Back to skill

Security audit

Stock Invest Master

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a stock research/reporting tool, but it can automatically start an unauthenticated web server that may expose saved investment reports beyond the local machine.

Review before installing. Use it only if you are comfortable with local report files under ~/.stock-invest-master and disable or avoid the report server unless needed. If you do run it, bind it to 127.0.0.1 only, avoid placing sensitive files or symlinks in the report directory, and treat outputs as informational rather than personalized financial advice.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/serve_reports.py:411
Finding

Unauthenticated report server listens on all network interfaces

Content
View full analysis
"${LOG_FILE}" 2>&1 & SERVER_PID=$! echo "${SERVER_PID}" > "${PID_FILE}" ``` ### Technical Analysis Passing an empty host string to `HTTPServer` binds the service to all available network interfaces rather than only the loopback interface. The server implements no authentication or authorization before serving directory listings and report files. This conflicts with the loopback URLs displayed by `scripts/manage_server.sh`, which may lead users to believe that the service is locally accessible only. Because the Skill workflow directs the Agent to start the report service after report generation, the exposure can occur without a user explicitly requesting a network-wide service. Reports stored in `~/.stock-invest-master` can contain company research, watchlists, investment decisions, valuation assumptions, and other user-specific information. ### Attack Path 1. A user invokes the Skill and generates an investment report. 2. The automated workflow starts `serve_reports.py` through `manage_server.sh`. 3. `HTTPServer(("", port), ReportServer)` listens on every host interface, normally on port 8888. 4. An attacker with network access to the host connects to `http://HOST:8888/`. 5. The attacker browses the unauthenticated directory listing. 6. The attacker requests and downloads available Markdown, HTML, JSON, CSV, text, or image reports. ### Impact Assessme ...[truncated 421 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/serve_reports.py:103
Finding

Symlink traversal can expose files outside the report directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/serve_reports.py:247
Finding

Unsanitized Markdown and active report formats allow stored browser script execution

Content
View full analysis
text
{safe_content}
``` The server also serves active HTML directly: ```python elif full_path.endswith((".html", ".htm")): self.serve_static(full_path, "text/html") ``` ### Technical Analysis `html.escape()` protects the Markdown source while it is embedded into the hidden `
text
` element. It does not sanitize the HTML subsequently produced by `marked.parse()`.

If raw HTML is present in a report and the Markdown parser preserves it, the generated markup is assigned directly to `innerHTML`. Event-handler attributes, dangerous URLs, and other active HTML constructs can consequently execute in the report server's browser origin.

Reports can incorporate content derived from external market data, news, research pages, or user input. If 
...[truncated 1646 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/serve_reports.py:270
Finding

Unpinned remote JavaScript and Python dependencies create supply-chain risk

Content
View full analysis
``` The stock-fetching script also imports third-party packages while its installation guidance does not specify versions or hashes: ```python import requests ``` ```python try: import yfinance as yf except ImportError: raise ImportError( "yfinance is not installed" ) ``` ### Technical Analysis The jsDelivr URL for `marked` contains no fixed version and no Subresource Integrity hash. The effective JavaScript executed by a browser can therefore change after the Skill package has been reviewed. A compromised CDN, package release, namespace, or dependency delivery path could introduce arbitrary browser-side code. The project also instructs users to install `yfinance` and `requests` without a lock file, exact versions, or verified hashes. Future installations can resolve to package versions different from those examined during the audit. The audit found no evidence that the currently referenced packages are intentionally malicious. The vulnerability is the lack of reproducible, integrity-verified dependency resolution. ### Attack Path 1. A package account, package release, registry, CDN, or delivery path is compromised, or an incompatible future version is published. 2. The user installs an unpinned Python dependency or opens a report that loads the unversioned JavaScript. 3. The environment resolves and executes content that differs from the version originally reviewed. 4. Malicious Python code can execute with the Skill process's user privileges, or malicious JavaScript can execute in the report site's browser origin. 5. The compromised compo ...[truncated 494 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Running an HTTP file server over a local reports directory and serving multiple file types goes well beyond stock analysis and can expose locally generated content or nearby files if path handling is flawed. Because the description does not prominently disclose this server behavior, users may unknowingly enable local data exposure and persistent background processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Running an HTTP file server over a local reports directory and serving multiple file types goes well beyond stock analysis and can expose locally generated content or nearby files if path handling is flawed. Because the description does not prominently disclose this server behavior, users may unknowingly enable local data exposure and persistent background processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Running an HTTP file server over a local reports directory and serving multiple file types goes well beyond stock analysis and can expose locally generated content or nearby files if path handling is flawed. Because the description does not prominently disclose this server behavior, users may unknowingly enable local data exposure and persistent background processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Running an HTTP file server over a local reports directory and serving multiple file types goes well beyond stock analysis and can expose locally generated content or nearby files if path handling is flawed. Because the description does not prominently disclose this server behavior, users may unknowingly enable local data exposure and persistent background processes.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger keywords are extremely broad (e.g., 股票、分析、估值、投资), making accidental activation likely in ordinary conversation. In this skill, accidental activation is more dangerous because the workflow includes file creation and service startup, so benign discussion could trigger unintended side effects.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/overview_card_template.html (reported line 1)May include surrounding context.

