Back to skill

Security audit

个股分析大师:面向A股支持单股深度分析与多股对比(综合/技术面/财报/价值面)。触发词:个股分析、个股对比、财报对比、价值分析、技术分析、买卖点、基本面、选时、ST分析。适用场景:用户需要对一个或多个明确股票标的做结构化分析与对比。

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent stock-analysis helper, but it asks agents to run an unpinned third-party CLI with an API token, which needs review before installation.

Install only if you trust the `daxiapi-cli` supply chain and are comfortable giving it access to your DAXIAPI token. Prefer a pinned, reviewed CLI version, avoid printing tokens into logs or chat transcripts, validate stock codes before command execution, and run the CLI with minimal filesystem and environment access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:48
Finding

Execution of an Unpinned Third-Party CLI Package

Content
View full analysis
--type stock ``` ```bash # Single stock npx daxiapi-cli@latest stock info # Multiple stocks npx daxiapi-cli@latest stock info ,, ``` The same mutable package reference is used for other operations, including: ```bash npx daxiapi-cli@latest kline npx daxiapi-cli@latest report finance npx daxiapi-cli@latest stock capital-flow npx daxiapi-cli@latest sector heatmap --order cs --limit 20 ``` ### Technical Analysis The Skill repeatedly invokes `daxiapi-cli` through `npx` using the mutable `@latest` version selector. Depending on the local npm configuration and cache state, `npx` can download the selected package and execute its code immediately. Because `@latest` can resolve to a different release after the Skill has been audited, the effective executable payload is not fixed by the reviewed project. The project provides no exact version, lockfile, integrity hash, vendored implementation, publisher verification procedure, or other mechanism for ensuring that the executed package is the version that was security-reviewed. This creates a third-party supply-chain boundary. A malicious or compromised future package release could execute arbitrary code with the privileges of the process running the Skill. The danger is amplified because the CLI is intentionally given access to a DAXIAPI token. ### Attack Path 1. An attacker compromises the npm publisher account, the package repository ...[truncated 1441 chars]
Remediation
View remediation
``` 2. Maintain a lockfile and verify package integrity against an approved checksum or trusted artifact registry. 3. Document the expected npm package publisher, repository, package signature, and review process. 4. Prefer installing an approved version in a controlled build step rather than downloading executable code during every Skill invocation. 5. Disable or audit npm lifecycle scripts where operationally possible. 6. Run the CLI in a restricted environment with: - Minimum filesystem access. - Only the required environment variables. - Restricted outbound network access. - No administrator or root privileges. 7. Establish a dependency-update process that requires review and testing before changing the pinned version. 8. Rotate the DAXIAPI token if an untrusted or compromised package version may have been executed. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:48
Finding

Plaintext API Token Exposure Through Configuration Inspection

Content
View full analysis
Remediation
View remediation
config status ``` The output should indicate only whether a token is present and valid. 2. If the CLI lacks a status command, validate authentication through a harmless API request without printing the token. 3. Ensure token-display commands mask all but a small suffix, for example `****abcd`. 4. Accept tokens through a protected interactive prompt, operating-system credential store, or secret manager rather than ordinary command arguments. 5. Configure tool and terminal logging to redact `DAXIAPI_TOKEN` and recognized token patterns. 6. Do not include plaintext credentials in chat messages, command transcripts, examples, or diagnostic output. 7. Restrict token scope, lifetime, and API permissions to the minimum required. 8. Document token revocation and rotation procedures, and rotate any token that may already have appeared in logs. 9. Run third-party tools with a minimal environment so unrelated secrets are not inherited. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:63
Finding

Potential Shell Command Injection Through Unvalidated Template Parameters

Content
View full analysis
--type stock ``` ```bash # Single stock npx daxiapi-cli@latest stock info # Multiple stocks npx daxiapi-cli@latest stock info ,, ``` Other affected command templates include: ```bash npx daxiapi-cli@latest kline npx daxiapi-cli@latest report finance npx daxiapi-cli@latest sector stocks --code --order cs npx daxiapi-cli@latest stock capital-flow ``` ### Technical Analysis The placeholders for company names, stock codes, and sector codes are ultimately derived from user input. The instructions present these values as direct substitutions into shell command strings but do not require: - An explicit allowlist for stock or sector identifiers. - Argument-array execution that bypasses shell parsing. - Robust shell escaping. - Rejection of control characters or shell metacharacters. A legitimate A-share stock code is expected to be six digits, making strict validation straightforward. Company names can contain spaces and other characters and therefore require safe argument handling. If an Agent implementation constructs a single shell command by replacing the placeholders with raw user input, shell syntax embedded in that input may be interpreted as an additional command. The documentation alone does not prove that every execution environment uses a shell or performs unsafe interpolation. The vulnerability arises when these templates are implemented through common shell-based execution without validation, which the Skill currently permits and encourages. ### Attack Path 1. An attacker supplies a company name or alleged stock code containing shell metacharacters and an additional comman ...[truncated 1520 chars]
Remediation
View remediation
- search - - --type - stock shell: false ``` 4. Treat company names as a single literal argument and reject NUL bytes, line breaks, and control characters. 5. Do not rely solely on adding quotation marks; use a platform-aware process API that bypasses shell interpretation. 6. If shell execution is unavoidable, apply robust shell-specific escaping and reject command separators, substitutions, redirections, and expansion syntax. 7. Prefer resolving a company name to a validated six-digit code before executing subsequent commands. 8. Add negative tests covering spaces, quotes, line breaks, command separators, redirection characters, and substitution syntax. 9. Document that placeholders must never be replaced through raw string concatenation. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (53)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description lists trigger terms such as “价值分析”, “技术分析”, “基本面”, and “选时”, which are broad financial discussion phrases rather than narrowly scoped invocation cues. Because these can appear in ordinary conversation about markets without intending this specific skill, they create ambiguity about when the skill should activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire skill specification enforces Chinese-language interaction and output conventions, but it does not state that the user may choose another language or that the locale restriction is an intentional region-specific requirement. