Back to skill

Security audit

A股智能选股 · BigA(A股实时行情·股票分析·基本面筛选·AI选股·买卖信号)

Security checks for vulnerabilities and agentic risk

Overview

This stock-alert skill is not clearly malicious, but it creates recurring agent tasks and message-sending behavior with broad automatic triggers and unpinned setup dependencies.

Review this before installing. Only use it if you want recurring stock-analysis messages, and verify the exact cron schedules, message destination, and update behavior first. Treat its buy/sell signals as informational rather than financial advice, and consider disabling or removing scheduled jobs when they are no longer needed. DSH users should be especially careful with the unpinned BigTimer GitHub install.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
references/cron-install-shell.sh:17
Finding

Recurring Cross-Session Agent Tasks Create System Persistence

Content
View full analysis

Vulnerability Details

File Location: references/cron-install-shell.sh:17-50; installation behavior is also directed by SKILL.md:219-221
Vulnerability Type: Persistent scheduled Agent execution
Risk Level: High

Vulnerable code:

bash
openclaw cron add \
  --name biga-morning \
  --cron "30 8 * * 1-5" \
  --tz "Asia/Shanghai" \
  --timeout-seconds 600 \
  --channel CHANNEL \
  --to TARGET \
  --session isolated \
  --no-deliver

openclaw cron add \
  --name biga-scan \
  --cron "30 9,10,11,13,14 * * 1-5" \
  --tz "Asia/Shanghai" \
  --timeout-seconds 600 \
  --channel CHANNEL \
  --to TARGET \
  --session isolated \
  --no-deliver

openclaw cron add \
  --name biga-evening \
  --cron "30 15 * * 1-5" \
  --tz "Asia/Shanghai" \
  --timeout-seconds 600 \
  --channel CHANNEL \
  --to TARGET \
  --session isolated \
  --no-deliver

Technical Analysis

The documented installation process creates three recurring OpenClaw tasks. These jobs survive the original skill invocation and execute in isolated Agent sessions every weekday. Their scheduled prompts direct future sessions to follow the skill's operational instructions, perform network searches, run the local scanner, and potentially transmit messages.

The persistence is installed at user request and is related to the advertised notification feature; however, it still establishes durable cross-session execution. No automatic expiration, revocation, integrity pinning, or uninstall procedure is included. Consequently, later changes to the effective skill instructions can alter the behavior of future scheduled executions without requiring the user to recreate or reapprove the jobs.

Attack Path

  1. A user invokes the documented installation flow.
  2. The skill obtains the current messaging channel and destination.
  3. Three openclaw cron add commands create recurring isolated Agent sessions.
  4. The jobs ...[truncated 752 chars]
Remediation
View remediation

Remediation Suggestions

  • Present every proposed job name, schedule, prompt, destination, and permission scope before installation.
  • Require explicit confirmation immediately before creating the jobs.
  • Pin scheduled behavior to a reviewed, immutable skill version or integrity-verified prompt instead of implicitly relying on mutable instructions.
  • Add an expiration time or disabled-by-default state for newly installed jobs.
  • Provide a documented uninstall operation that removes all three jobs and the local send configuration.
  • Record created job identifiers so cleanup can be performed reliably.
  • Apply least privilege to scheduled sessions and restrict their available tools, network destinations, workspace paths, and messaging targets.
  • Require renewed approval whenever the skill version, scheduled prompt, destination, or requested permissions change.

T08 · Insecure Dependencies

Error
Location
SKILL.md:44
Finding

Unpinned GitHub Plugin Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:44
Vulnerability Type: Installation of mutable third-party executable content
Risk Level: High

Vulnerable code:

bash
dsh plugin add github:kobenfang/BigTimer

Technical Analysis

The DSH setup guidance instructs users to install a plugin directly from a GitHub repository reference. The reference is not pinned to an audited commit hash or immutable signed release. No checksum, signature verification, provenance validation, or permission review is specified.

A mutable repository reference means the code installed by a future user may differ from the code that existed when this skill was audited. Compromise of the repository, maintainer account, release process, or dependency chain could therefore introduce attacker-controlled plugin behavior.

The reviewed BigA package does not itself contain the BigTimer source, so the behavior and permissions of the required external component cannot be verified as part of this audit.

Attack Path

  1. A DSH user follows the prerequisite instruction.
  2. DSH resolves the mutable github:kobenfang/BigTimer repository reference.
  3. If the repository or maintainer account has been compromised, DSH retrieves attacker-modified plugin content.
  4. The plugin is installed with the permissions made available to DSH plugins.
  5. The malicious component executes when installed, initialized, or used to create or run scheduled tasks.

