysis phrases can cause the skill to activate in unintended contexts, leading to unsolicited external requests or processing of user data. In an agent environment, ambiguous activation increases the risk of misuse, accidental invocation, and surprise transmission of queried tickers or portfolio-related inputs to third-party providers.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module unconditionally sets global HTTP_PROXY and HTTPS_PROXY environment variables for the entire process, affecting all subsequent network traffic made by this skill and any imported libraries. In the context of a data-fetching tool, this can silently reroute requests through an unexpected proxy, exposing market queries, authentication headers, or future requests to interception or manipulation if the proxy is untrusted or misconfigured.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This codebase presents its purpose, CLI description, and generated report content in Chinese only, including the main docstring and all report sections. The policy requires flagging language or locale constraints when a skill forces a specific language without explicit user opt-in or choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script unconditionally sets global HTTP_PROXY and HTTPS_PROXY environment variables to a hard-coded internal proxy address, affecting all subsequent network traffic in the process. This can silently redirect stock data requests and any other HTTP(S) communications through an unrelated intermediary, enabling traffic inspection, manipulation, data leakage, or unexpected outbound routing that is not necessary for report generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill sends stock queries to Yahoo Finance or Tushare but does not prominently warn users that their requested tickers or holding-related inputs may be transmitted to external services. This is a privacy and transparency issue that becomes more relevant when users provide portfolio cost basis or market-specific identifiers tied to their investments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions and evaluation guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level natural-language documentation and inline user-visible error strings are in Chinese only, which imposes a specific language without any opt-in or documented locale constraint. Under the policy, language-specific behavior should either offer user choice or clearly justify the locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code reads the TUSHARE_TOKEN environment variable to authenticate with Tushare, which is a sensitive credential access path. Although the module raises an error if the token is missing, there is no user-facing warning, logging, or comment near the access explaining that the skill consumes a credential.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.