Back to skill

Security audit

股票盯盯智能监控系统

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a stock-alerting purpose, but it handles sensitive trading data with local persistence and includes under-scoped Feishu notification behavior that should be reviewed before installation.

Review this skill before installing. Remove or replace the default Feishu target, confirm exactly whether alerts are sent externally, avoid putting sensitive cost-basis data in notifications unless you accept that exposure, and consider disabling or periodically deleting the local trader-pattern database/cache. Pin dependencies and harden control.sh PID handling before running it as a long-lived daemon or cron job.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
control.sh:32
Finding

Unvalidated PID File Can Cause Termination of an Unrelated Process

Content
View full analysis

Vulnerability Details

File Location: control.sh, lines 32-34
Vulnerability Type: Unsafe PID-file handling
Risk Level: Medium

bash
PID=$(cat "$PID_FILE")
kill $PID
rm "$PID_FILE"

Technical Analysis

The stop operation treats the contents of pid/stock-watcher.pid as a trusted process identifier. It does not verify that the value is numeric, confirm that the referenced process belongs to this Skill, or protect the value from being interpreted as an option by kill.

PID files can become stale when a process exits unexpectedly. Operating systems may subsequently reuse the same PID for an unrelated process. In that situation, invoking the stop command would send a termination signal to the unrelated process. A malformed value beginning with a hyphen could also be interpreted as an option or process-group selector because the command does not use kill -- "$PID".

Attack Path

  1. A stale or modified pid/stock-watcher.pid contains the PID of another process.
  2. The user invokes control.sh stop.
  3. The script reads the unvalidated value into PID.
  4. The script executes kill $PID without verifying process ownership or identity.
  5. If the caller has permission to signal the referenced process, that unrelated process is terminated.

Impact Assessment

Exploitation does not grant additional operating-system privileges. However, it can terminate an unrelated process that the current user is already authorized to signal, potentially causing denial of service, interrupted work, or loss of unsaved process state. A specially formed negative PID may broaden the effect to a permitted process group, depending on the shell and kill implementation.

Remediation
View remediation

Remediation Suggestions

  • Validate the PID with a strict numeric expression before passing it to kill.
  • Use kill -- "$PID" so the value cannot be parsed as an option.
  • Verify that the process exists with kill -0 -- "$PID".
  • Confirm process identity through /proc/$PID/cmdline, an expected executable path, or another platform-appropriate mechanism.
  • Detect and safely remove stale PID files instead of assuming that their existence means the monitor is active.
  • Reject symbolic links and create the PID file with restrictive permissions.
  • Quote all PID expansions.

Example hardening:

bash
PID=$(cat "$PID_FILE") || exit 1

case "$PID" in
    ''|*[!0-9]*)
        echo "Invalid PID file"
        exit 1
        ;;
esac

if ! kill -0 -- "$PID" 2>/dev/null; then
    echo "Removing stale PID file"
    rm -f -- "$PID_FILE"
    exit 1
fi

if ! tr '\0' ' ' < "/proc/$PID/cmdline" | grep -Fq "$MONITOR_PY"; then
    echo "PID does not belong to the stock monitor"
    exit 1
fi

kill -- "$PID"
rm -f -- "$PID_FILE"

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependency Is Not Reproducibly or Integrity Pinned

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, line 1
Vulnerability Type: Unpinned third-party dependency
Risk Level: Low

text
requests>=2.31.0

Related installation documentation also instructs users to install the package without a version or integrity constraint:

bash
pip install requests

Technical Analysis

The dependency declaration permits any version of requests equal to or newer than 2.31.0 and supplies no package hashes. Consequently, separate installations can resolve to artifacts that were not part of the audited project state.

The documented pip install requests command is even less restrictive because it does not enforce the minimum version from requirements.txt. Although no currently malicious dependency was identified, the installation process lacks reproducibility and integrity verification. This increases exposure to future upstream compromise, malicious package-index configuration, or an incompatible release.

Attack Path

  1. A user follows the documented installation command or installs from the open-ended requirements file.
  2. The configured Python package index resolves a newer or otherwise different artifact from the one reviewed during this audit.
  3. If the index or upstream release has been compromised, malicious package code can run during installation or when the Skill imports requests.
  4. That code executes with the privileges of the user running the installation or monitor.

This path is conditional on a package-index or upstream supply-chain compromise; the audit found no evidence that the current requests package is malicious.

Impact Assessment

A compromised resolved package could execute arbitrary Python code with the installing or runtime user's privileges. Its potential scope would include files, environment variables, network access, and processes available to that user. Under normal trusted-index conditions, the more ...[truncated 100 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specifically reviewed version instead of using an open-ended lower bound.
  • Generate and commit a lock file containing transitive dependency versions.
  • Record hashes for every resolved distribution and install with --require-hashes.
  • Update all documentation to install from the locked requirements file rather than using pip install requests.
  • Perform dependency updates through a controlled review and testing process.
  • Use an explicitly trusted package index in deployment environments.

