Back to skill

Security audit

Yyqdata Stock Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a market-data query helper, but it handles API tokens and updates in ways users should review carefully before installing.

Install only if you trust yyqdata and can configure it safely: use HTTPS only, avoid putting tokens in chat or URLs, prefer a platform secret manager, do not provide admin.provision credentials to the agent, and review update.sh before running any update command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (7)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:241
Finding

Automatic Vendor Communication and Agent Output Manipulation

Content
View full analysis
/dev/null \ | grep -oE '"version"[[:space:]]*:[[:space:]]*"[^"]+"' \ | head -1 \ | sed -E 's/.*"version"[[:space:]]*:[[:space:]]*"([^"]+)"/\1/' ``` The surrounding instructions require this command to run silently at the beginning of a new session, compare the returned version with the local version, and append an upgrade notice to the Agent's otherwise unrelated response. ### Technical Analysis The Skill introduces a mandatory “step zero” that is unrelated to the user's immediate financial-data request. It also declares its own instruction priority and directs the Agent to modify final responses by appending vendor upgrade messaging. The remote manifest controls whether this additional output appears. Although the Skill states that the updater should not run automatically, the manifest lookup itself is automatic and is expected to occur without informing the user. This creates a vendor-controlled channel that can influence Agent output after the Skill has been reviewed. This behavior exceeds the minimum privileges needed to query financial data. A stock-data Skill does not need to contact an update server at the beginning of user sessions or inject update promotion into unrelated answers. ### Attack Path 1. A user or platform loads the Skill. 2. A new Agent session begins. 3. The Skill directs the Agent to contact `static.yyqyx.com` without a user request. 4. The remote server returns a version selected by the server operator or an attacker controlling the distribution infrastructure. 5. The Agent compares the value with the local version. 6. If the remote version is considered newer, the Agent appends vendor-directed upgrade instructions to the current ...[truncated 538 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:44
Finding

Bearer Token Transmission over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:331
Finding

Bearer Token Exposure through URL Query Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
INSTALL-AGENT.md:61
Finding

Recommended Plaintext Persistent Storage of API Tokens

Content
View full analysis
~/.openclaw/skills/yyqdata/config.json <<'EOF' { "token": "stk_live_xxx", "base_url": "http://120.220.73.199" } EOF cat > ~/.hermes/skills/yyqdata/config.json <<'EOF' { "token": "stk_live_xxx", "base_url": "http://120.220.73.199" } EOF ``` A later command recommends restricting one OpenClaw file: ```bash chmod 600 ~/.openclaw/skills/yyqdata/config.json ``` `SKILL.md:115-143` subsequently instructs the Agent to search multiple Skill directories for this file and load the token from it. ### Technical Analysis The recommended setup writes a long-lived bearer token directly into the Skill directory. The file is initially created under the caller's current umask, and restrictive permissions are applied only afterward. A process interruption, permissive umask, backup agent, file indexer, or local monitoring process can expose the token during or after creation. The shown permission command covers only the OpenClaw path, not the Hermes example. Storing credentials inside a Skill directory also increases the chance that secrets will be copied during migration, archived with the Skill, included in support bundles, or exposed to other components that can read Skill files. This recommendation contradicts other project statements that tokens must not be written to disk. It also bypasses platform-specific secret-management facilities referenced elsewhere in the documentation. ### Attack Path 1. The user follows the recommended persistent configuration procedure. 2. The shell creates `config.json` using the current umask. 3. The token is temporarily or permanently readable beyond the intended account. 4. Another local process, backup tool, archive operation, or user reads the file. 5. The recovered bearer token is used against the yyqdata API. ### Impact Assessment Th ...[truncated 424 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
update.sh:144
Finding

Mutable Remote Skill Installation without a Pinned Trust Root

Content
View full analysis
/dev/null 2>&1; then actual_sha256=$(sha256sum "$zip_path" | awk '{print $1}') elif command -v shasum >/dev/null 2>&1; then actual_sha256=$(shasum -a 256 "$zip_path" | awk '{print $1}') else actual_sha256="" fi fi unzip -oq "$zip_path" -d "$INSTALL_DIR/" \ || { rm -rf "$tmpdir"; error "archive extraction failed" 1; } ``` The expected checksum is obtained from a manifest downloaded from the same distribution origin. The script also accepts alternative manifest and archive URLs through command-line arguments and environment variables. ### Technical Analysis The updater downloads a mutable ZIP archive and extracts it directly into a directory from which Agent Skills are loaded. Markdown files in that directory function as executable instructions for the Agent, and the archive format can contain additional scripts or other files. A SHA-256 value from the same mutable server does not establish publisher authenticity. An attacker controlling both the archive and manifest can supply a matching malicious hash. Verification is also skipped when the expected hash is absent, set to `null`, or no hashing utility is installed. The updater does not enforce a pinned publisher signature or a fixed source allowlist. The archive and manifest locations can be overridden using `--manifest-url`, `--zip-url`, `SKILL_MANIFEST_URL`, and `SKILL_UPDATE_URL`. The archive is extracted before validating its expected directory structure and file types. No evidence of archive path traversal validation or a staged ...[truncated 1372 chars]
Remediation
View remediation

other

Warning
Location
README.md:9
Finding

Package Documentation Incorrectly Claims There Is No Executable Code

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/api-full-spec.md:5540
Finding