Impact Assessment

The exact impact depends on DSH's plugin sandbox and granted permissions, which are not defined in the reviewed files. Potential exposure includes the user's DSH workspace, scheduler, available environment variables, network access, and any messaging or filesystem capabilities granted to plugins. No evidence confirms that the current upstream repository is malicious; the vulnerability is the absence of immutable version and integrity controls.

Remediation
View remediation

Remediation Suggestions

  • Pin the plugin to a reviewed full commit hash or immutable signed release.
  • Publish and verify a cryptographic checksum before installation.
  • Prefer a signed package from a trusted registry with provenance metadata.
  • Vendor the minimal required scheduler implementation when practical so it is included in the reviewed artifact.
  • Document the plugin's required permissions and deny unrelated filesystem, credential, process, and network access.
  • Re-audit and require user approval before changing the pinned version.
  • Configure automated dependency monitoring without automatically executing unreviewed updates.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/biga-scan.py:31
Finding

Unauthenticated HTTP Market Data Can Be Intercepted and Manipulated

Content
View full analysis

Vulnerability Details

File Location: scripts/biga-scan.py:31-33,87-93,106-112,126-127
Vulnerability Type: Plaintext network transport for security-relevant input data
Risk Level: Medium

Vulnerable code:

python
req=urllib.request.Request(
    f"http://www.szse.cn/api/report/exchange/onepersistenthour/monthList?month={ym}"
)
req.add_header("User-Agent","Mozilla/5.0")
req.add_header("Referer","http://www.szse.cn/aboutus/calendar/index.html")
with urllib.request.urlopen(req,timeout=5)as r:
    d=json.loads(r.read().decode("utf-8"))
python
def _fetch(url):
 try: return urllib.request.urlopen(url, timeout=5).read().decode("gbk","ignore")
 except: return ""

futs[ex.submit(_fetch,f"http://qt.gtimg.cn/q={lk}")]=lk
python
req = urllib.request.Request(
    url,
    headers={
        'User-Agent': 'Mozilla/5.0',
        'Referer': 'http://finance.sina.com.cn'
    }
)
return urllib.request.urlopen(req, timeout=5).read().decode("gbk","ignore")
python
url = (
    f"http://money.finance.sina.com.cn/quotes_service/api/json_v2.php/"
    f"CN_MarketData.getKLineData?symbol={lk}&scale=240&ma=5"
    f"&datalen=10&r={time.time()}"
    if try_sina else
    f"http://web.ifzq.gtimg.cn/appstock/app/kline/getkline?"
    f"_var=kline_dayqfq&param={lk},day,,,10,qfq&r={time.time()}"
)
d=urllib.request.urlopen(url,timeout=5).read().decode("utf-8","ignore")

Technical Analysis

The scanner obtains the trading calendar, current quotes, and historical K-line data over unauthenticated HTTP. HTTP does not provide server authentication, confidentiality, or transport integrity. An attacker capable of observing or modifying traffic can identify requested symbols, replace API responses, inject malformed values, or force failures.

The returned values directly influence calculations such as PE scoring, trend analysis, entry readiness, br ...[truncated 1737 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace every HTTP endpoint with an HTTPS endpoint provided by the authoritative service.
  • Reject redirects that downgrade HTTPS connections to HTTP.
  • Use standard certificate and hostname verification; do not disable TLS validation.
  • Validate response schemas, expected field counts, dates, symbol identifiers, and plausible numeric ranges before using data.
  • Compare security-relevant values across independent authenticated sources and reject material discrepancies.
  • Distinguish an unavailable calendar service from a confirmed non-trading day; fail with an explicit unknown state rather than silently returning False.
  • Apply response-size limits and bounded parsing to reduce denial-of-service exposure.
  • Avoid logging or exposing complete watch lists unnecessarily.
  • If an authoritative source has no authenticated endpoint, clearly mark the data as unverified and prevent it from automatically generating actionable recommendations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (46)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list contains broad phrases such as update/help-style language that can easily appear in ordinary conversation, causing accidental activation. Because activation leads to script execution, searches, and messaging behavior, unintended triggers can produce unauthorized actions or noisy automated outputs.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
> - **OpenClaw**:脚本在技能目录下执行(`python3 scripts/biga-scan.py`),数据默认 `~/.openclaw/workspace/memory/`,定时推送走 `openclaw cron` + `openclaw message send`。

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly states that any trigger causes automatic execution without waiting for clarification. In a skill that can run scripts, perform network access, and send messages, that ambiguity materially raises the risk of unintentional execution and side effects from casual mentions of stock-related terms.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code accepts JSON content and destination parameters, then sends arbitrary content to an external messaging target via the openclaw CLI. That enables exfiltration of workspace data, prompt outputs, or attacker-crafted payloads to third-party recipients, especially because the function can also consume stdin/argv and fallback config without meaningful trust boundaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.