Back to skill

Security audit

对上市公司进行系统性投资价值分析,支持 A 股、港股、美股

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis skill is mostly coherent, but it automatically starts an unauthenticated report web server and writes user-derived filenames without adequate safety controls.

Review this skill before installing. It may be useful for public stock analysis, but report generation should be run only with trusted inputs and in a contained environment; avoid exposing port 8888, and prefer fixing input validation, HTML escaping, HTTPS-only data sources, and server cleanup before routine use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate-pdf-report.sh:5
Finding

Path Traversal Through Unsanitized Report Filename

Content
View full analysis
<公司名>" exit 1 fi mkdir -p "$REPORT_DIR" # 1. 生成 HTML 报告 HTML_FILE="$REPORT_DIR/${COMPANY_NAME}_${STOCK_CODE}.html" cat > "$HTML_FILE" << EOF ``` ### Technical Analysis The script directly incorporates the user-controlled `COMPANY_NAME` and `STOCK_CODE` arguments into a filesystem path. It does not reject path separators, `..` components, control characters, or absolute-path-like input. Shell quoting prevents word splitting and shell command injection, but it does not prevent filesystem path traversal. For example, a company name containing `../../target` causes the resulting path to resolve outside the intended report directory. A related pattern exists in `scripts/analyze.sh:24-40`, where `STOCK_CODE` is used in cache filenames without validation: ```bash "$SCRIPT_DIR/fetch-eastmoney.sh" "$STOCK_CODE" price > "$OUTPUT_DIR/price_${STOCK_CODE}.json" "$SCRIPT_DIR/fetch-eastmoney.sh" "$STOCK_CODE" financial > "$OUTPUT_DIR/financial_${STOCK_CODE}.json" "$SCRIPT_DIR/fetch-ths.sh" "$STOCK_CODE" financial > "$OUTPUT_DIR/ths_${STOCK_CODE}.txt" "$SCRIPT_DIR/fetch-research.sh" "$STOCK_CODE" all > "$OUTPUT_DIR/research_${STOCK_CODE}.txt" "$SCRIPT_DIR/fetch-eastmoney.sh" "$STOCK_CODE" holder > "$OUTPUT_DIR/holder_${STOCK_CODE}.json" ``` The generated report has a fixed `.html` suffix, and cache files have fixed suffixes, which limits—but does not eliminate—the ability to overwrite arbitrary files. ### Attack Path 1. An attacker invokes the report-generation entry point with a company name or stock code containing traversal components. 2. The input is concatenated with `/app/skills/stock-analysis/reports` with ...[truncated 1180 chars]
Remediation
View remediation
&2 exit 1 fi SAFE_COMPANY=$(printf '%s' "$COMPANY_NAME" | tr -cd '[:alnum:]_.-') if [ -z "$SAFE_COMPANY" ]; then echo "Invalid company name" >&2 exit 1 fi HTML_FILE="$REPORT_DIR/${SAFE_COMPANY}_${STOCK_CODE}.html" ``` Canonical containment checks should still be added rather than relying solely on character replacement. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate-pdf-report.sh:18
Finding

Stored HTML and Script Injection in Generated Reports

Content
View full analysis
"$HTML_FILE" << EOF $COMPANY_NAME ($STOCK_CODE) 投资价值分析报告 body { font-family: Arial, 'Microsoft YaHei', sans-serif; margin: 2cm; line-height: 1.6; } h1 { color: #1a5490; border-bottom: 3px solid #1a5490; padding-bottom: 10px; text-align: center; } table { width: 100%; border-collapse: collapse; margin: 15px 0; } th, td { border: 1px solid #ddd; padding: 8px; text-align: left; } th { background-color: #1a5490; color: white; } .conclusion { background: linear-gradient(135deg, #667eea 0%, #764ba2 100%); color: white; padding: 20px; border-radius: 10px; margin: 20px 0; }

📈 $COMPANY_NAME ($STOCK_CODE) 投资价值分析报告

Stock Analysis Skill v1.4.1 | $(date +"%Y-%m-%d %H:%M")