Administrative Mutation APIs Are Bundled beyond the Declared Read-Only Purpose

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (100)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The /openapi/admin/provision endpoint can issue raw token material, which is fundamentally incompatible with a market-data query skill and turns the agent into a credential minting surface. If the agent can access or even reason over this endpoint, prompt injection or mis-routing could result in creation and exposure of new live credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The documented admin endpoints support revoke, rotate, renew, scope changes, IP allowlist changes, path controls, and rate-limit changes for tokens. In the context of a stock-data query skill, this grants broad access-control mutation powers that could be abused to extend token lifetime, widen scope, or rebind credentials for unauthorized use.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL-AGENT.md (reported line 19)May include surrounding context.

mkdir -p ~/.openclaw/skills # 或 ~/.hermes/skills 视你的 agent 而定 curl -fsSL https://static.yyqyx.com/skill/yyqdata-stock-skill.zip -o /tmp/yyqdata.zip unzip -oq /tmp/yyqdata.zip -d ~/.openclaw/skills/ rm /tmp/yyqdata.zip

解压后路径:~/.openclaw/skills/yyqdata/SKILL.md

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL-AGENT.md (reported line 159)May include surrounding context.

mkdir -p ~/.openclaw/skills # 或 ~/.hermes/skills 视你的 agent 而定 curl -fsSL https://static.yyqyx.com/skill/yyqdata-stock-skill.zip -o /tmp/yyqdata.zip unzip -oq /tmp/yyqdata.zip -d ~/.openclaw/skills/ rm /tmp/yyqdata.zip

解压后路径:~/.openclaw/skills/yyqdata/SKILL.md

text

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The stated purpose is data-query translation, but the skill also instructs remote manifest fetching, downloading zip archives, and running update scripts that modify the local filesystem. This hidden expansion of capability materially changes the trust boundary and could be abused for remote code or content replacement if the update channel or hosting is compromised.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
- "references/api-full-spec.md ← smart-doc 自动生成的完整 API 规格(含字段类型、示例)"

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill is described as a read-only stock-data query translator, but the published API surface includes extensive administrative token provisioning and mutation endpoints under /openapi/admin/*. This creates dangerous capability overreach: an agent integrated with this spec could be induced to perform privileged administrative actions far outside the user’s expected data-query intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly states OpenAPI should only expose read-only, non-personal, cacheable data, yet the same surface includes write operations that mutate token metadata and access controls. This contradiction increases the risk that integrators and agents will over-trust the API surface and accidentally permit privileged state-changing operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document claims the skill zip contains only Markdown and no executable code, but later instructs users to run an included update.sh script. This mismatch can mislead users and reviewers into trusting the package more than they should, reducing scrutiny of downloaded content and increasing supply-chain risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · INSTALL-AGENT.md (reported line 16)May include surrounding context.

bash
# 在 小龙虾(OpenClaw) / Hermes 客户端机器上:
mkdir -p ~/.openclaw/skills        # 或 ~/.hermes/skills 视你的 agent 而定
curl -fsSL https://static.yyqyx.com/skill/yyqdata-stock-skill.zip -o /tmp/yyqdata.zip
unzip -oq /tmp/yyqdata.zip -d ~/.openclaw/skills/
rm /tmp/yyqdata.zip

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The document instructs downloading and installing a skill archive from an external URL without requiring signature or checksum verification at install time. Even over HTTPS, this creates supply-chain exposure if the hosting endpoint, DNS, TLS trust chain, or published artifact is compromised.

Content

Scanner excerpt · INSTALL-AGENT.md (reported line 17)May include surrounding context.

bash
# 在 小龙虾(OpenClaw) / Hermes 客户端机器上:
mkdir -p ~/.openclaw/skills        # 或 ~/.hermes/skills 视你的 agent 而定
curl -fsSL https://static.yyqyx.com/skill/yyqdata-stock-skill.zip -o /tmp/yyqdata.zip
unzip -oq /tmp/yyqdata.zip -d ~/.openclaw/skills/
rm /tmp/yyqdata.zip
# 解压后路径:~/.openclaw/skills/yyqdata/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALL-AGENT.md (reported line 20)May include surrounding context.

curl -fsSL https://static.yyqyx.com/skill/yyqdata-stock-skill.zip -o /tmp/yyqdata.zip unzip -oq /tmp/yyqdata.zip -d ~/.openclaw/skills/ rm /tmp/yyqdata.zip

