Back to skill

Security audit

金融日报推送技能

Security checks for vulnerabilities and agentic risk

Overview

This finance-report skill fits its stated purpose, but it embeds a reusable TuShare API token and uses unencrypted quote data for financial reports.

Review before installing. Use only with your own explicitly configured TuShare token after the embedded token is removed and rotated, and treat generated stock recommendations as informational rather than investment advice. If you enable the cron examples, track and remove those tasks when you no longer want recurring reports. Prefer TLS-protected or independently verified quote sources before relying on report data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tushare_enhance.py:16
Finding

Hardcoded TuShare API Token Exposes a Reusable Credential

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch-quote.py:22
Finding

Tencent Market Quotes Are Retrieved Over Unencrypted HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

md
- ✅ 更新 `SKILL.md` - 增加 TuShare 配置说明

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The hardcoded fallback token means the skill will silently use privileged external API access even when the operator has not intentionally configured credentials. In skill ecosystems this is especially risky because users may unknowingly run code that makes authenticated third-party requests, while the exposed token can be reused by others for unauthorized access and service abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manual invocation phrase is very generic and closely resembles an ordinary user request for a finance summary, which can cause accidental skill triggering or unintentional routing into this skill. In a skill that generates recurring financial content and recommendations, ambiguous invocation increases the chance of unauthorized or surprising behavior, even if there is no overtly malicious content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and all user-facing descriptions are written only in Chinese, indicating a fixed language choice. Under the policy, language constraints should either offer user opt-in/choice or be clearly justified as region-specific; this file does not explicitly state such a justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script embeds a hardcoded TuShare API token and automatically uses it as a fallback, granting authenticated access to an external data provider without requiring explicit user consent or secure secret provisioning. This exposes the credential to anyone with source access and can lead to unauthorized API usage, quota exhaustion, billing or account abuse, and unintended outbound data access from the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill promotes cron-based scheduled pushes but does not prominently warn that this creates ongoing recurring outbound messages until the task is removed. That can lead users to enable persistent notifications without fully understanding the continuing behavior, causing unwanted message spam or repeated financial prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction explicitly requires the report to '重点聚焦 A 股', which constrains output to a specific regional market context. Under the policy criteria, locale or regional restrictions should either be optional, user-selected, or clearly justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The top-level documentation says the module is for a financial daily push skill providing individual stock market data and analysis recommendations. However, the implementation also retrieves LPR and SHIBOR macroeconomic data, which expands the module's behavior beyond the stated stock-focused scope in its own documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.