Back to skill

Security audit

A股业绩快报查询

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed A-share financial lookup tool that makes a purpose-aligned network request and does not show hidden persistence, credential access, destructive behavior, or unrelated data handling.

Installers should expect this skill to contact the configured market-data API when given a valid A-share ticker. Leave BASE_URL at the default unless you intentionally trust another endpoint, and be aware that broad finance keywords may cause the agent to consider the skill during general finance conversations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tainted flow: 'req' from os.environ.get (line 134, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request URL is derived from BASE_URL, which is taken directly from an environment variable without allowlisting or hostname validation. If an attacker can influence the execution environment, they can redirect the skill’s network call to an arbitrary host, enabling SSRF-style behavior, data exfiltration of queried stock codes, or interaction with internal services; because the code then trusts and parses the returned JSON, it also expands the attack surface to malicious upstream responses.

Content

Scanner excerpt · handler.py (reported line 139)May include surrounding context.

python
headers={"Accept": "application/json", "User-Agent": "openclaw-skill/1.0"},
    )

    with urllib.request.urlopen(req, timeout=REQUEST_TIMEOUT) as resp:
        # HTTPError 会在 urlopen 时抛出,此处只处理读取失败
        raw = resp.read().decode("utf-8")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes local code and explicitly allows configuration via environment variables and likely performs network access, but it does not declare any tool scope or permission boundaries. This creates an avoidable trust gap: a caller or platform cannot easily constrain network and environment access, increasing the risk of unexpected outbound requests, data exposure, or misuse if the handler behavior changes or is compromised.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description and the operational instructions are entirely in Chinese and describe the skill's behavior as querying and presenting results in that language, with no indication that users may choose another language. This is a natural-language policy concern because it imposes a locale/language expectation without explicit opt-in or justification as a region-specific language-only skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring, usage text, error messages, and rendered output are written only in Chinese, which enforces a specific language experience for users. Under the policy, forcing a language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language description is entirely in Chinese and the trigger model is built around Chinese financial terms, but the manifest does not state that the skill is region- or language-specific or provide any user opt-in for locale. Under the policy, forcing a specific language without documented choice or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad terms such as '营收', '净利润', 'EPS', and 'ROE' that can appear in many finance-related conversations, which increases the chance of the skill activating when the user did not specifically request this capability. Because the skill has network permission and can query external data, unintended activation may lead to unnecessary outbound requests, confusing responses, or unintended data disclosure about user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.