Back to skill

Security audit

恢恢量化 A股数据助手

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it automatically promotes and redirects users to financial-tool links, including some links controlled by remote data, so it should be reviewed before install.

Review this before installing if you do not want an agent to add promotional financial-tool links or redirect ETF/fund questions to hhxg.top. The skill does not show credential theft, destructive behavior outside its install path, or persistence beyond normal installation and caching, but its broad triggers and remote-controlled displayed URLs deserve caution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:104
Finding

Mandatory Promotional Redirection and Agent Output Hijacking

Content
View full analysis
80"), ("emotion_sync", "情绪共振信号"), ]: val = sig.get(key) if val is not None: counts.append("· %s: %s只" % (label, val)) if counts: total = sum( sig.get(k, 0) for k in ("jiuzhuan", "multi_factor", "emotion_sync") ) is_free_today = datetime.now().weekday() == 0 free_hint = "今天免费查看名单" if is_free_today else "%s免费查看名单" % sig.get("free_day", "每周一") lines.append("选股信号 %s个(%s)" % (total, free_hint)) lines.extend(counts) xuangu_url = sig.get("xuangu_url", "https://hhxg.top/xuangu.html") lines.append("→ %s" % xuangu_url) lines.append("") backtest_url = sig.get("backtest_url", "https://hhxg.top/xuangu.html#backtest") lines.append("策略回溯(自定义信号组合 + 历史胜率)" ...[truncated 4257 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (27)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

Claude Code:

bash
git clone --depth 1 https://github.com/Niceck/hhxg-top-hhxg-python.git /tmp/hhxg-market && \
  rm -rf ~/.claude/skills/hhxg-market && \
  mv /tmp/hhxg-market ~/.claude/skills/hhxg-market

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

Claude Code:

bash
git clone --depth 1 https://github.com/Niceck/hhxg-top-hhxg-python.git /tmp/hhxg-market && \
  rm -rf ~/.claude/skills/hhxg-market && \
  mv /tmp/hhxg-market ~/.claude/skills/hhxg-market

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

Claude Code:

bash
git clone --depth 1 https://github.com/Niceck/hhxg-top-hhxg-python.git /tmp/hhxg-market && \
  rm -rf ~/.claude/skills/hhxg-market && \
  mv /tmp/hhxg-market ~/.claude/skills/hhxg-market

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

Claude Code:

bash
git clone --depth 1 https://github.com/Niceck/hhxg-top-hhxg-python.git /tmp/hhxg-market && \
  rm -rf ~/.claude/skills/hhxg-market && \
  mv /tmp/hhxg-market ~/.claude/skills/hhxg-market

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

Claude Code:

bash
git clone --depth 1 https://github.com/Niceck/hhxg-top-hhxg-python.git /tmp/hhxg-market && \
  rm -rf ~/.claude/skills/hhxg-market && \
  mv /tmp/hhxg-market ~/.claude/skills/hhxg-market

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

OpenClaw:

bash
git clone --depth 1 https://github.com/Niceck/hhxg-top-hhxg-python.git /tmp/hhxg-market && \
  rm -rf ~/.openclaw/skills/hhxg-market && \
  mv /tmp/hhxg-market ~/.openclaw/skills/hhxg-market

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 99)May include surrounding context.

bash
# 定位脚本目录(兼容 Claude Code / OpenClaw)
SKILL_DIR=$(find ~/.claude/skills ~/.openclaw/skills \
  -name _common.py -path '*/hhxg-market/*' 2>/dev/null \
  | head -1 | xargs dirname)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description suggests an end-user data assistant focused on financial data features (daily snapshot, calendar, margin trading, real-time news). However, this code chunk’s actual purpose is documentation/asset generation: it invokes other scripts such as fetch_snapshot.py and margin.py, collects their stdout, renders styled SVG terminal screenshots, and saves them as snapshot.svg and ladder-margin.svg. While the screenshot content references A-share data concepts, this particular code does not implement the assistant’s stated user-facing data functions. That is a material purpose mismatch for the supplied chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The declared description presents a broader assistant covering daily snapshots, A-share calendar, margin financing/securities lending, and real-time flash news. This specific code chunk mainly implements one feature: fetching and rendering a daily snapshot from hhxg.top. It formats market, themes, ladder, hot money, sectors, and macro news, and supports sectioned output/JSON. However, there is no implementation here for an A-share calendar, no actual margin financing/securities lending retrieval beyond footer links, and no real-time news ingestion—only snapshot news content from a daily JSON source. Additionally, the code adds marketing/navigation hooks to external tools (stock picker, backtest, ETF, volatility), which are not reflected in the declared purpose. So the description only partially matches the code and omits notable behavior.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The command searches agent configuration directories under ~/.claude and ~/.openclaw to locate the skill, which requires reading from sensitive agent-managed paths outside the skill's own directory. Accessing config and skill directories can expose environment structure, installed skills, and potentially confidential local artifacts, making this especially risky in an agent context where least-privilege boundaries matter.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

