Back to skill

Security audit

Akshare

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward AKShare financial-data helper; it has some local CSV-writing and dependency-hardening caveats, but no evidence of hidden, deceptive, persistent, or destructive behavior.

Install and run this in a virtual environment, review AKShare before installing, and be aware that the included helper scripts save CSV files in the working directory. Use normal stock-code and date inputs rather than untrusted strings.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_stock_history.py:49
Finding

Path Traversal Through Unsanitized Output Filename Components

Content
View full analysis
2 else None end_date = sys.argv[3] if len(sys.argv) > 3 else None adjust = sys.argv[4] if len(sys.argv) > 4 else "qfq" get_stock_history(symbol, start_date, end_date, adjust) ``` ### Technical Analysis The `symbol`, `start_date`, and `end_date` values originate from command-line arguments and are used directly to construct `output_file`. No validation restricts these values to their documented formats, and no check ensures that the resolved output path remains within an approved directory. An attacker who can control the script arguments can include absolute paths, path separators, or traversal sequences such as `../`. Python's `DataFrame.to_csv()` then creates or truncates the resulting path. Although the fixed separators and `.csv` suffix limit exact filename selection, an attacker can still redirect output to an unintended writable directory and overwrite a file whose resulting name matches the constructed path. ### Attack Path 1. The attacker obtains the ability to invoke the script or influence its command-line arguments. 2. The attacker supplies a `symbol`, `start_date`, or `end_date` containing an absolute path or traversal components. 3. The values are passed unchanged to `get_stock_history()`. 4. The script interpolates the attacker-controlled values into `output_file`. 5. `df.to_csv()` creates or truncates that path using the privileges of the Python process. 6. Financial CSV content ...[truncated 672 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:134
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
``` 2. Maintain dependencies in a lock file or hashed requirements file. For example: ```text akshare== \ --hash=sha256: ``` 3. Install with hash enforcement where practical: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Pin and review transitive dependencies using a reproducible dependency-management process. 5. Remove unconditional `--upgrade` from routine installation instructions. 6. Perform dependency vulnerability and provenance checks before updating the pinned version. 7. Install dependencies in an isolated virtual environment under a non-privileged account. ]]>
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes the skill as fetching Chinese market data using AKShare, which implies retrieval of financial information. This script additionally persists the full dataset to disk as market_overview.csv, a behavior not reflected in the stated fetch-focused description and not necessary to simply obtain market data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes this skill as fetching Chinese market data, which implies retrieval and return of financial information. This script additionally persists the data to disk as a CSV file, which is a materially broader behavior than simple data fetching and is not mentioned in the manifest or the file's own top-level usage text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The API reference requires Chinese-language literals such as "全部", "股票型", "单位净值走势", and exchange labels like "中金所"/"上期所" in examples, but the document does not explicitly state that this skill or reference is China-market/Chinese-locale specific. Under the policy, forcing a specific language or locale without opt-in or clear justification can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes the skill as fetching Chinese stock market data, including A-shares, Hong Kong stocks, futures, funds, and macroeconomic indicators from Chinese markets. This reference file explicitly includes US stocks and US GDP functions, which broadens the documented behavior beyond the stated Chinese-market scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script performs a local file write by saving the full dataset to market_overview.csv. Although it prints the save path after writing, there is no advance disclosure in the top-level usage text or function docstring that running the script will create or overwrite a local file.

Content

No source excerpt is available for this finding.