Back to skill

Security audit

Cn Client Investigation

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed China-market research and deliverable workflow, but it includes unsafe credential, network, and dependency practices that deserve Review before installation.

Review before installing or running. Remove and rotate the embedded Tushare token, require user-provided credentials, switch Tushare and CNINFO retrieval to HTTPS, preserve proxy policy unless explicitly overridden, pass only required environment variables to subprocesses, and pin npm dependencies with a lockfile. Run the workflow in a contained workspace because it writes raw corporate data snapshots and generated deliverables locally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bj_smoke_v2.py:25
Finding

Hardcoded API Credential Transmitted over Plaintext HTTP

Content
View full analysis
" ``` ```python def ts(api: str, params: dict, fields: str) -> dict: body = json.dumps({"api_name": api, "token": TUSHARE_TOKEN, "params": params, "fields": fields}) r = urllib.request.Request( "http://api.tushare.pro", data=body.encode(), headers={"Content-Type": "application/json"}, method="POST") return json.loads(urllib.request.urlopen(r, timeout=15).read()) ``` The credential value is redacted from this report to prevent further disclosure. The audited source contains the full token. ### Technical Analysis The script first attempts to obtain `TUSHARE_TOKEN` from the environment but falls back to a complete credential embedded in the source code. Anyone who can read the repository or an installed copy of the Skill can recover and reuse that credential. The `ts()` function then places the token inside a JSON request body and sends it to `http://api.tushare.pro`. Because HTTP does not provide transport encryption, server authentication, or message integrity, the token and requested financial data may be observed or modified by an attacker with access to the network path. The API request itself is consistent with the Skill’s financial-research functionality. However, embedding a shared credential and transmitting it over plaintext HTTP are not necessary for that functionality and violate least-secret-exposure principles. ### Attack Path 1. An attacker obtains read access to the repository, installed Skill directory, source archive, backup, or build log. 2. The attacker extracts the embedded Tushare token and submits API calls under the associated account. 3. Alternativ ...[truncated 999 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/build_deck.py:430
Finding

Unpinned npm Installation Permits Mutable Supply-Chain Code Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/data-sources.md:5
Finding

Plaintext HTTP Guidance for Authoritative Financial Disclosure Retrieval

Content
View full analysis
` - Retrieval method: Search for the company disclosure URL and then use `web_fetch` to download the PDF for text extraction. ``` The wording above is translated into English for reporting consistency. The audited source explicitly provides the same `http://www.cninfo.com.cn/...` URL and instructs the Agent to fetch resulting disclosure documents. ### Technical Analysis The Skill defines CNINFO disclosures as authoritative Tier-1 inputs and directs the Agent to begin retrieval through an HTTP URL. Plaintext HTTP provides neither transport confidentiality nor cryptographic integrity and does not authenticate the remote endpoint. Although disclosure documents are public and normally do not require confidentiality, their integrity is critical. A modified annual report, prospectus, or search result could introduce false financial numbers while appearing to originate from an authoritative source. Network retrieval is necessary for the declared investigation function. Plaintext transport is not necessary and exceeds the minimum acceptable risk for integrity-sensitive financial analysis. ### Attack Path 1. The Agent follows the documented HTTP search pattern. 2. An attacker controlling a local network, proxy, DNS response, gateway, or other network-path component intercepts the request. 3. The attacker redirects the Agent to a counterfeit document or modifies the search response. 4. The Agent downloads and parses the attacker-controlled PDF or ...[truncated 691 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (56)

Tainted flow: 'r' from os.environ.get (line 39, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/bj_smoke_v2.py (reported line 42)May include surrounding context.

python
r = urllib.request.Request(
        "http://api.tushare.pro", data=body.encode(),
        headers={"Content-Type": "application/json"}, method="POST")
    return json.loads(urllib.request.urlopen(r, timeout=15).read())


