Back to skill

Security audit

A股实时盯盘

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real stock monitor, but it asks the agent to run a persistent background process with ongoing network polling and optional external webhook alerts without strong containment.

Install only if you are comfortable with an agent-managed, long-running stock monitor. Pin dependencies first, avoid nohup or screen unless you can track and stop the process, leave the webhook empty unless you intentionally want alerts sent to WeCom, and treat alerts as informational because one market-data source is fetched over HTTP.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-4
Vulnerability Type: Unpinned and unhashed third-party dependencies
Risk Level: Medium

Vulnerable Code:

text
requests
pandas
colorama
akshare

The documented installation process in SKILL.md:39 installs these mutable dependency versions:

bash
pip install -r requirements.txt

Technical Analysis

None of the four dependencies has an exact version constraint or an integrity hash. Consequently, each installation resolves whatever package release is available from the configured package index at that time. This makes builds irreproducible and prevents users from verifying that installed artifacts are the same artifacts reviewed during the security audit.

Python packages can execute package-controlled code during installation and later during import. If a dependency account, release process, distribution artifact, package index, or configured mirror is compromised, a future installation could retrieve attacker-controlled code. This finding does not establish that any currently listed package is malicious; it identifies the absence of controls that would constrain dependency resolution to reviewed artifacts.

Attack Path

  1. An attacker compromises a listed dependency's release channel, package-index account, distribution artifact, or package mirror.
  2. The attacker publishes a malicious release under the legitimate package name.
  3. A user or agent follows the documented installation instruction and runs pip install -r requirements.txt.
  4. Because no exact versions or hashes are required, pip can select and install the attacker-controlled release.
  5. Malicious package code executes during installation or when the application imports the affected dependency.
  6. The payload operates with the privileges of the user running pip or the stock monitor.

Impact Assessment

Successful exploitation could permit arbitra ...[truncated 398 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed exact version using ==.
  2. Generate a lock file that also constrains transitive dependencies.
  3. Record cryptographic hashes for all approved distributions and install with:
    bash
    pip install --require-hashes -r requirements.txt
    
  4. Generate pinned requirements in a controlled environment using a tool such as pip-tools.
  5. Prefer reviewed wheel artifacts and use a trusted, access-controlled package mirror where practical.
  6. Add automated dependency vulnerability and provenance scanning to the release process.
  7. Review and update pins deliberately rather than resolving unrestricted releases during deployment.

T09 · Insecure Skill Coding Practices

Warning
Location
stock_monitor.py:43
Finding

Real-Time Financial Quote Data Is Retrieved over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: stock_monitor.py:43
Vulnerability Type: Unencrypted external API communication
Risk Level: Medium

Vulnerable Code:

python
url = f"http://hq.sinajs.cn/list={codes}"

Technical Analysis

The real-time quote endpoint uses plaintext HTTP. HTTP does not provide transport confidentiality, server authentication, or response integrity. A network-positioned attacker can observe the requested stock symbols and can intercept or modify the returned quote payload.

The application parses the response into prices, closing values, and volumes. These values feed directly into percentage calculations and abnormal-price or volume alerts. There is no cryptographic verification of the response, and the request path shown does not enforce a trusted HTTPS transport. Therefore, forged market data could be accepted as legitimate and used to generate, suppress, or distort notifications.

Attack Path

  1. An attacker gains a network position between the monitor and the quote service, such as through a hostile wireless network, compromised router, malicious proxy, or upstream traffic interception.
  2. The application requests the quote endpoint over plaintext HTTP.
  3. The attacker reads the requested stock codes or replaces the HTTP response with a syntactically valid forged quote payload.
  4. The application splits and converts the attacker-supplied fields into price and volume values.
  5. The abnormal-movement logic treats the forged values as authentic.
  6. False alerts may be printed locally or forwarded through the configured WeCom webhook; alternatively, genuine alerts may be suppressed by manipulated values.

