Back to skill

Security audit

太几何交易

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis skill is not malicious, but it needs review because it gives actionable trading guidance while handling API keys insecurely and sending analysis data to external LLM services.

Install only if you are comfortable with a Chinese-language stock-analysis tool that fetches live market data and may send analysis prompts to external LLM providers. Do not paste real API keys into scripts/config.py in a shared or version-controlled workspace; use environment variables or a separate private secrets file instead. Treat all trading scores and buy/sell language as general information, not personalized investment advice, especially because some auxiliary scores can be defaults or placeholders.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:11
Finding

API Credentials Stored in Plaintext Source Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill markets a complete geometry-based and multi-signal stock analysis system, yet the finding states that core declared methods are not implemented. This overstatement is dangerous because it can induce misplaced user trust, especially given the domain involves financial forecasting and buy/sell timing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill markets a complete geometry-based and multi-signal stock analysis system, yet the finding states that core declared methods are not implemented. This overstatement is dangerous because it can induce misplaced user trust, especially given the domain involves financial forecasting and buy/sell timing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill markets a complete geometry-based and multi-signal stock analysis system, yet the finding states that core declared methods are not implemented. This overstatement is dangerous because it can induce misplaced user trust, especially given the domain involves financial forecasting and buy/sell timing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill markets a complete geometry-based and multi-signal stock analysis system, yet the finding states that core declared methods are not implemented. This overstatement is dangerous because it can induce misplaced user trust, especially given the domain involves financial forecasting and buy/sell timing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill documents commands that invoke scripts using external data providers and LLM APIs, but it does not declare any explicit tool scope or permissions. In an agent environment, undeclared network capability weakens least-privilege controls and can allow broader-than-expected outbound access when the skill is triggered.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger description is broad enough to activate on many generic stock-related queries, increasing the chance that the skill runs in contexts the user did not explicitly intend. Because the skill can provide high-stakes financial guidance, over-triggering raises the risk of unsolicited or misplaced analysis influencing decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content of the skill, including its description and usage instructions, is entirely in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally restricted to a Chinese-speaking context. This can constitute a language-policy issue when a skill effectively forces one language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instructions tell users to place API tokens directly into a configuration file but do not warn about secure secret handling. This increases the risk of credential leakage through source control, logs, shared workspaces, or accidental disclosure in agent interactions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document content is entirely in Chinese and does not indicate that other languages are supported or that Chinese is an optional locale. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guide gives concrete trading recommendations such as '可买入', '可加仓', and '减仓/观望' without a clear, prominent disclaimer that outputs are informational only and not financial advice. In a trading-analysis skill, this increases the chance that users will treat generated output as personalized investment advice and make harmful financial decisions based on incomplete, unlicensed, or non-suitability-assessed analysis.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The code transmits analysis context to an externally configured LLM endpoint using requests.post, and the destination base_url is taken from configuration without restriction. In this skill context, that increases risk because a misconfigured or malicious endpoint could receive sensitive market-analysis prompts, API metadata, or future user-supplied trading context, with little transparency to the user.

Content

Scanner excerpt · scripts/analyze_stock.py (reported line 93)May include surrounding context.

python
return None
    
    try:
        resp = requests.post(url, headers=headers, json=data, timeout=60)
        if resp.status_code == 200:
            result = resp.json()

Tainted flow: 'data' from requests.get (line 187, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/analyze_stock.py (reported line 93)May include surrounding context.

python
return None
    
    try:
        resp = requests.post(url, headers=headers, json=data, timeout=60)
        if resp.status_code == 200:
            result = resp.json()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends stock code, stock name, recent price history, and derived technical-analysis context to external LLM providers without explicit user consent or a prominent disclosure at the point of use. In a trading-analysis skill, users may reasonably assume analysis stays local, so silent transmission to third-party APIs creates a privacy and data-governance risk, especially if prompts later include user portfolio or proprietary strategy context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing strings, prompts, and status messages are consistently hard-coded in Chinese, including the main analysis output and setup guidance. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language instructions and descriptions exclusively in Chinese, including the module docstring and configuration guidance. That can violate language/locale policy when users are not given a choice of language and the locale restriction is not explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/config.py (reported line 32)May include surrounding context.

python
OPENAI_API_KEY = ""       # OpenAI API Key (ChatGPT)
ANTHROPIC_API_KEY = ""   # Anthropic API Key (Claude)
MINIMAX_API_KEY = ""
MINIMAX_BASE_URL = "https://api.minimax.chat/v1"      # MiniMax API Key
DEEPSEEK_API_KEY = ""     # DeepSeek API Key
QWEN_API_KEY = ""         # 阿里Qwen API Key

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/config.py (reported line 38)May include surrounding context.

python
# 自定义API配置 (如使用其他大模型)
CUSTOM_API_KEY = ""
CUSTOM_BASE_URL = ""       # 如: https://api.openai.com/v1
CUSTOM_MODEL = ""         # 如: gpt-4o

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/config.py (reported line 116)May include surrounding context.

python
# 自定义API配置 (如使用其他大模型)
CUSTOM_API_KEY = ""
CUSTOM_BASE_URL = ""       # 如: https://api.openai.com/v1
CUSTOM_MODEL = ""         # 如: gpt-4o

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The strings appended to issues and printed to the user are all Chinese-language messages, but the file does not provide any opt-in or alternate locale. This is a natural-language locale constraint affecting user interaction and should be explicitly justified or made configurable.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/config.py (reported line 130)May include surrounding context.

python
return {
            "provider": "minimax",
            "api_key": MINIMAX_API_KEY,
            "base_url": MINIMAX_BASE_URL if 'MINIMAX_BASE_URL' in globals() else "https://api.minimaxi.com/anthropic",
            "model": "MiniMax-M2.5"
        }
    elif provider == "deepseek" and DEEPSEEK_API_KEY:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/config.py (reported line 137)May include surrounding context.

python
return {
            "provider": "deepseek",
            "api_key": DEEPSEEK_API_KEY,
            "base_url": "https://api.deepseek.com/v1",
            "model": "deepseek-chat"
        }
    elif provider == "qwen" and QWEN_API_KEY:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains a Chinese-only module description and later emits Chinese-only report text and console output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation because users are not given a locale choice or documented justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

If no market data is supplied, the function silently generates deterministic synthetic price/volume data and proceeds to produce a stock-specific analysis and recommendation. In the context of an investment skill, this is especially dangerous because users may act on advice that has no relationship to the requested security's real market behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code presents itself as performing comprehensive analysis, but the fundamental, sentiment, and AI prediction components are fixed placeholder scores and fabricated factor text. In a trading-analysis skill, this can mislead users into believing recommendations are based on real inputs when they are not, creating integrity and decision-risk issues even though it is not a code-execution flaw.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The formatted report, risk messages, recommendations, and CLI output are all emitted in Chinese, with no mechanism for users to select another language. This is a clear language/locale policy issue in natural-language string literals within the code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.