Back to skill

Security audit

HALO · A股可信分析框架

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent A-share stock analysis tool, but its installer and some report-generation paths have unsafe scoping and injection risks that should be reviewed before installation.

Review the installer before running it. Prefer a manual, pinned install over curl | bash, expect calls to public Chinese financial data APIs, and expect local writes under the skill's data/ and reports/ directories plus persistent installation under ~/.claude/skills. Treat generated reports as untrusted analysis context, especially content derived from news or imported Serenity JSON.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:3
Finding

Mutable Remote Installer and Unpinned Supply Chain

Content
View full analysis
/install.sh | bash set -e SKILL_DIR="${HOME}/.claude/skills/halo-skill" REPO_URL="${1:-https://github.com/lululu811/halo-skill.git}" ``` ```bash if [ -d "${SKILL_DIR}" ]; then echo "Updating existing installation..." cd "${SKILL_DIR}" git pull else echo "Cloning into ${SKILL_DIR}..." git clone "${REPO_URL}" "${SKILL_DIR}" fi ``` ```bash source .venv/bin/activate echo "Installing dependencies..." pip install -q requests ``` ### Technical Analysis The installer advertises piping a remotely downloaded script directly into Bash. This executes the response before the user can inspect it and makes the effective payload depend on mutable remote content rather than the audited package. The subsequent installation process compounds that risk: - `REPO_URL` can be supplied by the caller and is not restricted to an approved repository. - `git clone` installs the current state of the remote default branch without pinning a commit or signed release. - `git pull` automatically incorporates new remote code into an existing Skill installation. - `pip install -q requests` installs an unpinned package without hash verification. - The resulting Skill is placed under `~/.claude/skills`, where it may be loaded in future Agent sessions. The repository URL currently defaults to the project’s stated GitHub repository, and no malicious embedded payload was found in the audited snapshot. Nevertheless, the installation method permits the executed and installed code to change after review. ### Attack Path 1. An attacker compromises the installer hosting location, repository, maintainer account, release process, DNS/TLS trust path, or dependency public ...[truncated 1228 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
fetch_qualitative.py:253
Finding

Path Traversal Through Unvalidated Stock-Code Arguments

Content
View full analysis
...[truncated 2435 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
generate_report.py:407
Finding

Indirect Prompt Injection Through Remote News Content

Content
View full analysis
", "").replace("", ""), "date": a.get("date", ""), "source": a.get("mediaName", ""), "url": a.get("url", ""), "summary": a.get("content", "")[:200], }) ``` `generate_report.py` inserts the title directly into the report skeleton: ```python news = qual.get("news", []) for i, n in enumerate(news[:5]): title = n.get("title", "") date = n.get("date", "")[:10] w(f"| {i+1} | {{AI_NEWS_TYPE_{i+1}}} | {title} | {date} | {{AI_NEWS_IMPACT_{i+1}}} | ⭐⭐⭐⭐ |") ``` The Skill workflow then instructs the Agent to read the skeleton and fill its analysis slots. ### Technical Analysis News titles originate from an external API and are therefore outside the local trust boundary. Only two HTML tags are removed. The implementation does not: - Escape Markdown control characters. - Reject multiline or instruction-like content. - Apply a strict length limit to titles. - Mark retrieved fields as untrusted quoted evidence. - Tell the Agent to ignore instructions contained in retrieved data. - Preserve a structured separation between data and Agent instructions. A compromised upstream service, manipulated response, malicious local qualitative JSON file, or other attacker-controlled data source can insert instruction-like text or Markdown that becomes part of the Agent’s working document. This is an indirect prompt-injection risk. Exploitability depends on the Agent runtime treating the generated skeleton as contextual instructions rather than inert data. ### Attack Path 1. An attacker gains control over an u ...[truncated 1260 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
integrate_serenity.py:19
Finding

Unsanitized Serenity Data Injection Into Agent-Facing Reports

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims a narrow, on-demand analysis function, but the finding indicates broader direct network ingestion, local writes, and absent trigger/permission declarations. In a skill context, that discrepancy is dangerous because users may authorize analysis while unintentionally granting a workflow capable of broader data collection and persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims a narrow, on-demand analysis function, but the finding indicates broader direct network ingestion, local writes, and absent trigger/permission declarations. In a skill context, that discrepancy is dangerous because users may authorize analysis while unintentionally granting a workflow capable of broader data collection and persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill claims a narrow, on-demand analysis function, but the finding indicates broader direct network ingestion, local writes, and absent trigger/permission declarations. In a skill context, that discrepancy is dangerous because users may authorize analysis while unintentionally granting a workflow capable of broader data collection and persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill claims a narrow, on-demand analysis function, but the finding indicates broader direct network ingestion, local writes, and absent trigger/permission declarations. In a skill context, that discrepancy is dangerous because users may authorize analysis while unintentionally granting a workflow capable of broader data collection and persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims a narrow, on-demand analysis function, but the finding indicates broader direct network ingestion, local writes, and absent trigger/permission declarations. In a skill context, that discrepancy is dangerous because users may authorize analysis while unintentionally granting a workflow capable of broader data collection and persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims a narrow, on-demand analysis function, but the finding indicates broader direct network ingestion, local writes, and absent trigger/permission declarations. In a skill context, that discrepancy is dangerous because users may authorize analysis while unintentionally granting a workflow capable of broader data collection and persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims a narrow, on-demand analysis function, but the finding indicates broader direct network ingestion, local writes, and absent trigger/permission declarations. In a skill context, that discrepancy is dangerous because users may authorize analysis while unintentionally granting a workflow capable of broader data collection and persistence.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
- 这些数据由 `generate_report.py` 从 JSON 精确填充

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The script explicitly instructs users to execute a remotely fetched shell script via curl | bash, which prevents meaningful inspection before execution and creates a direct remote-code-execution path if the hosting source, transport, redirect target, or repository supply chain is compromised. In a skill installer context, this is especially dangerous because the script also clones code and installs dependencies from the network immediately afterward.

