Back to skill

Security audit

A-Stock Reporter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed A-share market reporting helper with some documentation and dependency hygiene issues, but no evidence of hidden control, credential access, exfiltration, or destructive behavior.

Install this only if you are comfortable with a Chinese-language A-share reporting tool that fetches public market data from third-party sources. Use a virtual environment, pin dependencies before installing, avoid relying on the generated market stance as financial advice, and only add the cron entries if you intentionally want scheduled reports.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:128
Finding

Unpinned and Unnecessary Third-Party Dependencies

Content
View full analysis
Remediation
View remediation
requests== ``` 3. Generate and verify cryptographic hashes, for example with `pip-tools`, and install using: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Pin and review transitive dependencies through a lock file. 5. Run dependency vulnerability and provenance checks in CI. 6. Install dependencies inside a dedicated, non-privileged virtual environment rather than into a system Python environment. 7. Periodically update pins through an explicit review process rather than automatically accepting the newest releases. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/historical_report.py:23
Finding

Historical Financial Data Retrieved over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code does match part of the declared purpose: it generates a current A股 market brief using live A-share data and does not appear to handle non-A-share assets. However, several declared core capabilities are absent from this code chunk. There is no interface for querying a specific stock, no logic for historical report lookup, no scheduled/cron trigger handling, and no push/delivery mechanism. Additionally, the docstring says '板块表现' but the implementation does not actually compute or output sector performance. This is not an undeclared dangerous capability; rather, the description overstates the implemented functionality relative to the provided code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个较完整的A股报告与推送技能,包含主动查询、市场简报、历史日报、以及定时触发报告等多项能力。而实际代码只覆盖了其中很小一部分:实时查询一个或多个股票/指数并打印行情。没有看到任何定时任务、历史数据访问、日报存储/检索、市场简报汇总、推送机制或触发器相关实现。因此描述显著高于代码实际能力,属于描述与行为不一致。尽管“查询个股”这一点与代码部分吻合,但整体主功能范围明显不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad activation phrases can cause the skill to trigger in unintended contexts, which increases the chance of accidental tool use, unnecessary network access, or confusion during unrelated conversations. In an agent environment, overbroad invocation expands the attack surface for prompt-triggering and can route user requests into functionality they did not intend to invoke.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The entire skill description and invocation vocabulary are defined only in Chinese, with no indication that users may choose another language or that the Chinese-only constraint is an intentional opt-in. Under the policy, locale or language restrictions should either offer user choice or be clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly limits the skill to A股 and says it is not for 港股. In the 科技 sector components, code '00700' corresponds to Tencent, a Hong Kong-listed security, so the bundled reference data expands the skill's apparent coverage beyond its declared A-share-only scope.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/cron_runner.sh (reported line 3)May include surrounding context.

sh
#!/bin/bash
# A股交易时段自动推送脚本
# 添加到 crontab: crontab -e

SKILL_DIR="/root/.openclaw/workspace/skills/a-stock-reporter"
VENV="/root/.openclaw/workspace/venv/bin/activate"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language docstrings and CLI/help/output text in Chinese, starting with the module docstring and continuing throughout the script. Because the skill forces a specific language without user opt-in or an explicit justification that it is a region-specific tool, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and all user-facing output are hardcoded in Chinese, indicating the skill is designed to operate only in a specific language. The provided policy requires flagging language or locale constraints when the skill does not offer user opt-in or clearly document a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes the skill as supporting A-share stock queries, market briefs, and historical daily reports, and explicitly says it is not for non-A-share assets. This script's documented and implemented interface also accepts index symbols such as sh000001, sz399001, and sz399006, which are market indices rather than individual A-share stocks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's docstrings, CLI description, help text, and generated output strings are all fixed in Chinese, with no option for the user to select another language. This is a natural-language policy concern because the skill imposes a specific locale by default rather than offering opt-in or documenting a justified region-only constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON file contains user-facing natural-language labels and descriptions entirely in Chinese, including watchlist names, descriptions, conditions, and actions. Under the policy criteria, forcing a specific language without user opt-in or documented locale justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file-level description and all user-facing messages are written only in Chinese, which effectively constrains the skill's language/locale behavior. There is no indication that the user can choose another language, and no documented justification that this is a region-specific or compliance-bound tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.