def items_to_dicts(resp: dict) -> list[dict]:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on China-specific client investigation, banker-grade analytical safeguards, Chinese text typo prevention, and data provenance controls. The supplied code does not perform company investigation, Chinese market data retrieval, source validation, typo checking, or factual analysis. Instead, it converts an already-produced slides-outline.md into slide JS files and compiles a PPTX using Node/pptxgenjs. While the code references a cn-client-investigation template path and uses Chinese fonts/text fields, those are presentation/rendering details rather than evidence of the claimed analytical or validation behavior. Therefore the actual primary purpose is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a comprehensive China-focused investigation and analysis skill with strict safeguards for Chinese text accuracy and data provenance. The supplied code only implements one narrow safeguard: scanning a text file for suspicious Chinese character corruption patterns and rare CJK characters. That supports the 'Chinese text accuracy' aspect, but it is only a small subcomponent of the declared workflow. There is no evidence of company research, financial analysis, source provenance enforcement, target classification, CNINFO/Tushare access, or broader report-generation logic. Therefore the declared description materially overstates and misrepresents the code's actual primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code’s actual function is narrowly scoped: it reads a Word document, extracts paragraph/table text, identifies hard numbers, and verifies whether those numbers appear in a provenance markdown file. This does align loosely with the description’s mention of data provenance guards, but it does not implement the skill’s primary declared purpose of China mainland client investigation or banker-grade analysis for Chinese companies. It also lacks any Chinese-language validation, typo prevention, target detection, or integrations/resources implied by the description (e.g., A-share/HK/CNINFO/Tushare-specific handling). Therefore the description materially overstates and mischaracterizes the code’s real behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a high-level China mainland customer-investigation/analysis skill with strict guards for Chinese-language accuracy and provenance integrity. The supplied code instead implements a narrow producer script that reads a local data-provenance.md, regex-extracts numeric metrics plus units/sources, and emits a JSON lookup file. While there is a thematic overlap around data provenance and avoiding number re-typing drift, the code does not conduct investigation, banker-grade analysis, Chinese text validation, market-specific handling, or enforcement against fabricated numbers. Its primary purpose is materially different: exporting numbers from markdown into JSON for slide/doc generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad China-mainland investigation/analysis skill specialized for Chinese companies, emphasizing Chinese text accuracy and data provenance in a research workflow. The supplied code, however, is a narrow utility script whose primary function is to audit compiled PowerPoint slides for numeric provenance coverage. While there is a partial thematic overlap with 'data provenance' and possibly Chinese-text workflow quality controls mentioned in the docstring, the actual code does not perform client investigation, banker-grade analysis, Chinese-company targeting, trigger handling, or Chinese typo checking. Its main behavior is materially different: it reads a PPTX, extracts slide text, finds hard numbers, compares them to a provenance corpus, and returns pass/fail. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad China-mainland investigation and banker-analysis skill with strict guards for Chinese text accuracy and data provenance across deliverables. The supplied code, however, is a narrow authenticity checker for source labels inside markdown tables in a specific file (data-provenance.md). It does not investigate companies, analyze Chinese issuers, verify Chinese text correctness, or build/replace a larger workflow. Its main purpose is to detect forbidden or weak source citations such as Wind/同花顺 and optionally fail media-only citations under strict mode. While this partially relates to 'data provenance,' that is only one small subset of the declared functionality, and the primary purpose is materially different and much narrower than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad China-focused investigation/analysis skill with strict safeguards for Chinese text accuracy and source provenance, intended for A-share/HK/private-unicorn company research workflows. The supplied code does not implement investigation, banker analysis, provenance checking, source retrieval, company-specific handling, or numeric truthfulness checks. Instead, it is a narrow linting utility for markdown style consistency. While some checks relate loosely to Chinese-language deliverable quality, the primary purpose is materially different and much narrower than declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a specialized China mainland client investigation and banker-grade analysis skill with strong controls for Chinese text accuracy and provenance integrity, triggered by China-market contexts such as A-share, HK, CNINFO, Tushare, etc. The supplied code does not perform investigation or analysis of Chinese companies. Instead, it is a narrow file-based post-processor that reads analysis.md and data-provenance.md, detects hard-number references not already present in provenance, and appends guessed provenance rows marked [auto-sync]. It also adds rows for unreferenced raw-data files. While provenance is part of the declared description, the code’s primary purpose is materially different: automated provenance patching for banker-memo deliverables. It lacks the claimed Chinese-text accuracy safeguards, China-target routing logic, or substantive market/company research behavior. Therefore the description does not accurately represent the actual code behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
references/compile_with_typo_gate.template.js.txt

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 276)May include surrounding context.

md
references/compile_with_typo_gate.template.js.txt

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 245)May include surrounding context.

md
**PREFERRED ROUTE (0.9.6+): Prompt-driven `banker-memo` skill + `build_outline_deck.py`.**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
Why preferred: 0.9.5 Python-templated `build_deck.py` produced an 8-slide data dashboard — no industry context, no peer benchmarking, no SOTP / 4C's. 0.9.6 prom