🎯 核心结论

报告已生成完成!

``` ### Technical Analysis `COMPANY_NAME` and `STOCK_CODE` are inserted directly into HTML element content and the document title without HTML escaping. The variables originate from positional command-line arguments and are therefore attacker-controlled whenever an untrusted caller can trigger the Skill. Shell quoting is irrelevant to HTML safety. HTML metacharacters such as `<`, `>`, `"`, and `&` retain their browser interpretation. A malicious company name containing an element with an event handler can become active content in the generated `

` element. Because the generated report is saved to disk and later served through the built-in HTTP server, this is a stored injection issue rather than a transien ...[truncated 1503 chars]

Remediation
View remediation
` tags; event handlers, SVG content, malformed markup, and other browser parsing mechanisms must also be neutralized. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate-pdf-report.sh:50
Finding

Unauthenticated HTTP File Server Exposes Generated Reports

Content
View full analysis
/dev/null; then cd "$REPORT_DIR" && python3 -m http.server $HTTP_PORT > /tmp/http-server.log 2>&1 & sleep 2 fi ``` ### Technical Analysis `python3 -m http.server` binds to all available interfaces by default unless a bind address is explicitly provided. The server offers no authentication or authorization and normally exposes directory listings when no index file is present. The process is placed in the background and is not terminated after the report is downloaded or after the generating script exits. Although this is not an operating-system persistence mechanism such as a startup service or scheduled task, it creates a lingering network service for the lifetime of the process or container. The `pgrep -f` check is also imprecise. It searches the entire process command line for a pattern rather than tracking a specific process identifier created by this Skill. ### Attack Path 1. A user runs the report-generation workflow. 2. The script starts Python's generic HTTP server on port 8888. 3. The server listens on all interfaces available inside the execution environment. 4. If the port is exposed directly or through container port mapping, another network participant connects to it. 5. The participant requests the root path and obtains a directory listing, or guesses known report filenames. 6. The server returns generated reports without authentication. ### Impact Assessment A remote or adjacent-network attacker may be able to: - Enumerate files in the report directory. - Download every readable generated report. - Access malicious HTML created through the separate HTML-injection issue. - Keep using the service after the generating command has completed. - Consume se ...[truncated 255 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch-price.sh:14
Finding

Financial Data Retrieved Over Plaintext HTTP

Content
View full analysis
/dev/null) if [ -n "$TX_DATA" ]; then echo "腾讯数据:$TX_DATA" echo "$TX_DATA" | grep -oP 'v_sz[0-9]+="[^"]*"' return 0 fi ``` The technical-analysis script uses the same plaintext endpoint: ```bash # 获取行情数据(腾讯财经) DATA=$(curl -s "http://qt.gtimg.cn/q=sz${STOCK_CODE}" 2>/dev/null) ``` The Tonghuashun data source is also configured with plaintext HTTP: ```bash # 同花顺 API 基础 URL THS_BASE="http://data.10jqka.com.cn" case $DATA_TYPE in "financial") # 获取财务指标 echo "获取同花顺财务数据:$STOCK_CODE" curl -s "${THS_BASE}/f10/zb/${STOCK_CODE}" | grep -oP 'data-field="[^"]*"' | head -20 ;; "report") # 获取研报摘要 echo "获取研报数据:$STOCK_CODE" curl -s "${THS_BASE}/f10/yybg/${STOCK_CODE}" | grep -oP '<[^>]+>' | head -30 ;; "industry") # 获取行业数据 echo "获取行业数据:$STOCK_CODE" curl -s "${THS_BASE}/f10/hyqk/${STOCK_CODE}" ;; ``` One company investor-relations mapping also uses HTTP: ```bash declare -A IR_URLS=( ["蓝思科技"]="https://www.lensTechnology.com/investor" ["宁德时代"]="https://www.catl.com/investor" ["茅台"]="http://www.moutai.com.cn/investor" ) ``` ### Technical Analysis Plaintext HTTP does not provide server authentication, transport confidentiality, or response integrity. An attacker positioned on the network path can observe and modify responses. The fetched values are subsequently parsed and presented as market, technical, financial, or research information. The scripts only test whether some responses are nonempty and do not cryptographically authenticate the source or robustly valida ...[truncated 1320 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (36)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file title and all operational instructions are written in Chinese, which can amount to a language policy constraint if users are not given an explicit choice or informed that the skill is intended only for a Chinese-speaking context. No opt-in, alternative language, or justification for the locale-specific presentation is provided in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation is entirely in Chinese and provides example prompts only in Chinese, with no indication that the skill adapts to the user's preferred language. In a multi-language agent environment, this can bias the skill toward responding in Chinese without user consent, causing usability failures, misunderstanding, or exclusion of users who requested another language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The phrase '同行业哪个更好' is broad and conversational, making it plausible that unrelated user requests about sector comparisons could unintentionally trigger this skill. Unintended invocation can cause the agent to enter stock-analysis behavior when the user did not explicitly request investment analysis, increasing the chance of irrelevant financial recommendations or overreach.