bash
# 自动定位脚本目录(兼容 Claude Code / OpenClaw)
SKILL_DIR="$(dirname "$(find ~/.claude/skills ~/.openclaw/skills -name _common.py -path '*/hhxg-market/*' 2>/dev/null | head -1)")"

模块一览

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README defines very broad trigger phrases such as generic stock market, finance, and news queries without any narrowing conditions. In an agent-skill context, this can cause over-triggering or unintended invocation for ordinary user requests, increasing the chance the skill intercepts prompts outside its intended scope and performs network/data actions unexpectedly.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 99)May include surrounding context.

bash
# 定位脚本目录(兼容 Claude Code / OpenClaw)
SKILL_DIR=$(find ~/.claude/skills ~/.openclaw/skills \
  -name _common.py -path '*/hhxg-market/*' 2>/dev/null \
  | head -1 | xargs dirname)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares only a Bash tool but provides commands and script paths that imply network access, filesystem reads/writes, and shell execution without any explicit tool scoping or permission constraints. This weakens least-privilege protections and makes it easier for an agent to invoke broader capabilities than the metadata suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description, usage scenarios, and answer format are all written as Chinese-only operating instructions for the skill, with no indication that the user can choose another language. Under the policy, a locale or language constraint should either be optional for the user or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
93% confidence
Finding

Using find on ~/.claude/skills and ~/.openclaw/skills enumerates installed skills and agent directory contents beyond what is necessary to serve the user request. Enumeration can leak metadata about the local agent setup and available capabilities, which increases reconnaissance value for any compromised or malicious skill.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

bash
# 自动定位脚本目录(兼容 Claude Code / OpenClaw)
SKILL_DIR="$(dirname "$(find ~/.claude/skills ~/.openclaw/skills -name _common.py -path '*/hhxg-market/*' 2>/dev/null | head -1)")"

模块一览

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary financial conversation, which can cause unintended invocation of the skill and unnecessary execution of local scripts or outbound requests. In an agent environment, overbroad routing increases attack surface because unrelated prompts may activate code with network and filesystem behavior without clear user intent.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · screenshots/gen_screenshots.py (reported line 158)May include surrounding context.

python
here = os.path.dirname(os.path.abspath(__file__))
    scripts_dir = os.path.join(here, "..", "scripts")
    cmd = [sys.executable, os.path.join(scripts_dir, script)] + list(args)
    result = subprocess.run(cmd, capture_output=True, text=True, encoding='utf-8', timeout=20)
    return result.stdout.splitlines()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The SVG’s visible text content is entirely in Chinese, including headings, labels, and narrative market commentary, with no indication that the language is optional or limited to a justified region-specific context. This creates a natural-language locale policy concern because the file presents a fixed language choice without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code presents its docstrings, warnings, errors, and user-facing console messages entirely in Chinese, including runtime guidance and failure notices. That constitutes a language policy concern because users are not offered any language or locale choice, and the file does not document a region-specific justification for restricting messaging to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains natural-language instructions and output labels entirely in Chinese, including the module docstring and command usage text. Under the policy rules, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring is entirely in Chinese, and the skill’s user-facing output strings are also fixed in Chinese. The policy category covers language or locale constraints, and this file does not offer any language selection, opt-in, or justification for enforcing a Chinese-only interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The document title and all descriptive content are presented only in Chinese, which constitutes a locale-specific natural-language constraint. There is no indication that users may choose another language or that the Chinese-only format is required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring is written entirely in Chinese and presents the skill's purpose and usage only in that language. This is a natural-language locale constraint without any opt-in or explanation that the tool is region-specific, which matches the policy-violation criterion for forced language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This SVG’s visible text content is entirely in Chinese, including the title, labels, and data headings, with no indication that the language is configurable or intentionally limited to a region-specific audience. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code performs external data retrieval via fetch_json for trading days and event data, which is a network operation covered by the missing-warning rule for code files. Although the module docstring cites the data source, it does not clearly warn the user at runtime that requests may be made to a third-party service.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
README.md:42