Back to skill

Security audit

A股多智能体投研-15 AI 分析师

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed stock-analysis API client, but it can send its bearer token to a configurable non-HTTPS endpoint, so users should review it before installing.

Install only if you are comfortable sending stock-analysis requests and a TradingAgents API token to the configured backend. Keep the default HTTPS endpoint or use an HTTPS self-hosted endpoint; do not set TRADINGAGENTS_API_URL to plain HTTP except possibly loopback-only local testing with a disposable token. Use a least-privilege token, rotate it if exposed, and require confirmation before the agent submits analysis jobs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/analyze.sh:25
Finding

Bearer Token May Be Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/analyze.sh:25-26, 55-57, 94-95, 176; related insecure configuration guidance at SKILL.md:178-179
Vulnerability Type: Sensitive credential transmission over an unencrypted connection
Risk Level: High

Complete Code Snippets

The documentation explicitly permits an HTTP API endpoint while configuring a bearer token:

bash
export TRADINGAGENTS_API_URL="http://your-server:8000"
export TRADINGAGENTS_TOKEN="ta-sk-your_key_here"

The script accepts that endpoint without validating its scheme:

bash
API_URL="${TRADINGAGENTS_API_URL:-https://api.510168.xyz}"
TOKEN="${TRADINGAGENTS_TOKEN:?Please set the TRADINGAGENTS_TOKEN environment variable}"

The token is then attached to submission, polling, and result requests:

bash
resp=$(curl -s -w "\n%{http_code}" -X POST "${API_URL}/v1/analyze" \
  -H "Authorization: Bearer ${TOKEN}" \
  -H "Content-Type: application/json" \
  -d "$payload")
bash
resp=$(curl -s "${API_URL}/v1/jobs/${job_id}" \
  -H "Authorization: Bearer ${TOKEN}")
bash
resp=$(curl -s -w "\n%{http_code}" "${API_URL}/v1/jobs/${job_id}/result" \
  -H "Authorization: Bearer ${TOKEN}")

The batch polling path has the same behavior:

bash
resp=$(curl -s "${API_URL}/v1/jobs/${jid}" -H "Authorization: Bearer ${TOKEN}")

Technical Analysis

The configurable API URL is used directly without requiring HTTPS. Although the default hosted endpoint uses HTTPS, the documented self-hosting configuration explicitly uses http://. Every API operation supplies TRADINGAGENTS_TOKEN in the Authorization header.

When the endpoint is HTTP, transport encryption and server authentication are absent. Any party able to observe or intercept traffic—such as an untrusted Wi-Fi operator, compromised router, malicious proxy, or adjacent network attacker—can obtain the bearer token. Because a bearer credential proves authorization solely through possession, the captured val ...[truncated 1747 chars]

Remediation
View remediation

Remediation Suggestions

  1. Validate TRADINGAGENTS_API_URL before making any request and reject non-HTTPS schemes by default.
  2. If plaintext HTTP is needed for local development, permit it only for loopback hosts such as 127.0.0.1, localhost, and ::1.
  3. Require an explicit, prominently named opt-in such as ALLOW_INSECURE_HTTP_FOR_LOCAL_DEVELOPMENT=1 for any exceptional HTTP use.
  4. Replace the documentation's http://your-server:8000 example with an HTTPS endpoint and provide TLS termination guidance for self-hosted deployments.
  5. Configure curl with secure transport options such as --proto '=https' --tlsv1.2 for non-loopback endpoints.
  6. Do not introduce --insecure or disable certificate verification.
  7. Use narrowly scoped, short-lived tokens where supported, and provide clear token rotation and revocation procedures.
  8. Add automated tests verifying that remote HTTP endpoints are rejected before the bearer token is transmitted.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: tradingagents-analysis
version: 0.6.1
description: >-
  A股多智能体 AI 投研分析工具 — 15 名 AI 分析师协作完成技术分析、基本面分析、
  市场情绪研判、资金流向追踪(北向资金/主力资金)、宏观经济分析及博弈论推演,
  输出结构化买卖建议与风险评估。支持沪深 A 股股票代码和中文名称。
  Multi-agent AI stock analysis for China A-shares.
  15 specialized analysts collaborate across technical analysis, fundamental analysis,
  sentiment analysis, smart money flow tracking, macro economics, and game theory
  to deliver structured buy/sell/hold reco

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/analyze.sh (reported line 73)May include surrounding context.

sh
while true; do
    local resp
    resp=$(curl -s "${API_URL}/v1/jobs/${job_id}" \
      -H "Authorization: Bearer ${TOKEN}")

    status=$(echo "$resp" | python3 -c "import sys,json; print(json.load(sys.stdin)['status'])")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/analyze.sh (reported line 185)May include surrounding context.

sh
[ "${DONE_MAP[$jid]:-}" ] && continue

    resp=$(curl -s "${API_URL}/v1/jobs/${jid}" -H "Authorization: Bearer ${TOKEN}")
    status=$(echo "$resp" | python3 -c "import sys,json; print(json.load(sys.stdin)['status'])")

    if [ "$status" = "completed" ] || [ "$status" = "failed" ]; then

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly instructs use of Bash and curl to call external services, but it does not declare a restrictive tool scope such as permissions or allowed-tools. This creates an overbroad execution surface where a host agent may grant shell access more generally than necessary, increasing the chance of unintended command execution or abuse if the skill is triggered in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are broad natural-language stock questions that overlap with ordinary conversation, making accidental invocation likely. Because invocation leads to external API calls and use of credentials, a casual user query could unintentionally send data or consume privileged backend resources without clear confirmation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill sends data and a bearer token to an external backend API. Even though the document claims only symbol/date/horizon fields are transmitted, this still constitutes outbound data flow to a third-party endpoint and exposes a credential during network operations, so misuse, endpoint compromise, or misconfiguration could affect confidentiality and account security.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

  1. 提交分析任务
bash
curl -X POST "${TRADINGAGENTS_API_URL:-https://api.510168.xyz}/v1/analyze" \
  -H "Authorization: Bearer $TRADINGAGENTS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"symbol": "贵州茅台"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/analyze.sh (reported line 50)May include surrounding context.

sh
local payload resp http_code body job_id

  payload=$(_build_payload "$symbol")
  resp=$(curl -s -w "\n%{http_code}" -X POST "${API_URL}/v1/analyze" \
    -H "Authorization: Bearer ${TOKEN}" \
    -H "Content-Type: application/json" \
    -d "$payload")

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This shell script reads the sensitive environment variable TRADINGAGENTS_TOKEN and then uses it in Authorization headers for outbound HTTP requests. Although the file documents that the token is required, there is no explicit user-facing warning about handling credentials or that the token will be transmitted to a remote API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script sends user-provided symbols, trade dates, and horizons to a remote API via curl. While this is part of the script's functionality, the file does not clearly disclose in user-facing output or safety comments that supplied inputs are transmitted off-host to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.