Back to skill

Security audit

Stock Monitor - 股票监控

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its optional state file can overwrite any writable path supplied in the config, so users should review it before installing.

Install only if you are comfortable giving the skill a JisuAPI key, sending stock codes to JisuAPI, and storing local holding/cost data. Use a trusted config, set `state_file` only to a dedicated state path, avoid running configs from others, and prefer installing dependencies in a virtual environment with pinned versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
monitor.py:61
Finding

User-Controlled State Path Permits Arbitrary File Overwrite

Content
View full analysis
Optional[str]: if "state_file" in req: v = req["state_file"] if v in (False, None, ""): return None return str(v).strip() env = os.environ.get("JISU_STOCK_MONITOR_STATE", "").strip() if env: return env return None ``` ```python def _save_state(path: str, state: dict) -> None: if not path: return state["version"] = STATE_VERSION d = os.path.dirname(os.path.abspath(path)) if d and not os.path.isdir(d): os.makedirs(d, exist_ok=True) fd, tmp = tempfile.mkstemp(suffix=".json", prefix="jisu-sm-", dir=d or None) try: with os.fdopen(fd, "w", encoding="utf-8") as f: json.dump(state, f, ensure_ascii=False, indent=2) os.replace(tmp, path) except Exception: try: os.unlink(tmp) except OSError: pass raise ``` ### Technical Analysis The `state_file` value is accepted directly from request JSON and converted into a filesystem path without validating its destination. The save routine converts it to an absolute parent directory, creates missing directories, and then uses `os.replace()` to replace the selected target with generated state JSON. There is no restriction requiring the destination to remain inside a dedicated application state directory. There is also no check that an existing destination is a legitimate state file. Consequently, anyone able to influence the monitor configuration can select any path writable by the operating-system account running the Skill. The temporary file itself is created securely through `tempfile.mkstemp()`. The vulnerability is not predictable temporary-file creation; it is the unrestricted final destination passed to ...[truncated 1280 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:24
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly describes capabilities that use environment variables, local file reads/writes, and outbound network access, yet it does not declare an explicit tool scope or permissions boundary. This creates a governance and least-privilege gap: an agent may invoke the skill with broader authority than users or platform policy expect, increasing the chance of unintended file access, state persistence, or external data transmission.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation guidance is broad enough to match generic portfolio-help requests, which can cause the agent to invoke a capability-bearing skill in situations where the user did not clearly request data retrieval, local state handling, or external API use. In this skill, that matters because invocation can lead to reading configuration files, using API credentials, persisting state, and contacting a third-party service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Forcing Chinese-language output without checking user preference can cause instruction-priority conflicts and miscommunication, especially when the user requested another language or when downstream automation expects a specific locale. While not a direct code-execution issue, it can undermine safe, accurate agent behavior and lead users to accept misunderstood financial-monitoring results.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · monitor.py (reported line 20)May include surrounding context.

python
import requests

STOCK_BASE = "https://api.jisuapi.com/stock"
HISTORY_BASE = "https://api.jisuapi.com/stockhistory"
STATE_VERSION = 2

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · monitor.py (reported line 21)May include surrounding context.

python
import requests

STOCK_BASE = "https://api.jisuapi.com/stock"
HISTORY_BASE = "https://api.jisuapi.com/stockhistory"
STATE_VERSION = 2

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON example includes natural-language labels only in Chinese, such as "示例股" and "黄金 ETF 示例", with no indication that the skill is region-specific or that other languages/locales are supported. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.