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 268)May include surrounding context.

md
Why preferred: 0.9.5 Python-templated `build_deck.py` produced an 8-slide data dashboard — no industry context, no peer benchmarking, no SOTP / 4C's. 0.9.6 prom

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/bj_nonlisted_v2.py (reported line 30)May include surrounding context.

python
bridge = (pathlib.Path.home() /
              ".openclaw/extensions/aigroup-lead-discovery-openclaw"
              "/scripts/mcp_compat/prime_matrix_stdio_bridge.mjs")
    child_env = {**os.environ,
                 "MCP_API_KEY": env.get("PRIMEMATRIX_MCP_API_KEY", ""),
                 "BASE_URL":    env.get("PRIMEMATRIX_BASE_URL", "")}
    r = subprocess.run(

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script embeds a live-looking Tushare API token directly in source and automatically uses it for outbound requests. Hard-coded credentials are dangerous because anyone who can read the skill can reuse the token, incur charges, consume quota, or access data under the owner's account without consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Using a hard-coded default API token for automatic outbound requests means the skill silently performs network actions under someone else's credential context. This is risky both from a security and governance standpoint because users may unknowingly consume protected resources and the credential owner loses control over where the token is used.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
90% confidence
Finding

The code copies the entire current process environment into the subprocess with {**os.environ, ...}, then adds API settings. While it is not harvesting variables for direct exfiltration in this snippet, it unnecessarily exposes all parent-process secrets to the Node bridge, which could access or leak credentials unrelated to this skill if compromised or overly verbose.

Content

Scanner excerpt · scripts/bj_smoke_v2.py (reported line 66)May include surrounding context.

python
bridge = (pathlib.Path.home() /
              ".openclaw/extensions/aigroup-lead-discovery-openclaw"
              "/scripts/mcp_compat/prime_matrix_stdio_bridge.mjs")
    env = {**os.environ,
           "MCP_API_KEY": openclaw_env.get("PRIMEMATRIX_MCP_API_KEY", ""),
           "BASE_URL":    openclaw_env.get("PRIMEMATRIX_BASE_URL", "")}
    r = subprocess.run(

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes and relies on broad capabilities including network access, file read/write, shell execution, and environment use, but it declares no explicit tool scope or allowed-tools boundary. In an agent setting, this widens the attack surface and can let the skill invoke more powerful operations than users or platform policy may expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states that cover slides 'MUST use the English company name' as the hero title with Chinese only as a secondary subtitle. This is a language policy constraint presented as mandatory behavior, and the file does not offer user choice or clearly frame it as an optional preference.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 270)May include surrounding context.

md
**LEGACY ROUTE (still supported for quick fact-sheets): `build_deck.py`** emits a fixed 8-slide stat-card dashboard. Use only when depth isn't required.

**Both routes share:** pptxgenjs slide compile + cn_typo_scan post-write gate. NEVER use python-pptx for generation (white background / no theming; only permitted for text extraction inside `validate-delivery.py`).

For CN targets, these routes override `ppt-deliverable`'s "MiniMax first" routing — only pptxgenjs compile integrates the compile-time typo gate.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file description states this template is specifically for a Chinese-market company and enforces a Chinese typo scan gate. This imposes a locale-specific behavior in natural-language guidance without offering user choice or documenting an opt-in mechanism, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/bj_nonlisted_v2.py (reported line 33)May include surrounding context.

python
child_env = {**os.environ,
                 "MCP_API_KEY": env.get("PRIMEMATRIX_MCP_API_KEY", ""),
                 "BASE_URL":    env.get("PRIMEMATRIX_BASE_URL", "")}
    r = subprocess.run(
        ["node", str(bridge), tool,
         json.dumps({"company_name": fullname})],
        capture_output=True, text=True, timeout=30, env=child_env)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script sends target company names to a subprocess-backed bridge that appears to reach an external PrimeMatrix service, but there is no operator-facing disclosure, approval step, or configuration guard confirming that organizational data may be transmitted off-host. In client-investigation workflows, undisclosed outbound transmission can violate internal handling expectations or confidentiality requirements even if the transport is functionally necessary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script writes raw company investigation data, including identifiers, addresses, shareholder, risk, and judicial records, into predictable local files under 'raw-data/' without any consent gate, data classification check, retention control, or warning to the operator. In a due-diligence context this can create unintended local exposure of sensitive corporate information and may leave persistent artifacts on shared workstations or build agents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.