T09 · Insecure Skill Coding Practices
- Location
scripts/config.py:11- Finding
API Credentials Stored in Plaintext Source Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This stock-analysis skill is not malicious, but it needs review because it gives actionable trading guidance while handling API keys insecurely and sending analysis data to external LLM services.
Install only if you are comfortable with a Chinese-language stock-analysis tool that fetches live market data and may send analysis prompts to external LLM providers. Do not paste real API keys into scripts/config.py in a shared or version-controlled workspace; use environment variables or a separate private secrets file instead. Treat all trading scores and buy/sell language as general information, not personalized investment advice, especially because some auxiliary scores can be defaults or placeholders.
scripts/config.py:11API Credentials Stored in Plaintext Source Configuration
The skill markets a complete geometry-based and multi-signal stock analysis system, yet the finding states that core declared methods are not implemented. This overstatement is dangerous because it can induce misplaced user trust, especially given the domain involves financial forecasting and buy/sell timing.
The skill markets a complete geometry-based and multi-signal stock analysis system, yet the finding states that core declared methods are not implemented. This overstatement is dangerous because it can induce misplaced user trust, especially given the domain involves financial forecasting and buy/sell timing.
The skill markets a complete geometry-based and multi-signal stock analysis system, yet the finding states that core declared methods are not implemented. This overstatement is dangerous because it can induce misplaced user trust, especially given the domain involves financial forecasting and buy/sell timing.
The skill markets a complete geometry-based and multi-signal stock analysis system, yet the finding states that core declared methods are not implemented. This overstatement is dangerous because it can induce misplaced user trust, especially given the domain involves financial forecasting and buy/sell timing.
The skill documents commands that invoke scripts using external data providers and LLM APIs, but it does not declare any explicit tool scope or permissions. In an agent environment, undeclared network capability weakens least-privilege controls and can allow broader-than-expected outbound access when the skill is triggered.
The trigger description is broad enough to activate on many generic stock-related queries, increasing the chance that the skill runs in contexts the user did not explicitly intend. Because the skill can provide high-stakes financial guidance, over-triggering raises the risk of unsolicited or misplaced analysis influencing decisions.
The natural-language content of the skill, including its description and usage instructions, is entirely in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally restricted to a Chinese-speaking context. This can constitute a language-policy issue when a skill effectively forces one language without opt-in.
The instructions tell users to place API tokens directly into a configuration file but do not warn about secure secret handling. This increases the risk of credential leakage through source control, logs, shared workspaces, or accidental disclosure in agent interactions.
The document content is entirely in Chinese and does not indicate that other languages are supported or that Chinese is an optional locale. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.
The guide gives concrete trading recommendations such as '可买入', '可加仓', and '减仓/观望' without a clear, prominent disclaimer that outputs are informational only and not financial advice. In a trading-analysis skill, this increases the chance that users will treat generated output as personalized investment advice and make harmful financial decisions based on incomplete, unlicensed, or non-suitability-assessed analysis.
The code transmits analysis context to an externally configured LLM endpoint using requests.post, and the destination base_url is taken from configuration without restriction. In this skill context, that increases risk because a misconfigured or malicious endpoint could receive sensitive market-analysis prompts, API metadata, or future user-supplied trading context, with little transparency to the user.
return None
try:
resp = requests.post(url, headers=headers, json=data, timeout=60)
if resp.status_code == 200:
result = resp.json()
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
return None
try:
resp = requests.post(url, headers=headers, json=data, timeout=60)
if resp.status_code == 200:
result = resp.json()
The script sends stock code, stock name, recent price history, and derived technical-analysis context to external LLM providers without explicit user consent or a prominent disclosure at the point of use. In a trading-analysis skill, users may reasonably assume analysis stays local, so silent transmission to third-party APIs creates a privacy and data-governance risk, especially if prompts later include user portfolio or proprietary strategy context.
The script's user-facing strings, prompts, and status messages are consistently hard-coded in Chinese, including the main analysis output and setup guidance. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.
This code file contains natural-language instructions and descriptions exclusively in Chinese, including the module docstring and configuration guidance. That can violate language/locale policy when users are not given a choice of language and the locale restriction is not explicitly justified as region-specific.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
OPENAI_API_KEY = "" # OpenAI API Key (ChatGPT)
ANTHROPIC_API_KEY = "" # Anthropic API Key (Claude)
MINIMAX_API_KEY = ""
MINIMAX_BASE_URL = "https://api.minimax.chat/v1" # MiniMax API Key
DEEPSEEK_API_KEY = "" # DeepSeek API Key
QWEN_API_KEY = "" # 阿里Qwen API Key
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 自定义API配置 (如使用其他大模型)
CUSTOM_API_KEY = ""
CUSTOM_BASE_URL = "" # 如: https://api.openai.com/v1
CUSTOM_MODEL = "" # 如: gpt-4o
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 自定义API配置 (如使用其他大模型)
CUSTOM_API_KEY = ""
CUSTOM_BASE_URL = "" # 如: https://api.openai.com/v1
CUSTOM_MODEL = "" # 如: gpt-4o
The strings appended to issues and printed to the user are all Chinese-language messages, but the file does not provide any opt-in or alternate locale. This is a natural-language locale constraint affecting user interaction and should be explicitly justified or made configurable.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
return {
"provider": "minimax",
"api_key": MINIMAX_API_KEY,
"base_url": MINIMAX_BASE_URL if 'MINIMAX_BASE_URL' in globals() else "https://api.minimaxi.com/anthropic",
"model": "MiniMax-M2.5"
}
elif provider == "deepseek" and DEEPSEEK_API_KEY:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
return {
"provider": "deepseek",
"api_key": DEEPSEEK_API_KEY,
"base_url": "https://api.deepseek.com/v1",
"model": "deepseek-chat"
}
elif provider == "qwen" and QWEN_API_KEY:
This Python file contains a Chinese-only module description and later emits Chinese-only report text and console output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation because users are not given a locale choice or documented justification.
If no market data is supplied, the function silently generates deterministic synthetic price/volume data and proceeds to produce a stock-specific analysis and recommendation. In the context of an investment skill, this is especially dangerous because users may act on advice that has no relationship to the requested security's real market behavior.
The code presents itself as performing comprehensive analysis, but the fundamental, sentiment, and AI prediction components are fixed placeholder scores and fabricated factor text. In a trading-analysis skill, this can mislead users into believing recommendations are based on real inputs when they are not, creating integrity and decision-risk issues even though it is not a code-execution flaw.
The formatted report, risk messages, recommendations, and CLI output are all emitted in Chinese, with no mechanism for users to select another language. This is a clear language/locale policy issue in natural-language string literals within the code.
No suspicious patterns detected.