Back to skill

Security audit

DSA 股票智能分析 (daily_stock_analysis)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed stock-analysis API wrapper with some wording ambiguity, but no hidden code, persistence, privilege escalation, or deceptive behavior was found.

Install this only if you trust the DSA service configured in DSA_BASE_URL. Avoid sending sensitive personal or account information in stock-analysis prompts or agent chat, and confirm the intended ticker when using Chinese company names because the code/name mapping is not fully specified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill manifest says it only supports stock codes, but the body broadens scope by permitting Chinese-name-to-code mapping and by documenting a more general conversational agent endpoint. This mismatch can cause the orchestrator or user to invoke the skill in cases not clearly bounded by the manifest, increasing the chance of unintended data transmission or misuse of a broader backend capability.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger guidance says requests like '分析茅台' should use the skill while also stating Chinese names are unsupported, creating contradictory behavior. In practice this ambiguity can lead an agent to infer or transform user input beyond the declared interface, causing wrong-stock analysis or unanticipated external requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation condition says to use the skill whenever the user requests analysis of a stock, with examples like '分析茅台' and '帮我看看 600519'. This overlaps with common conversational phrasing and does not clearly define boundaries, exclusions, or an explicit trigger list, which could cause unintended invocation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill explicitly sends user-provided content to an external service endpoint (/api/v1/agent/chat) that supports multi-turn conversation. This increases exposure because arbitrary user text, session identifiers, and potentially sensitive investment context can be transmitted to a backend service, and the broader chat endpoint has a wider attack surface than the narrowly scoped analysis API.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

若 DSA 已启用 AGENT_MODE=true,可调用 Agent 策略问股接口,支持多轮对话与多种策略(缠论、均线金叉等):

bash
curl -X POST {DSA_BASE_URL}/api/v1/agent/chat \
  -H 'Content-Type: application/json' \
  -d '{"message": "用缠论分析 600519", "session_id": "optional-session-id"}'

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description is primarily written in Chinese and includes Chinese-specific invocation examples and constraints, but does not state that language choice is optional or user-selectable. This can create an implicit language/locale preference without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.