T09 · Insecure Skill Coding Practices
- Location
fund_daily_report.py:200- Finding
Hard-Coded JQData Account Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a Chinese fund-report generator, but it embeds a third-party data-service login and can automatically use it without clear user control.
Review before installing. The publisher should remove and rotate the exposed JQData credentials, require users to supply their own credentials through environment variables or a secret manager, pin dependencies, and clarify which report sections are estimates rather than verified capital-flow or holdings data.
fund_daily_report.py:200Hard-Coded JQData Account Credentials
README.md:15Unpinned Third-Party Python Dependencies
The skill’s declared purpose is a simple daily fund report, but the content describes broader behavior including external data collection from third-party services, proxy-based inference of capital flows, and the static finding indicates hardcoded JQData authentication not disclosed in the metadata. This mismatch is dangerous because it can cause operators to invoke the skill under false assumptions, leading to unauthorized third-party access, hidden credential use, or data handling that exceeds the stated business purpose.
The module docstring states the output is top 30-day fund gainers, estimated fund inflow leaders, top industry inflows, and stocks with the most inferred fund buying. This diverges from the manifest's stated purpose of producing daily fund performance reports with NAV changes, market commentary, and portfolio updates, because the implementation is focused on market-wide ranking screens and inferred capital-flow analytics instead of per-fund daily summaries.
The function comments and docstrings claim to retrieve the funds with the most inflow over 30 days and the stocks with the most fund buying, but the implementation ranks ETFs by 1-month performance and ranks stocks by成交额/涨跌幅-derived '资金关注度'. These statements actively overstate what the code measures and could mislead users into believing the output reflects actual fund capital flows or portfolio changes.
The fallback path imports a separate third-party service and embeds live JQData credentials directly in the skill. Hard-coded credentials in distributed code can be extracted and abused by anyone with access to the file, leading to unauthorized use of the external account, billing abuse, account suspension, or exposure of associated data access.
The line jq.auth('13918681158', 'Yindb1158') contains hard-coded authentication material with no disclosure or consent mechanism. This creates an immediate secret exposure risk: downstream users or attackers can reuse the credentials for unauthorized access, consume paid quotas, and potentially pivot into the associated third-party account.
The activation section uses general conditions such as '用户要求生成基金日报' and mention-based triggers like '天天基金', '基金排行', or '基金日报' without negative examples or constraints. These phrases can match ordinary discussion about funds, rankings, or data sources, making invocation boundaries unclear.
The module docstring, status messages, and report output are all written in Chinese, and the skill provides no option for the user to select another language. This constitutes a language/locale policy issue because the behavior is imposed rather than user-configurable or explicitly opt-in.
The manifest description is effectively empty and provides no domain-specific invocation cues, trigger phrases, or exclusion conditions. In a manifest file, this lack of specificity can make activation behavior unclear and increases the risk of unintended invocation.
The entire skill description, headings, and usage notes are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking or region-specific audience. Under the policy, locale or language constraints should be opt-in or clearly justified rather than implicitly enforced.
The manifest says the skill generates daily fund performance reports with NAV changes, market commentary, and portfolio updates. The README describes additional behavior focused on cross-market rankings and analytics such as ETF fund inflows, concept-sector capital flows, and top stocks by fund position increases, which goes beyond a straightforward daily fund performance summary.
The skill instructions, usage guidance, and output examples are presented only in Chinese, which effectively forces a specific language experience. There is no indication that the user can opt into another language or that the skill is intentionally limited to a Chinese-language or region-specific audience.
No suspicious patterns detected.