Back to skill

Security audit

China Stock Data

Security checks for vulnerabilities and agentic risk

Overview

This stock-data skill is mostly purpose-aligned, but it includes unsafe credential handling, insecure transport, overbroad setup guidance, and misleading data behavior that users should review before installing.

Install only in an isolated environment. Rotate or remove the embedded Tushare token before use, avoid the custom plaintext Tushare endpoint and CNINFO HTTP where HTTPS is available, do not run Chromium with --no-sandbox on trusted hosts, avoid proxy/IP-rotation evasion guidance, and treat generated briefing images as demo/static unless the data path is replaced with live verified sources.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/china_stock.py:506
Finding

Hardcoded Tushare API Token Transmitted Through a Plaintext Custom Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/cninfo-pdf-extraction.md:18
Finding

Instructions Disable the Chromium Security Sandbox for Remote Content

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:4
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Supply-Chain Changes

Content
View full analysis
=2.28.0 beautifulsoup4>=4.11.0 lxml>=4.9.0 # Data processing pandas>=2.0.0 openpyxl>=3.0.0 # Stock data sources pytdx>=1.74 akshare>=1.14.0 ``` The setup instructions also recommend installing optional dependencies without version constraints: ```bash pip install jqdatasdk pip install rqdatac pip install tushare pip install wencai ``` ### Technical Analysis Lower-bound-only requirements allow pip to install any future release satisfying the constraint. Optional packages are installed without any version restriction. The project provides neither a lock file nor cryptographic hashes for approved distributions. As a result, installing the Skill at different times can produce materially different executable environments that were not covered by this audit. Compromise of a direct dependency, transitive dependency, source distribution, or build backend could introduce malicious code during installation or later at import time. No evidence was found that the currently named packages are intentionally malicious. The vulnerability is the absence of reproducible and integrity-verified dependency resolution. ### Attack Path 1. An attacker compromises a permitted direct or transitive package release or its publishing account. 2. A user runs `pip install -r requirements.txt` or one of the documented optional installation commands. 3. pip resolves the attacker's newer package because it satisfies the broad constraint. 4. Malicious build, installation, or imported runtime code executes under the installing or running user's account. 5. The malicious package can access data and privileges available to that Python environment. ### Impact Assessment Successful supply-chain compromise coul ...[truncated 394 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/china_stock.py:306
Finding

