Back to skill

Security audit

获取大A股票历史数据

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches Chinese stock and index price data from disclosed finance data sources, with no evidence of hidden control, persistence, credential use, or destructive behavior.

Install this in an isolated Python environment and consider pinning dependency versions before use. The skill makes outbound requests to finance data providers and should be treated as a market-data helper, not as financial advice or a guaranteed real-time quote source.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:50
Finding

Unpinned Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 50
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Complete Code Snippet:

bash
pip install akshare pandas

Technical Analysis

The documented installation command retrieves the latest available versions of akshare and pandas without version constraints, cryptographic hashes, or a lock file. This makes installation results dependent on mutable upstream package releases.

Although the audit found no evidence that either named package is currently malicious, this practice weakens supply-chain integrity. A compromised upstream release, malicious dependency introduced transitively, or unexpected incompatible update could be installed automatically. Python packages may execute code during installation and will execute package-controlled code when imported; kline.py imports akshare at runtime.

Attack Path

  1. An attacker compromises the release process or distribution account of a named or transitive dependency.
  2. The attacker publishes a malicious version to the package index used by pip.
  3. A user follows the documented command without reviewed version constraints or hash verification.
  4. pip resolves and installs the malicious release.
  5. Attacker-controlled code executes during package installation or when the Skill imports and uses the package.

Impact Assessment

Malicious dependency code would generally run with the privileges of the user installing or invoking the Skill. It could access files and credentials available to that user, make arbitrary network requests, modify user-writable resources, or execute additional local commands. The practical scope depends on the invoking account's permissions and environment; the audited project itself does not request elevated privileges.

Remediation
View remediation

Remediation Suggestions

  • Pin every direct dependency to a reviewed, exact version.
  • Generate and commit a lock file that also constrains transitive dependencies.
  • Record cryptographic hashes and install with pip --require-hashes.
  • Use a trusted, explicitly configured package index or an internally controlled package mirror.
  • Add automated dependency vulnerability and integrity scanning.
  • Review and deliberately update dependency versions rather than resolving the latest releases during every installation.
  • Prefer an isolated virtual environment with only the permissions required by the Skill.

Example hardened workflow:

bash
python -m pip install --require-hashes -r requirements.txt

The associated requirements.txt should contain exact versions and hashes for all resolved packages.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.