Back to skill

Security audit

Eastmoney Financial Search 1.0.2

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its setup instructions tell users to print an API key, which can leak the credential into logs or transcripts.

Review before installing. Use it only in a trusted environment, do not run the documented echo command for the API key, avoid logging request headers, and do not send confidential personal, business, or trading-strategy text as search queries.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:18
Finding

Plaintext API Key Disclosure Through Documented Environment Check

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18–20
Vulnerability Type: Plaintext credential exposure
Risk Level: Medium

Complete Code Snippet:

markdown
1. First check whether the environment variable `EASTMONEY_APIKEY` exists:
   ```bash
   echo $EASTMONEY_APIKEY
   ```

Technical Analysis

The documented environment check expands and prints the complete EASTMONEY_APIKEY value. This is not necessary to determine whether the variable is configured and contradicts the credential-protection statement elsewhere in the same document.

Terminal output can be retained in agent transcripts, CI/CD logs, shell-session recordings, monitoring systems, screenshots, or support records. Consequently, following the documented procedure may move a secret from a protected environment variable into less-protected output channels.

The executable script itself reads the key from the environment and sends it only to the declared HTTPS endpoint; the confirmed flaw is specifically the documentation instructing users or agents to disclose the value.

Attack Path

  1. A user or agent configures a valid EASTMONEY_APIKEY.
  2. The user or agent follows SKILL.md and runs echo $EASTMONEY_APIKEY.
  3. The shell expands the variable and writes the complete API key to standard output.
  4. The output is captured in an agent transcript, command log, CI record, terminal recording, screenshot, or another observable channel.
  5. An unauthorized party with access to that channel retrieves the key.
  6. The party reuses the credential against services that accept it, subject to the key's server-side permissions and limits.

Impact Assessment

The exposed privilege is limited to the authorization granted to the compromised Eastmoney API key. A successful attacker could potentially submit API requests as the key owner, consume quotas, generate costs if billing applies, or access any data and operations authori ...[truncated 160 chars]

Remediation
View remediation

Remediation Suggestions

Replace the plaintext disclosure command with a presence-only test that never emits the credential:

bash
if [ -n "${EASTMONEY_APIKEY:-}" ]; then
  echo "EASTMONEY_APIKEY is configured"
else
  echo "EASTMONEY_APIKEY is not configured"
fi

Additional hardening measures:

  • Explicitly instruct users and agents never to print, log, or include the API key in model responses.
  • Redact the apikey header in HTTP diagnostics, exception reporting, and observability systems.
  • Rotate the key if it may already have appeared in logs or transcripts.
  • Apply server-side least privilege, usage quotas, anomaly detection, and expiration where supported.
  • Keep the credential only in a trusted secret store or protected environment variable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tainted flow: 'headers' from os.getenv (line 26, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/search.py (reported line 35)May include surrounding context.

python
}
    
    try:
        response = requests.post(url, headers=headers, json=data)
        response.raise_for_status()
        result = response.json()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents code capabilities that access environment variables, perform network requests, and optionally save output to the working directory, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens runtime safety boundaries because an agent may invoke broader capabilities than reviewers or users expect, increasing the chance of unintended data exposure or filesystem writes.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The curl example transmits the user's query and an API key to an external API endpoint. While this is core to the skill's intended function and the endpoint appears to be the official service, it still constitutes outbound data transfer and credential use that could expose sensitive query content or be abused if the skill is run in inappropriate contexts.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

  1. 使用POST请求调用接口:
    bash
    curl -X POST --location 'https://mkapi2.dfcfs.com/finskillshub/api/claw/news-search' \
    --header 'Content-Type: application/json' \
    --header "apikey: $EASTMONEY_APIKEY" \
    --data '{"query":"用户的查询内容"}'
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The example code sends user-supplied query content to an external third-party API. Even though the skill states the data is for financial search and not intended to include sensitive data, the mechanism still enables exfiltration of user input to an external service, which is risky if prompts, confidential research, or personal data are passed through.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
"query": "立讯精密的资讯"
}

response = requests.post(url, headers=headers, json=data)
response.raise_for_status()
result = response.json()
print(result)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring and runtime messages are written only in Chinese, which imposes a specific language on all users. Under the policy, locale or language constraints should either be optional for the user or clearly documented as region-specific and justified; this file does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search.py (reported line 35)May include surrounding context.

python
}
    
    try:
        response = requests.post(url, headers=headers, json=data)
        response.raise_for_status()
        result = response.json()

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content in the manifest and README sections is written only in Chinese, which can amount to a language/locale policy constraint for users who do not read Chinese. The file does not indicate that the skill is region-specific or provide any user opt-in or alternative language support.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.