CNINFO Queries and Announcement Links Use Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The description is broadly aligned with the code's main purpose: a China stock market multi-source data skill aggregating several providers. However, there are material mismatches. First, the code uses an additional undeclared source, CNINFO, for announcements. Second, RiceQuant is advertised as an integrated source, but the code only imports/authenticates it and reports status; there is no exposed RiceQuant data query feature. Third, the '8-source automatic fallback' claim is overstated: fallback exists for quote queries (TDX→Tencent→iFinD) and announcements (CNINFO→Tushare→AKShare), but not as a general unified 8-source downgrade mechanism. Finally, the docstring claims TDX supports tick-by-tick trades, but the visible code implements only quote and K-line retrieval, not transaction-level trade data. These are sufficient to flag a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a broad financial data access skill with many upstream integrations and automatic failover. The supplied code chunk instead is a visual report generator that renders a PNG briefing with preset text and numbers. Its only external interactions are local font discovery and writing an output image file. There is no evidence of real-time quote retrieval, order book access, K-line handling, valuation lookup, hot topic scraping, report/announcement fetching, iWencai search, or quant platform integration. This is a clear description-behavior mismatch, with the code serving a materially different purpose from the declared skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a broad China A-share integrated data source with multiple named providers and capabilities centered on stock market data retrieval and fallback across 8 sources. The supplied code instead mainly aggregates financial news from Eastmoney, Tonghuashun, and Sina, and supplements that with limited index data from TDX for a daily briefing. While TDX and Eastmoney appear, the implemented functionality is much narrower than declared: there is no comprehensive multi-source stock data layer, no valuation/fundamental metrics from Tencent, no 5档盘口, no K-line retrieval, no iWencai/JQData/Tushare/RiceQuant integrations, and no automatic 8-source degradation framework beyond simple TDX host rotation. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a clear description-behavior mismatch. The declared purpose describes a broad Chinese A-share market data aggregation skill using several named Chinese data vendors and services. The supplied code does none of that. Instead, it exclusively interfaces with SEC EDGAR for U.S. public-company filings and institutional holdings, exposing commands for search, 13F, and 10-K retrieval. The primary purpose, data sources, geographic/market focus, and capabilities are materially different from the declaration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents the skill as a broad China A-share integrated data-source connector spanning many vendors and data types. The supplied code chunk instead implements a focused monitoring utility: it checks current prices against thresholds and scans a watchlist for abnormal moves. While it likely relies on a quote abstraction from another module and may indirectly use some stock data providers, this code does not evidence the claimed primary purpose of multi-provider comprehensive data aggregation, nor the listed capabilities such as 5-level order book, K-line retrieval, reports/announcements, iWencai search, or quant platform integrations. The actual triggers/usage are CLI monitor commands, which materially differ from the declared capability framing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code embeds a live Tushare Pro API token directly in source, which exposes credentialed third-party access to anyone who can read the file and causes undisclosed outbound use of that account. Hard-coded secrets are routinely leaked via source control, logs, packaging, or redistribution and can be abused to consume quota, impersonate the account, or access paid data under the owner's identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A hard-coded API token in source is a real secret exposure and also means the skill silently uses a third-party account without requiring user configuration or consent. In a skill context that performs many network requests, this is especially risky because the credential may be redistributed widely and abused at scale.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises capabilities that inherently require network, shell, environment-variable access, and likely local file writes, but it does not declare any explicit tool scope or permission boundaries. That creates an over-broad execution surface where a host agent may grant more access than users expect, increasing the risk of unintended command execution, credential exposure, or filesystem modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger guidance is extremely broad, effectively allowing almost any A-share-related natural language input to activate a skill that can use shell, network, and credentials-backed third-party services. Over-broad invocation criteria increase the chance of accidental execution, unintended external data disclosure, and confusing tool selection in multi-skill environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to configure multiple tokens, usernames, and passwords in environment variables or local files, but it does not clearly warn that queries and potentially sensitive watchlists or research terms will be sent to third-party services. In a credentialed, networked skill, lack of disclosure around secret handling and outbound data sharing can lead to credential misuse, privacy leakage, and unsafe deployment in shared environments.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cninfo-api.md (reported line 49)May include surrounding context.

bash 示例:

bash
curl -s "http://www.cninfo.com.cn/new/fulltextSearch/full" \
  -H "User-Agent: Mozilla/5.0" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "searchkey=000001&pageNum=1&pageSize=5&sortName=pubdate&sortType=desc"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains end-user instructions exclusively in Chinese, including headings, steps, and warnings, but does not indicate that the skill is region-specific or that users may choose another language. That can violate a language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cninfo-pdf-extraction.md (reported line 5)May include surrounding context.

md
## 问题

巨潮公告详情页中的 PDF 地址是 **动态生成 + 有时限** 的。直接构造 URL(如 `https://disc.static.szse.cn/download/...`)返回 404。通过静态 curl 抓取 HTML 也拿不到真实 PDF 链接(页面纯 JS 渲染)。