Impact Assessment

Exploitation compromises the confidentiality and integrity of monitored market data. It may disclose which securities the user monitors and may cause misleading financial alerts or inaccurate displayed prices and volumes. If webhook delivery is enab ...[truncated 377 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the HTTP endpoint with an official HTTPS endpoint that provides valid certificate authentication.
  2. Do not disable TLS certificate verification. Use the default trusted certificate validation and maintain an appropriate CA store.
  3. Call raise_for_status() before parsing the response so HTTP failures are not processed as quote data.
  4. Validate the response schema, expected symbol identifiers, numeric ranges, field counts, and timestamps before updating state or issuing alerts.
  5. Reject zero or implausible previous-close values before calculating percentage changes.
  6. Consider confirming unusually large movements against a second independent HTTPS-protected data source before sending high-impact alerts.
  7. Log validation failures without including webhook credentials or other sensitive configuration.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (18)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README describes the skill exclusively as a China A-share monitoring skill ("中国A股实时盯盘技能") with no indication that the user can choose another market, locale, or language context. The policy explicitly calls for flagging language or locale constraints when they are imposed without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill clearly relies on network-capable behavior such as fetching market/news data and optionally sending WeCom webhook notifications, yet it declares no explicit tool scope or permissions. This creates an authorization gap where an agent may perform network actions without clear user-visible constraints, increasing the risk of unintended outbound requests or overbroad tool access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad trigger phrases like '监控股票', '异动提醒', and '主力资金' are likely to match many ordinary finance-related requests, causing the skill to activate unexpectedly. In this skill's context, accidental activation is more dangerous because activation can lead to code-editing guidance, network fetching, and potentially starting a persistent monitor process.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The user-facing description does not clearly disclose that setup requires editing code, installing dependencies, and potentially running a long-lived background process. This lack of transparency undermines informed consent and may cause users to trigger more invasive actions than they reasonably expect from a 'stock monitoring' skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to launch and manage a persistent background Python process, including lifecycle management, which expands the skill from simple data retrieval into autonomous long-running execution. That increases risk by creating ongoing network activity, resource consumption, and a process that may continue beyond the user's immediate awareness or consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The explicit recommendation to use 'nohup / screen' for running the monitor establishes session persistence outside the normal interactive lifecycle. Persistence is risky because it allows the skill's monitoring and network behavior to continue unattended, making it easier to overlook ongoing execution, resource usage, or unintended notifications/exfiltration via configured webhooks.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
当用户要求启动盯盘时:
1. 检查是否已安装依赖(requirements.txt)。
2. 修改或确认 STOCKS 列表。
3. 在后台运行:`python stock_monitor.py`(或使用 nohup / screen)。
4. 实时将异动、资金、消息通过聊天或推送通知用户。
5. 用户说“停止盯盘”时,结束进程。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill can transmit monitored stock activity to an external WeCom webhook without any explicit notice, consent flow, or destination validation. In this skill context, alerts may reveal a user's watchlist, trading interests, and timing patterns to a third-party endpoint, which is a real privacy and data-governance concern even though the payload is not highly sensitive by default.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This code performs outbound transmission of alert content to a user-supplied external webhook. In the context of a stock-monitoring skill, that can leak watchlist symbols, abnormal-movement detections, and monitoring behavior outside the local environment; the risk is amplified because the transmission is silent, unaudited, and lacks safeguards such as timeout/error handling policy, destination validation, or redaction.

Content

Scanner excerpt · stock_monitor.py (reported line 143)May include surrounding context.

python
def send_alert(self, message):
        if WECHAT_WEBHOOK:
            try:
                requests.post(WECHAT_WEBHOOK, json={"msgtype": "text", "text": {"content": message}})
            except:
                pass

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency 'requests' is unpinned, so builds may resolve to different versions over time, reducing reproducibility and increasing supply-chain risk. In a skill that performs real-time monitoring and likely makes network requests, an unexpected vulnerable or breaking release could affect confidentiality or availability.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests
pandas
colorama
akshare

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The manifest does not pin 'requests', and this package has multiple known advisories across versions, so there is no way to verify whether the deployed environment is affected. Given the skill's likely reliance on network access for real-time stock and message monitoring, a vulnerable 'requests' version could expose credentials, weaken TLS/session guarantees, or leak sensitive data.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency 'pandas' is unpinned, which allows uncontrolled version drift and makes the environment non-reproducible. Although often used for data processing, dependency confusion and accidental adoption of a vulnerable release remain supply-chain concerns.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests
pandas
colorama
akshare

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest does not pin 'pandas', and at least one advisory exists for some versions, making the actual exposure unverifiable. In this skill context the risk is lower than for networking libraries, but unverified versions still create avoidable uncertainty in security posture.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency 'colorama' is unpinned, introducing unnecessary supply-chain uncertainty even if the package is mainly used for console output. Any unpinned package can unexpectedly change behavior or introduce a compromised release.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests
pandas
colorama
akshare

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency 'akshare' is unpinned, which is notable because it is central to market-data retrieval in this stock-monitoring skill. An unexpected upstream release could introduce security issues, data integrity problems, or break monitoring behavior during trading hours.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
requests
pandas
colorama
akshare

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

User-visible strings throughout the script are in Chinese, and the skill does not provide any mechanism for users to select another language or opt in to this locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes '消息面热点监测' as part of an A-share monitoring skill, which implies monitoring news relevant to the watched stocks. In code, the feature pulls a general Eastmoney hot-rank table or a hard-coded Sina news roll page and only does a crude string presence check, so the implemented behavior is broader and less targeted than the stated monitoring purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The inline comment says the fallback is '简单新浪新闻标题拉取', suggesting title-level retrieval. The actual code requests a fixed Sina roll page URL and checks whether certain substrings appear anywhere in the response body, which is materially different from fetching and processing news titles.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.