Content

Scanner excerpt · install.sh (reported line 3)May include surrounding context.

sh
#!/bin/bash
# HALO Skill 一键安装脚本
# 用法: curl -sL <url>/install.sh | bash

set -e

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping directly into bash chains network retrieval and shell execution into a single step, eliminating an opportunity for the user or platform to inspect content before it runs. If an attacker can influence the fetched content or repository path, arbitrary commands will execute immediately with the user's privileges, including writes under the home directory and dependency installation.

Content

Scanner excerpt · install.sh (reported line 3)May include surrounding context.

sh
#!/bin/bash
# HALO Skill 一键安装脚本
# 用法: curl -sL <url>/install.sh | bash

set -e

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The examples use very generic natural-language requests to activate the skill, which can cause unintended invocation during ordinary conversation about A-share stocks. In an agent environment, overly broad triggers increase the chance the skill runs without clear user intent, potentially causing unplanned external API calls and report/file generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed trigger phrases are ambiguous and map to common investment-chat language such as asking whether a stock is worth buying. Because the skill performs external data retrieval and creates artifacts, ambiguous activation scope can lead to accidental execution from casual discussion rather than an intentional skill command.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares executable behaviors involving shell, network, and filesystem access but does not constrain them with an explicit permissions or allowed-tools scope. That increases the blast radius if the skill is invoked unexpectedly or later extended, because the agent may perform external access and local writes without a clearly declared trust boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

An overly broad trigger for any request to analyze an A-share stock can cause the skill to activate during ordinary conversation, increasing the chance of unintended shell, network, or file actions. Automatic invocation is more dangerous here because the skill's workflow includes external access and local artifact creation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Ambiguous activation scope without exclusion conditions makes it unclear when the skill should run and under what circumstances side effects are permitted. Because this skill's context includes shell and network operations, ambiguity raises the risk of accidental execution and user confusion about what actions will occur.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains user-facing documentation and CLI usage text only in Chinese, which forces a specific language for users interacting with the skill. The policy allows locale constraints only when users are given a choice or the restriction is clearly documented and justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The top-level documentation says the output is 'data/{code}.json' fully compatible with HALO standard JSON format. In reality, the script generates routing metadata and saves it as 'data/{code}_bridge.json', not stock data in HALO’s standard schema, so the documentation actively misstates the program’s effect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes HALO as a fixed A-share fundamental analysis framework with a data layer sourced from APIs, but this file explicitly adds 'HALO 新增能力' such as dragon-tiger list, northbound flow, and margin trading via another skill. Those capabilities materially expand the skill’s behavior and analysis inputs beyond what the manifest says, rather than merely implementing the stated purpose.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

The script probes a fixed path under ~/.claude/skills to determine whether another skill is installed, which leaks local environment composition to anyone who can observe script output or resulting JSON. In an agent ecosystem, installed-skill enumeration can aid capability fingerprinting and targeted prompt/integration attacks, even though the immediate impact here is limited because it checks only one known path and performs no execution.

Content

Scanner excerpt · bridge_a_stock_data.py (reported line 127)May include surrounding context.

python
def check_a_stock_data_available():
    """检查 a-stock-data skill 是否已安装"""
    skill_path = os.path.expanduser("~/.claude/skills/a-stock-data/SKILL.md")
    return os.path.exists(skill_path)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module documentation claims certain sources and behavior that do not match the implementation, including mention of Baidu search while the code substitutes other sources and leaves some fields for later AI filling. In a financial-analysis skill, inaccurate source declarations are security-relevant because they can mislead users and other components about provenance, verification level, and susceptibility to prompt/tool manipulation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata promises Python is constrained to API-sourced data and 'never fabricates', but this code explicitly pushes ESG, management, and sentiment-risk inputs to later AI/tool-based search. That creates a trust-boundary mismatch: downstream consumers may rely on the output as deterministic, API-backed evidence when some dimensions are actually gathered ad hoc by an LLM at report time, increasing the risk of hallucinated, manipulated, or non-reproducible analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language instructions, usage context, and output descriptions exclusively in Chinese, and the CLI/status messages later in the file are also Chinese-only. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest states 'Python锁定数据层(100%来自API,绝不编造),AI只做分析判断', which implies Python should only retrieve/source data while AI handles analysis. However, this file computes HALO dimensions, financial ratios, growth metrics, and writes derived analytical outputs such as 'halo', 'ratios', and 'growth', so Python is doing more than pure data fetching.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code persists fetched results to data/{stock_code}.json, and the saved payload includes company profile and F10 fields such as phone, address, and management names. Although the module docstring states the output path, there is no explicit user warning or confirmation near the write operation that data will be stored locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing natural-language strings and generates an entire report template exclusively in Chinese, including the title, usage text, and all report sections. The file does not offer any language/locale selection or explain that the skill is intentionally restricted to a Chinese-only regulatory or regional context, which violates the language-choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.