## 解决方案:用 Hermes browser 工具

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document goes beyond describing data retrieval and instructs users to patch Hermes browser tooling so environment variables are injected into subprocess execution. Modifying shared tool code and forcing browser launch flags expands the skill's operational scope and weakens platform safety boundaries, creating a path for broader tool manipulation than is necessary for fetching stock disclosures.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly recommends using a proxy pool and rotating multiple IPs after an upstream service has temporarily banned the server IP. That is guidance for bypassing rate limits and access restrictions imposed by a third party, which creates legal, policy, and abuse risk and could encourage operators to continue prohibited scraping rather than reduce request volume or obtain authorized access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The specific recommendation to use a proxy pool with multiple IP rotation normalizes evasion of upstream controls without any warning about terms-of-service violations, account suspension, network abuse, or possible legal consequences. In a stock-data aggregation skill, this is not necessary for legitimate function and increases the chance the skill will be used to continue scraping after a ban.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These protocol notes go beyond normal API usage and provide explicit anti-rate-limit, anti-blocking, host-rotation, jitter, and batching guidance intended to reduce detection and avoid IP bans. In a stock-data aggregation skill, this materially enables evasion of provider controls and could facilitate abusive scraping or unauthorized use of third-party infrastructure, especially because it recommends rotating among multiple verified servers to lower per-host detection.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/china_stock.py (reported line 48)May include surrounding context.

python
global _LAST_TDX_TIME
    elapsed = time.time() - _LAST_TDX_TIME
    if elapsed < 0.5:
        time.sleep(round(0.5 - elapsed + __import__('random').random() * 0.2, 3))
    _LAST_TDX_TIME = time.time()
    pass

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/china_stock.py (reported line 233)May include surrounding context.

python
at = IF.get("access_token","")
    if not at: return {"errorcode":-9999,"errmsg":"未配置iFinD token"}
    try:
        r = requests.post(f"{IFIND_URL}/{ep}", headers={"Content-Type":"application/json","access_token":at}, json=params, timeout=30)
        d = r.json()
        if d.get("errorcode") in (-1010,-1300,-1302) and retry and IF.get("refresh_token"):
            r2 = requests.post(f"{IFIND_URL}/get_access_token", headers={"Content-Type":"application/json","refresh_token":IF["refresh_token"]}, timeout=15)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill refreshes an iFinD access token and writes the updated credential back to disk in a predictable local file without any user-facing warning or protection. Persisting bearer tokens to plaintext config increases the chance of credential theft from source directories, backups, multi-user systems, or accidental inclusion in artifacts.

Content

No source excerpt is available for this finding.

Tainted flow: 'IF' from requests.get (line 224, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/china_stock.py (reported line 236)May include surrounding context.

python
r = requests.post(f"{IFIND_URL}/{ep}", headers={"Content-Type":"application/json","access_token":at}, json=params, timeout=30)
        d = r.json()
        if d.get("errorcode") in (-1010,-1300,-1302) and retry and IF.get("refresh_token"):
            r2 = requests.post(f"{IFIND_URL}/get_access_token", headers={"Content-Type":"application/json","refresh_token":IF["refresh_token"]}, timeout=15)
            d2 = r2.json()
            if d2.get("errorcode")==0:
                IF["access_token"]=d2.get("access_token","")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest advertises '8大来源自动降级' including JQData, Tushare Pro, and RiceQuant. In the code, smart fallback is only TDX → Tencent → iFinD, announcement fallback is CNINFO/Tushare/AKShare, and RiceQuant is merely initialized without any exposed data retrieval path. This overstates the implemented coverage and fallback behavior compared with actual operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script is presented as generating a real-time A-share market briefing from live data sources, but it actually renders entirely hardcoded prices, market breadth, and headlines. In a financial-data skill, this is dangerous because users may rely on fabricated or stale market information for trading or reporting decisions while believing it is live and authoritative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and CLI description present the skill exclusively in Chinese and define it specifically as an A-share market briefing generator, with no indication that language choice is optional. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/daily_briefing_image.py (reported line 33)May include surrounding context.

python
if os.path.isfile(fp):
            return fp
    try:
        r = subprocess.run(['fc-list', ':lang=zh'], capture_output=True, text=True, timeout=5)
        for line in r.stdout.split('\n'):
            path = line.split(':')[0].strip()
            if path and os.path.isfile(path):

Static analysis

No suspicious patterns detected.