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The explicit trigger list includes generic terms like “基本面”, “买卖点”, “选股”, and “选时”, which can overlap with common investment conversation and adjacent skills. Although the document includes some non-use cases, it does not provide negative trigger examples clarifying when these broad phrases should not invoke this skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says the skill is not for scenarios that only request immediate buy/sell or position instructions, suggesting it should avoid operational trade directives. However, the report template later mandates output of 'current phase', 'entry conditions', bolded stop-loss, and target price, which are direct actionable trading instructions rather than just structured analysis.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill repeatedly instructs use of npx daxiapi-cli@latest, which fetches and executes the newest package version at runtime rather than a reviewed, fixed release. That creates a supply-chain execution risk: if the package or one of its dependencies is compromised, the agent could run attacker-controlled code when following the skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Using @latest in setup guidance causes runtime resolution of an unreviewed package version and can lead to arbitrary code execution through a compromised upstream release. Because this appears in authentication/bootstrap steps, it is especially likely to be executed early and broadly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The search command is invoked through npx ...@latest, so the skill depends on code downloaded at execution time. In an agent environment, that expands the attack surface from data retrieval to remote code execution via package supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command uses the latest published CLI version without verification, enabling unexpected behavior changes or malicious code execution if the package is tampered with. Since it is part of the normal data validation workflow, users and agents are likely to run it routinely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

A second normal-path command again relies on @latest, compounding the same supply-chain risk across common workflows. Repetition throughout the skill increases the probability that an agent will execute unreviewed code many times.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill's data-collection phase instructs runtime execution of the newest CLI release. In practice, that means the behavior and trust boundary can change without notice, which is unsafe for an agent expected to follow deterministic, reviewed tooling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This unpinned npx invocation exposes the agent to the same remote code execution and unexpected behavior risk as the others. Because it is used for market-data retrieval, an attacker compromising the package could abuse a high-frequency execution path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Fetching the latest CLI release at runtime for multi-stock information retrieval is a genuine supply-chain weakness. The issue is not the stock command itself but the dynamic installation/execution model embedded in the skill instructions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The unpinned kline command again depends on unaudited runtime package resolution. In an automated environment, this creates a path for code execution unrelated to the user’s requested analysis.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Another routine command uses @latest, so the agent's execution behavior is nondeterministic and vulnerable to compromised releases. The cumulative pattern across the file shows an operationally significant supply-chain flaw, not an isolated documentation typo.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Finance-report collection via npx ...@latest creates the same package substitution risk and could let an attacker run code under the guise of retrieving financial data. This is especially risky because financial-analysis paths may be triggered frequently by users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command inherits the full risk of dynamic package execution at runtime. Since the skill encourages repeated per-stock execution, exposure increases with every comparative analysis request.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The repeated unpinned invocation pattern indicates the skill is designed around live dependency fetching rather than a controlled runtime. That makes a compromise of the upstream package or registry materially dangerous.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Sector-analysis commands also use @latest, broadening the same supply-chain issue beyond bootstrap and quote retrieval into additional workflows. More command coverage means more opportunities for an agent to execute a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This is a true vulnerability because the command executes package code fetched at runtime from an unpinned latest release. In agent contexts, that can be exploited for arbitrary code execution or silent behavior manipulation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Market-temperature retrieval is another normal execution path using an unpinned npx package, so it carries the same high-confidence supply-chain risk. The context does not mitigate the issue because the danger comes from the execution mechanism, not the business domain.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The technical-analysis section again depends on @latest, making tool execution nondeterministic and susceptible to compromised releases. For security review purposes, this is a real vulnerability pattern repeated throughout the file.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command repeats the same unsafe dynamic package execution model. Even if the package is currently benign, the skill's design leaves future executions exposed to upstream compromise or breaking changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

In Step 2.4, the document explicitly says shape signals can be read directly from stock info and that there is no need to run stock pattern. Later, Step 3.2 states that pattern analysis comes from 'kline + stock pattern', which directly contradicts the earlier instruction about how the skill should operate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Capital-flow retrieval via unpinned npx ...@latest is another true supply-chain vulnerability. Because the skill provides direct execution instructions, an agent following them could unknowingly run malicious package code.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 492)May include surrounding context.

md
### 关联 Skill 与触发说明

- **daxiapi 路由入口 Skill**(数据获取基础,所有分析自动依赖)
  - 优先定位:`skills/daxiapi/SKILL.md`
  - 兜底方式:在当前环境搜索 `name: daxiapi`

- **财务深度分析 Skill**(财报对比或价值分析时自动联动)

Static analysis

No suspicious patterns detected.