Back to skill

Security audit

stock-analysis-lianghua

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stock-analysis purpose, but its bundled script uses the stock symbol directly in cache file paths, creating a local file read/write boundary risk.

Review before installing or running on untrusted input. The skill is not deceptive and does not install persistence, but the analysis script should validate stock symbols, escape glob input, and enforce cache-directory containment before it is used broadly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
analyze_stock.py:58
Finding

Unsanitized Stock Symbol Permits Cache Path Traversal and Glob Injection

Content
View full analysis
str | None: """在缓存目录中查找已有的数据文件,优先选最新的。""" candidates = [] for cache_dir in CACHE_DIRS: pattern = os.path.join(cache_dir, f"{symbol}-YFin-data-*.csv") candidates.extend(glob.glob(pattern)) if not candidates: return None candidates.sort(key=os.path.getmtime, reverse=True) return candidates[0] ``` ```python def _save_cache(data: pd.DataFrame, symbol: str, start_date, curr_date: str): """保存数据到缓存目录。""" try: cache_dir = CACHE_DIRS[0] os.makedirs(cache_dir, exist_ok=True) start_str = start_date.strftime("%Y-%m-%d") if hasattr(start_date, "strftime") else str(start_date)[:10] cache_file = os.path.join(cache_dir, f"{symbol}-YFin-data-{start_str}-{curr_date}.csv") data.to_csv(cache_file, index=False) except Exception: pass ``` ```python symbol = args.symbol.upper() ``` ### Technical Analysis The positional `symbol` argument is controlled by the command-line caller. The application only converts it to uppercase and does not validate it against an allowed stock-symbol syntax. The resulting value is embedded directly in two security-sensitive filesystem operations: 1. `_find_cached_file()` incorporates it into a `glob.glob()` pattern. 2. `_save_cache()` incorporates it into a cache output path. Uppercasing does not remove directory separators, `..` path components, absolute-path prefixes, or glob metacharacters such as `*`, `?`, and character classes. A crafted symbol can therefore alter the intended path or glob pattern instead of being treated as an ordinary filename component. The cache lookup is particularly exposed because traversal and wildcard syntax can make the search inspect matching CSV fi ...[truncated 2506 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
脚本位置:`.cursor/skills/stock-analysis/analyze_stock.py`(项目根目录也有一份副本 `analyze_stock.py`)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs execution of a Python script that reads local files and performs network access, but the skill metadata does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: an agent may use capabilities broader than a user or orchestrator expects, increasing the chance of unintended data access or external communication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation states that the script automatically fetches data from external HTTP sources and writes successful results into a local cache directory, but it does not present this as a user-visible warning or require confirmation. Hidden network egress and filesystem modification are risky because they can expose usage patterns, introduce untrusted remote data into the workflow, and alter local state unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The note says all analysts output Chinese and that system messages are uniformly written in Chinese. This is a natural-language locale policy constraint that forces a specific language choice without offering the user an option or explaining a justified regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code hard-codes the Accept-Language header to en-US,en;q=0.9 for Google Finance requests. That is a natural-language/locale policy concern because it imposes a specific locale preference without offering user opt-in or explaining why English is required.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest emphasizes analyzing stocks and, separately, modifying analyst nodes in TradingAgentsV2. In this script, analysis is accompanied by filesystem writes via _save_cache, creating CSV files under project cache paths, which is broader than a purely analytical/read-only behavior implied by the standalone analysis use case.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The printed message explicitly states Yahoo Finance as the source, while fetch_data actually attempts Stooq, then Yahoo Chart API, then yfinance, and finally local cached files. This is an active contradiction between the code's user-facing documentation/output and its real behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, starting from the title and continuing throughout the document. Under the policy rule for language/locale, forcing a specific language without user opt-in can be a policy violation when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.