Back to skill

Security audit

eastmoney skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Eastmoney financial-data query tool that sends user queries to the documented API and writes local result files, with a spreadsheet safety caveat.

Install only if you are comfortable sending financial query text and the MX_APIKEY credential to Eastmoney's documented API. Treat generated XLSX files as externally sourced data: avoid enabling external links or active spreadsheet features unless you trust the source, and avoid putting unrelated secrets or personal data in query text.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
mx_data.py:306
Finding

Unsanitized API Data Allows Excel Formula Injection

Content
View full analysis

Vulnerability Details

File Location: mx_data.py, lines 136-140 and 306-308
Vulnerability Type: Excel formula injection caused by exporting untrusted data without neutralization
Risk Level: Medium

Vulnerable Code

API-supplied values are converted to strings without checking for spreadsheet formula prefixes:

python
raw_values = table.get(key, [])
value = raw_values[row_idx] if row_idx < len(raw_values) else ""
row[label] = flatten_value(value)
rows.append(row)

The resulting values are subsequently written directly to an XLSX workbook:

python
df = pd.DataFrame(table["rows"], columns=table["fieldnames"])
df.to_excel(writer, sheet_name=table["sheet_name"], index=False)

Technical Analysis

Values returned by the remote financial-data API are treated as trusted spreadsheet content. The flatten_value() function converts values to strings but does not neutralize strings beginning with spreadsheet formula markers, particularly =.

When pandas exports the values through the openpyxl engine, formula-like strings can be stored as active spreadsheet formulas instead of inert text. If an upstream response is compromised, manipulated, or otherwise contains attacker-controlled values, the generated workbook may therefore include formulas that are evaluated when opened in spreadsheet software.

Formula behavior depends on the spreadsheet application and its security configuration. Potential payloads can reference external resources, manipulate displayed data, trigger link-resolution behavior, or abuse application-specific formula functionality. This issue does not establish that the current API is malicious; it creates an exploitable trust-boundary weakness if hostile data reaches the API response.

The same neutralization policy should be applied to all remotely derived workbook content, including cell values and column labels.

Attack Path

  1. An attacker gains influence ove ...[truncated 1713 chars]
Remediation
View remediation

Remediation Suggestions

  1. Sanitize every remotely sourced string before placing it in a spreadsheet cell. At minimum, detect values beginning with formula markers and prefix them with an apostrophe so the spreadsheet treats them as text.

    python
    def safe_excel_value(value: Any) -> str:
        text = flatten_value(value)
        if text.startswith(("=", "+", "-", "@")):
            return "'" + text
        return text
    
  2. Apply the sanitizer when constructing rows:

    python
    row[label] = safe_excel_value(value)
    
  3. Apply equivalent protection to remotely derived headers and labels, not only ordinary data cells.

  4. Where supported, explicitly set exported cells to the string data type rather than relying solely on prefix escaping.

  5. Keep the raw JSON response separate from the workbook and clearly treat it as untrusted external data.

  6. Add regression tests covering values such as =1+1, =HYPERLINK(...), +1, -1, and @SUM(...). Inspect the resulting workbook to verify that these cells are stored and displayed as literal text rather than formulas.

  7. Document that generated workbooks contain externally sourced financial data and should not be opened with external-link updates or active-content features enabled unless the source is trusted.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares capabilities that imply access to environment variables, filesystem output, and outbound network calls, but it does not declare any explicit permission or allowed-tools scope. This weakens least-privilege controls and makes it harder for a host platform or reviewer to constrain what the skill may access, increasing the blast radius if the skill is misused or later extended.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

  • 凭据保护: API Key 仅通过环境变量 MX_APIKEY 在服务端或受信任的运行环境中使用,不会在前端明文暴露。
javascript
curl -X POST --location 'https://mkapi2.dfcfs.com/finskillshub/api/claw/query' \
--header 'Content-Type: application/json' \
--header 'apikey: YOUR_API_KEY' \
--data '{"toolQuery": "东方财富最新价"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · mx_data.py (reported line 188)May include surrounding context.

python
"toolQuery": tool_query
        }
        
        response = requests.post(self.BASE_URL, headers=headers, json=data, timeout=30)
        response.raise_for_status()
        return response.json()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This Python file makes an outbound HTTP POST request containing the user's natural-language query and an API key in headers. Although the module docstring says it provides financial data querying, there is no explicit runtime warning, confirmation, or user-facing notice that the query text is sent to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Natural-language strings throughout the file describe the skill, usage, errors, and example queries exclusively in Chinese, and the query parameter is documented as Chinese-language input. This can amount to a language/locale policy issue because the skill does not present an opt-in or alternative language choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.