html
<!--
  Stock Invest Master — Overview Card Template (v3)
  
  This HTML generates a dark-themed visual summary card for investment reports.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/overview_card_template.html (reported line 20)May include surrounding context.

html
<html>
<head>
<meta charset="utf-8">
<!-- NO external fonts - use system fonts for Chinese rendering -->
<style>
  * { margin: 0; padding: 0; box-sizing: border-box; }
  body {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description is presented entirely in Chinese and the README does not indicate that language selection is optional or that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 67)May include surrounding context.

手动安装

git clone https://github.com/mickshu/stock-invest-master.git ~/.hermes/skills/stock-invest-master mkdir -p ~/.stock-invest-master

text

## 项目结构

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest and README consistently describe a stock investment analysis skill that performs analysis, valuation, and report generation. However, the documented project structure explicitly includes serve_reports.py and manage_server.sh, indicating the skill can run a web service to expose reports, which is a separate operational capability beyond analysis itself.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

For a skill described as providing stock analysis, valuation, financial interpretation, and investment research, operating a web server is not an obvious or necessary capability from the stated purpose alone. The README documents service management and report hosting components, introducing application-serving behavior that is not clearly scoped or justified in the manifest description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope while its documented behavior implies file writes, network access, shell/process control, environment access, and local service management. This creates an over-privileged and opaque execution model where a user invoking a stock-analysis skill could unintentionally trigger filesystem changes or start services without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill description and operating instructions are entirely in Chinese and present the workflow as fixed, with no indication that users may choose another language or that the locale restriction is intentional and justified. Under the language/locale policy, forcing a specific language without opt-in can be a policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs saving reports into a user-home directory without clearly warning the user that local files will be created. Undisclosed writes can leak sensitive analysis artifacts, clutter the filesystem, or violate user expectations in managed environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow includes starting a web service without warning the user. Launching a local service changes the host’s attack surface, may expose reports or metadata over HTTP, and is especially risky when bundled into a skill whose declared purpose sounds like simple content analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The section "中文报告图片生成" explicitly directs generation of Chinese report images and discusses only Chinese font-rendering solutions, which indicates a fixed language/locale expectation. The file does not offer a user choice of language or explain a justified region-specific constraint, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill reference is written in Chinese and provides no indication that language is optional, selectable, or limited to a justified region-specific use case. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document is presented entirely in Chinese beginning with the title, and it does not state that the skill or notes are China-specific or that users may choose another language. This creates a natural-language locale constraint without opt-in, which matches the policy category for language or locale violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file is entirely written in Chinese and presents a fixed output format in Chinese without indicating any user-language negotiation or justified locale restriction. This can reduce accessibility and cause the skill to ignore user language preferences, which is a genuine policy and usability weakness, though it is not a code-execution or data-exfiltration issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions, formulas, and output templates exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can exclude users and violates language/locale choice expectations when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

该文件的标题及全部自然语言内容均为中文,且未见任何说明用户可选择其他语言,或该技能为何必须限定为中文。按照语言/locale 政策,未经用户选择而默认强制单一语言属于自然语言策略违规。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file includes a standardized output template that directly produces buy/sell/hold and position-sizing style recommendations without any accompanying warning, suitability check, or limitation statement. In an investment-analysis skill, this materially increases the chance that users treat the output as actionable financial advice, which can lead to harmful decisions and expose the system to financial, compliance, and trust risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all instructions, framework criteria, and examples exclusively in Chinese. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file provides a structured investment output template with explicit action labels such as buy, sell, add, and trial position sizing, but does not include any warning about financial risk, uncertainty, or potential loss. In the context of an investing skill that is designed to support investment decisions, this can cause users to over-trust the output as actionable financial advice and make risky decisions without understanding downside risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language documentation, CLI help text, warnings, and status messages entirely in Chinese, which imposes a specific language on users. The policy allows locale constraints only when users are given a choice or the restriction is clearly justified; neither is present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.