Back to skill

Security audit

Daily Stock Analysis (DSA 股票智能分析)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward wrapper for a configured stock-analysis REST API, with its network use and optional chat endpoint disclosed in the artifact.

Before installing, confirm that DSA_BASE_URL points to a DSA service you trust. If it is remote, stock codes, analysis prompts, optional chat messages, session identifiers, and any required cookies may be sent to that service. Avoid sending private financial details unless you control or trust the endpoint.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not warn users that their stock query will be transmitted to an external REST API endpoint defined by DSA_BASE_URL. This creates a transparency and privacy problem because users may reasonably believe analysis is local while their query content is sent to another service, potentially including remote infrastructure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger condition is broad enough that normal user requests like 'analyze AAPL' or stock-related discussion may invoke the skill without clearly signaling that data will be sent to an external service. This can cause unintended tool use and external disclosure of user-provided financial queries, especially when the user did not explicitly consent to API-backed analysis.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The optional agent chat workflow explicitly sends free-form user messages and a session identifier to an external endpoint, which can expose sensitive financial interests, conversation context, or identifiers to the DSA service. The risk is increased because the skill notes that remote deployment is supported and authentication may be absent by default, so user content could be transmitted to infrastructure outside the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

若 DSA 已启用 AGENT_MODE=true,可调用 Agent 策略问股接口,支持多轮对话与多种策略(缠论、均线金叉等):

bash
curl -X POST {DSA_BASE_URL}/api/v1/agent/chat \
  -H 'Content-Type: application/json' \
  -d '{"message": "用缠论分析 600519", "session_id": "optional-session-id"}'

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The description and examples are primarily written to handle Chinese requests and state support limitations in Chinese, while not documenting any user choice of language or locale behavior. This can be read as imposing a specific language/locale pattern without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.