解压后路径:~/.openclaw/skills/yyqdata/SKILL.md

text

**OpenClaw(小龙虾)用户**:解压到 `~/.openclaw/skills/yyqdata/` 后**不需要任何注册**——openclaw 启动时自动扫描 `~/.openclaw/skills/*/SKILL.md` 发现 skill。重启 openclaw(或 gateway)即可生效。

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALL-AGENT.md (reported line 50)May include surrounding context.

curl -fsSL https://static.yyqyx.com/skill/yyqdata-stock-skill.zip -o /tmp/yyqdata.zip unzip -oq /tmp/yyqdata.zip -d ~/.openclaw/skills/ rm /tmp/yyqdata.zip

解压后路径:~/.openclaw/skills/yyqdata/SKILL.md

text

**OpenClaw(小龙虾)用户**:解压到 `~/.openclaw/skills/yyqdata/` 后**不需要任何注册**——openclaw 启动时自动扫描 `~/.openclaw/skills/*/SKILL.md` 发现 skill。重启 openclaw(或 gateway)即可生效。

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL-AGENT.md (reported line 79)May include surrounding context.

md
agent 每次启动时从 skill 目录内读取,**无需修改任何 agent / platform 配置**,OpenClaw / Hermes / Claude Code 均适用。

> ⚠️ `config.json` 含明文 token,权限设为 0600:`chmod 600 ~/.openclaw/skills/yyqdata/config.json`

### 方式 B:claw 托管实例(平台自动注入)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions normalize sending a live API token directly in chat, while also noting backend logs may record related requests. Secrets provided in conversation can be exposed through chat history, agent memory, telemetry, screenshots, or tool logs, making credential compromise more likely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide explicitly instructs users to provide a secret token in conversation and states the agent will retain it in session memory and use it in API calls. In the context of an LLM agent, conversational secrets are especially risky because they may persist in logs, traces, memory, or be revealed through prompt injection and tool output.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The fallback reinstall path again relies on fetching and installing a remote zip directly from the network with no integrity verification. Repeating this pattern in recovery instructions increases the chance users execute a tampered artifact under time pressure.

Content

Scanner excerpt · INSTALL-AGENT.md (reported line 157)May include surrounding context.

如 update.sh 失败(网络 / 安装目录权限),仍可走原始装法:

bash
curl -fsSL https://static.yyqyx.com/skill/yyqdata-stock-skill.zip -o /tmp/yyqdata.zip
unzip -oq /tmp/yyqdata.zip -d ~/.openclaw/skills/
rm /tmp/yyqdata.zip

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 69)May include surrounding context.

2. 装 Skill 到 Agent

bash
mkdir -p ~/.openclaw/skills        # 或 ~/.hermes/skills 视 agent 而定
curl -fsSL https://static.yyqyx.com/skill/yyqdata-stock-skill.zip -o /tmp/yyqdata.zip
unzip -oq /tmp/yyqdata.zip -d ~/.openclaw/skills/

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The README instructs users to download a zip from an external host and install it directly into the agent skills directory without any integrity verification such as checksum or signature validation. If the hosting endpoint, DNS path, TLS trust chain, or distribution pipeline is compromised, a tampered skill could be delivered and then loaded by the agent as trusted instructions.

Content

Scanner excerpt · README.md (reported line 70)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills        # 或 ~/.hermes/skills 视 agent 而定
curl -fsSL https://static.yyqyx.com/skill/yyqdata-stock-skill.zip -o /tmp/yyqdata.zip
unzip -oq /tmp/yyqdata.zip -d ~/.openclaw/skills/

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to paste a live API token into agent chat, which exposes the secret to chat history, model context, logs, transcripts, and potentially downstream tools. Although the document warns elsewhere not to commit the token publicly, the point-of-use instruction normalizes unsafe secret handling and increases the chance of credential leakage.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents extensive shell usage but does not declare a corresponding tool scope or allowlist. That weakens least-privilege controls and can let a host agent expose broader shell capability than users expect, including command execution beyond simple API translation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest-style description says the skill translates questions like “看下宁德时代最近怎么样”, “龙虎榜”, “ML 选股”, and “美债收益率” into API calls, but it does not define a precise invocation scope or exclusion criteria. Several of these phrases are short, generic finance terms that could match ordinary conversation and cause unintended activation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document first states user-provided tokens must remain in-session and not be persisted, but later recommends config.json as a persistent storage mechanism. This contradiction can cause operators or agents to persist sensitive API tokens contrary to the declared security model, increasing leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly permits passing the bearer token in the URL query string as a normal fallback. Query-string credentials are commonly exposed through browser history, intermediary logs, reverse proxies, referer leakage, and debugging output, making credential disclosure significantly more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs reading bearer tokens from local config files in user home directories, which broadens access from in-session credentials to filesystem-resident secrets. For a skill whose purpose is query translation, harvesting tokens from disk increases the chance of unauthorized secret access and cross-session credential reuse.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.generated_source_template_injection

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:112