Example installation pattern:

bash
python3 -m pip install --require-hashes -r requirements.lock
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Persisting trader-behavior patterns in SQLite and monkey-patching monitor logic are substantial functional departures from the stated seven-rule alerting purpose. This is risky because hidden stateful analytics and runtime code modification make the system harder to audit and may collect or infer sensitive trading behavior without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Persisting trader-behavior patterns in SQLite and monkey-patching monitor logic are substantial functional departures from the stated seven-rule alerting purpose. This is risky because hidden stateful analytics and runtime code modification make the system harder to audit and may collect or infer sensitive trading behavior without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Persisting trader-behavior patterns in SQLite and monkey-patching monitor logic are substantial functional departures from the stated seven-rule alerting purpose. This is risky because hidden stateful analytics and runtime code modification make the system harder to audit and may collect or infer sensitive trading behavior without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

Persisting trader-behavior patterns in SQLite and monkey-patching monitor logic are substantial functional departures from the stated seven-rule alerting purpose. This is risky because hidden stateful analytics and runtime code modification make the system harder to audit and may collect or infer sensitive trading behavior without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Persisting trader-behavior patterns in SQLite and monkey-patching monitor logic are substantial functional departures from the stated seven-rule alerting purpose. This is risky because hidden stateful analytics and runtime code modification make the system harder to audit and may collect or infer sensitive trading behavior without clear disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README consistently presents all user-facing instructions in Chinese and does not indicate that another language is available or that the skill is intentionally limited to Chinese-speaking users. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises operational commands and a file structure implying shell execution, file access, and likely network use, but it does not declare any tool scope or permissions. This creates a transparency and least-privilege problem: users and hosts cannot easily understand or constrain what the skill may access before installation or execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation indicates extra capabilities such as trader-behavior analysis and end-of-day summaries beyond the manifest's simpler 7-rule alert description. Security-relevant documentation inconsistencies can conceal additional data processing and retention that users would not reasonably expect from the declared scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Feishu push notifications can transmit sensitive portfolio and alert data to an external service, yet the documentation does not clearly warn users that stock-monitoring information leaves the local environment. In a financial monitoring context, this is particularly dangerous because holdings, costs, and timing signals can expose personal investment strategy and account-sensitive behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains all user-facing comments and setup instructions in Chinese, including installation steps and configuration guidance. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script contains user-facing comments and console output entirely in Chinese, including usage and operational status messages. Because the file does not offer any language selection or explain that it is intended only for a Chinese-speaking environment, it creates a natural-language locale policy concern under the requirement to avoid forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill hardcodes a default Feishu recipient ID, which means notifications can be routed to a specific external account even when the user has not explicitly configured a target. In a monitoring tool that emits potentially sensitive portfolio or trading-signal information, this creates a real privacy and data-exfiltration risk through unintended outbound messaging.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a stock monitoring and alerting system focused on seven concrete alert rule types such as cost percentage, moving-average crosses, RSI, volume anomalies, gaps, and trailing take-profit. This module instead introduces a separate behavior-profiling feature that learns supposed '操盘手' habits over time and generates trader profiles, which is a materially different capability from the stated alert-rule set.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Multiple docstrings, printed messages, and alert strings in this file are written exclusively in Chinese, including the main module description and runtime output. Under the language/locale policy, forcing a specific language without opt-in or an offered choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The integration hook monkey-patches the monitor class at runtime, silently persists learned behavior, and appends a new alert type without an explicit contract or disclosure. This kind of hidden behavioral modification can undermine caller assumptions, enable stealthy persistence of analysis data, and make downstream systems process alerts they were not designed to trust.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs users to configure Feishu push notifications with a user ID and demonstrates sending stock-monitoring alerts to an external messaging service, but it does not warn about data leaving the local environment. In the context of a trading-monitoring skill, these messages may disclose portfolio interests, watchlists, market behavior, and timing patterns to third-party infrastructure or unintended recipients if misconfigured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide instructs users to configure Feishu push notifications for stock alerts but does not clearly disclose that sensitive portfolio information, including holdings, cost basis, profit/loss, and trading signals, will be sent to an external messaging platform. In a stock-monitoring skill, that data is financially sensitive and could be exposed through misdelivery, account compromise, logging, or retention by third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to configure Feishu push delivery using a personal user ID, but does not clearly warn that stock watchlists, holdings cost basis, alert conditions, and potentially sensitive investment activity will be transmitted to an external messaging platform. This creates a privacy and data-sharing risk because users may unknowingly expose financial preferences and position information outside the local environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a stock monitoring and alerting system focused on concrete alert rules such as cost percentage, moving averages, RSI, volume, gaps, and trailing stops. This documentation additionally states that the system 'automatically learns trader behavior patterns' including time preferences, price behavior, volume behavior, and support/resistance identification, which is a materially broader behavioral-analysis capability not reflected in the stated 7-rule alert scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The description states the skill '符合中国投资者习惯(红涨绿跌)', and the feature section later reinforces this as the default convention. This is a locale-specific behavior presented as mandatory rather than optional, which can violate language/locale neutrality expectations when no user opt-in or clear region scoping is provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest claims a stock monitoring/alerting system centered on seven alert rules, but the changelog states v2.0 Pro版: 新闻舆情分析 at L203. News and sentiment analysis is a distinct capability beyond the narrow alert-rule description in the manifest.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified as requests>=2.31.0, which permits installation of any newer release without ensuring a tested, known-safe version. This weakens build reproducibility and can allow an affected or unexpected version to be installed later, especially relevant because requests has had multiple historical advisories.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest references requests without pinning an exact version, so it is impossible to verify from this file whether deployments will use a version affected by known requests CVEs. In a stock-watching skill that likely makes outbound HTTP requests to market or notification services, a vulnerable HTTP client library could expose credentials, weaken TLS/request validation, or leak sensitive request data depending on the runtime version installed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring presents the tool entirely in Chinese and describes its operation in that language, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. The same single-language constraint continues throughout user-facing output, which matches the policy category for language or locale restrictions without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script prints operational status messages such as start, skip, and completion notices exclusively in Chinese. Because these are user-visible strings and no language selection mechanism or locale justification is provided, this is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.