T07 · Tool Hijacking and Spoofing
- Location
main.py:23- Finding
Execution of an Unverified External Skill from a Hard-Coded Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a financial-data wrapper, but it delegates every query to an unreviewed local skill path and advertises portfolio changes without explaining storage or safeguards.
Install only if you trust both this wrapper and the separate akshare-stock skill at the hard-coded local path. Use an isolated environment, pin and review dependencies, and avoid entering real portfolio holdings until storage and deletion behavior are documented.
main.py:23Execution of an Unverified External Skill from a Hard-Coded Path
SKILL.md:56Unpinned and Unverified Third-Party Dependency Installation
The skill metadata does not declare any explicit tool scope or allowed tools, yet the skill documentation includes shell-based execution instructions and the static analyzer detected shell capability. Missing scope declarations can cause the platform or agent to grant broader execution latitude than intended, increasing the risk of command execution in response to ambiguous natural-language requests.
The description states the skill supports natural-language queries for A-share analysis entirely in Chinese and all examples and instructions are Chinese-only. There is no user opt-in, language selection, or justification that the skill is intentionally restricted to a Chinese-language locale.
The invocation examples are very broad natural-language phrases with no trigger boundaries, exclusions, or confirmation requirements. This makes accidental or overly eager activation more likely, which is more dangerous here because the skill can access market data and also advertises portfolio-management actions that may modify stored user state.
The skill advertises holding-management actions such as viewing and adding positions, but it does not warn users that portfolio data may be stored, persisted, or modified. This creates a privacy and integrity risk because users may disclose sensitive financial holdings or trigger state changes without understanding retention, storage location, or edit behavior.
The file's natural-language interface and descriptions are entirely in Chinese, and the help/usage flow is also presented only in Chinese. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly documented and justified.
The manifest describes an A股-focused skill with capabilities like A股行情、个股分析、板块轮动、资金流向. In code, the wrapper treats 港股、美股、可转债、基金 as expected query categories and even adjusts timeout for them, showing the implemented scope extends beyond the declared A股-only purpose.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
timeout = 25 # 跨市场查询更慢
try:
result = subprocess.run(
cmd,
cwd=skill_path,
capture_output=True,
The help text is part of the skill's documented behavior and tells users the skill can handle other markets and 新闻/研报 queries. That is materially broader than the manifest's stated purpose of A股 market data and analysis.
The phrase '输入任意查询即可开始使用!' presents the interaction model as Chinese-only and does not offer any language or locale choice. This reinforces a mandatory language constraint without opt-in or justification.
No suspicious patterns detected.