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly documents starting an HTTP server on port 8888 and exposing a direct download URL for generated reports, but provides no indication of binding only to localhost, adding authentication, or warning that reports may become reachable by other hosts. Because the reports contain user-requested analysis and file names derived from company inputs, this creates a real risk of unintended data exposure and service exposure beyond the local session context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The only natural-language content is written in Chinese and appears to define the skill behavior without offering any user language choice or opt-in. This can violate language/locale policy when the skill implicitly constrains interaction to a specific language without documenting that limitation or making it optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file declares lang="zh-CN" and presents the entire report in Chinese, but there is no natural-language indication that the user opted into Chinese output or that the skill is restricted to a China-specific audience. Under the policy rule, forcing a specific language/locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file contains user-facing natural-language strings entirely in Chinese, including the description, usage help, status messages, and completion notice. Because the script does not offer any language selection or indicate that it is intentionally limited to a Chinese-speaking or region-specific context, it may violate the language/locale policy for user-facing skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's comments and all user-facing output strings are exclusively in Chinese, including the usage message and status updates. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The comments and all user-facing output strings are written in Chinese, including the usage message and result labels. This creates a natural-language locale policy issue because the skill forces a specific language without user opt-in, and the file does not document that it is intended only for a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comments and usage text specify the skill's interface entirely in Chinese, and the runtime messages are likewise Chinese-only. This imposes a language constraint without user opt-in or a documented region-specific justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Comments and printed messages such as the usage text and progress output are only provided in Chinese, with no option for another language or indication that the tool is intentionally region-specific. This can violate language/locale policy when a skill imposes one language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The header comment and usage text describe this as a 'PDF report generation script', but the implementation writes only an .html file and instructs the user to open it and use the browser's 'Save as PDF' feature. This is a direct contradiction between the documented intent and the actual behavior, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments, usage text, generated HTML language tag, and all user-facing messages are fixed to Chinese, which imposes a specific language/locale by default. There is no indication that this skill is region-specific or that users can opt into another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script silently starts a Python HTTP server on port 8888 and serves the report directory without authentication or an explicit opt-in. In a container or host with port mapping or shared network access, this can unintentionally expose generated reports and directory contents to other users or systems, increasing the risk of information disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's comments and user-visible output are entirely in Chinese, including the usage message and status text. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script prints usage and status messages only in Chinese (for example at L05 and L11), which imposes a specific language on users without opt-in. This is a natural-language policy issue because the file contains user-facing text but does not offer any locale selection or explain that the skill is intended only for a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script comments, usage text, and runtime output are written exclusively in Chinese, which imposes a specific language on users without opt-in. Under the policy, locale or language restrictions should either offer user choice or be clearly documented as justified for a region-specific skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template provides specific portfolio allocation ranges, entry timing, holding guidance, and stop-loss style trading instructions while only including a minimal disclaimer. That can cause users to treat generated output as personalized financial advice, increasing legal/compliance risk and the chance of harmful financial decisions if the analysis is wrong or inapplicable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template is entirely written in Chinese and structures the generated output around Chinese-language headings and labels. This creates a language policy concern because it implies the skill will respond in a fixed language without offering the user a locale or language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template presents all headings, labels, and guidance exclusively in Chinese, which imposes a specific language on users without any opt-in or documented regional justification. Under the policy, forcing a language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration explicitly enables automatic retrieval from third-party financial sources and describes shell scripts being automatically invoked, but it does not clearly warn the user that network access will occur. This creates a transparency and consent issue, and in agent environments it can unexpectedly expose user queries, timing, or operational metadata to external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language instructions, triggers, workflow, and usage guidance are presented in Chinese only, which effectively forces a specific language for users. The file does not offer an opt-in language choice or explain that the skill is intentionally restricted to a Chinese-language audience or region-specific context.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest-like JSON file contains only the phrase "获取财务数据:300433" without any explicit activation conditions, scope limits, or exclusion conditions. As written, it does not clarify when this skill should activate versus when similar requests should not, making the trigger/description overly ambiguous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The only natural-language content in the file is Chinese ("获取行情数据:300433"), which indicates a fixed language/locale with no visible opt-in or alternative. Under the policy, forcing a specific language without user choice can be a locale-policy violation unless it is clearly documented as region-specific or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file consists entirely of Chinese-language text and provides no indication that the language choice is optional or tied to a documented region-specific requirement. Under the policy, language constraints should either be user-selectable or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.