Back to skill

Security audit

A股分析技能包装器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a financial-data wrapper, but it delegates every query to an unreviewed local skill path and advertises portfolio changes without explaining storage or safeguards.

Install only if you trust both this wrapper and the separate akshare-stock skill at the hard-coded local path. Use an isolated environment, pin and review dependencies, and avoid entering real portfolio holdings until storage and deletion behavior are documented.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
main.py:23
Finding

Execution of an Unverified External Skill from a Hard-Coded Path

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:56
Finding

Unpinned and Unverified Third-Party Dependency Installation

Content
View full analysis
=1.18.0 pandas>=3.0.0 numpy>=2.4.0 ``` ### Technical Analysis The documented installation command installs mutable latest releases of the named packages and their transitive dependencies. It does not provide exact versions, package hashes, a lock file, or an explicitly trusted package index. The documented minimum-version constraints do not adequately mitigate this issue. A constraint such as `akshare>=1.18.0` permits any later release, including releases that have not been reviewed or tested with this Skill. Moreover, the shown `pip install` command does not apply even those minimum constraints directly. Python packages may execute code during installation, import, or normal runtime. Consequently, compromise of an allowed package release, an unsafe package source, or an unreviewed future dependency version could introduce code into the Skill's execution environment. ### Attack Path 1. A user follows the installation command in `SKILL.md`. 2. `pip` queries its configured package index and resolves the latest compatible releases and transitive dependencies. 3. A compromised, malicious, or unexpectedly changed release is selected because no exact version or cryptographic hash is required. 4. The package is installed into the environment. 5. Package-controlled code executes during installation, import, or a subsequent market-data query. 6. That code operates with the permissions of the user or service performing the installation or running the Skill. ### Impact Assessment The potential impact includes arbitrary code execution under the installing or runtime account, dependency-based data access, credential exposure, unauthorized network requests, and corruption of the ...[truncated 295 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill metadata does not declare any explicit tool scope or allowed tools, yet the skill documentation includes shell-based execution instructions and the static analyzer detected shell capability. Missing scope declarations can cause the platform or agent to grant broader execution latitude than intended, increasing the risk of command execution in response to ambiguous natural-language requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states the skill supports natural-language queries for A-share analysis entirely in Chinese and all examples and instructions are Chinese-only. There is no user opt-in, language selection, or justification that the skill is intentionally restricted to a Chinese-language locale.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation examples are very broad natural-language phrases with no trigger boundaries, exclusions, or confirmation requirements. This makes accidental or overly eager activation more likely, which is more dangerous here because the skill can access market data and also advertises portfolio-management actions that may modify stored user state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises holding-management actions such as viewing and adding positions, but it does not warn users that portfolio data may be stored, persisted, or modified. This creates a privacy and integrity risk because users may disclose sensitive financial holdings or trigger state changes without understanding retention, storage location, or edit behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's natural-language interface and descriptions are entirely in Chinese, and the help/usage flow is also presented only in Chinese. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes an A股-focused skill with capabilities like A股行情、个股分析、板块轮动、资金流向. In code, the wrapper treats 港股、美股、可转债、基金 as expected query categories and even adjusts timeout for them, showing the implemented scope extends beyond the declared A股-only purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · main.py (reported line 32)May include surrounding context.

python
timeout = 25  # 跨市场查询更慢
    
    try:
        result = subprocess.run(
            cmd,
            cwd=skill_path,
            capture_output=True,

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The help text is part of the skill's documented behavior and tells users the skill can handle other markets and 新闻/研报 queries. That is materially broader than the manifest's stated purpose of A股 market data and analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The phrase '输入任意查询即可开始使用!' presents the interaction model as Chinese-only and does not offer any language or locale choice. This reinforces a mandatory language constraint without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.