Back to skill

Security audit

quant_trading-skills

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches finance-data fetching, but its batch modes can write to caller-chosen local paths and one opinion-data mode returns unlabeled mock data.

Review before installing. Use only in an isolated project or account, do not pass custom status_file or data_path values, expect outbound requests to AkShare-backed sources, and treat public_opinion results as unreliable until the publisher labels or replaces the mock implementation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_status.py:19
Finding

Caller-Controlled Filesystem Paths Permit Writes Outside Intended Storage Directories

Content
View full analysis
bool: try: os.makedirs(os.path.dirname(status_file), exist_ok=True) with open(status_file, 'w', encoding='utf-8') as f: json.dump(status, f, ensure_ascii=False, indent=2) return True except IOError: return False ``` Dataset storage similarly w ...[truncated 3676 chars]
Remediation
View remediation
/config` and `/data`. 3. Canonicalize every requested path before use and verify that it remains inside its permitted root: ```python from pathlib import Path PROJECT_ROOT = Path(__file__).resolve().parent.parent STATUS_ROOT = (PROJECT_ROOT / "config").resolve() DATA_ROOT = (PROJECT_ROOT / "data").resolve() def resolve_within(root: Path, supplied: str) -> Path: candidate = (root / supplied).resolve() if candidate != root and root not in candidate.parents: raise ValueError("Path escapes the permitted storage directory") return candidate ``` 4. Reject absolute paths, traversal components, null bytes, unexpected path types, and symbolic-link escapes. 5. Validate paths in both the Node.js entry point and Python code so the Python layer remains secure if called directly. 6. Use atomic status updates by writing to a temporary file inside the permitted directory and replacing the target only after a successful write. 7. Refuse to overwrite symbolic links and, where practical, existing files that are not recognized application-owned data. 8. Run the Skill under a dedicated low-privilege operating-system account with write access only to its designated data directories. 9. Add tests covering absolute paths, `../` traversal, symbolic links, malformed paths, and attempts to target files outside the project. ]]>

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Make Installation Non-Reproducible

Content
View full analysis
=1.18.0 pandas>=2.0.0 pyarrow>=14.0.0 ``` Node.js dependencies use version ranges, and no lockfile was present in the audited project: ```json "dependencies": { "axios": "^1.6.2", "moment": "^2.29.4" } ``` The installer upgrades pip to an unspecified current release before installing the unpinned requirements: ```python subprocess.check_call([sys.executable, '-m', 'pip', 'install', '--upgrade', 'pip']) requirements_path = os.path.join(script_dir, 'requirements.txt') subprocess.check_call([sys.executable, '-m', 'pip', 'install', '-r', requirements_path]) ``` ### Technical Analysis The Python requirements permit any future version greater than or equal to the listed minimum, while npm caret ranges permit compatible future releases. No Python package hashes or npm lockfile were present in the reviewed project. Consequently, the exact code installed depends on registry state at installation time rather than a reviewed dependency set. The installer further expands this trust boundary by automatically upgrading pip to the latest version available from the configured package index. Python packages, npm packages, and their transitive dependencies may execute installation hooks or later run with the Skill's privileges. The reviewed dependency names are established packages, and no evidence of dependency confusion, typosquatting, or an already malicious release was found. The issue is the absence of reproducible, integrity-verified dependency resolution. ### Attack Path 1. A user follows the documented installation process and runs `npm install` or `python install.py`. 2. The package manager contacts its confi ...[truncated 1044 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (59)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual implementation mainly performs local state management and incremental scheduling rather than real financial retrieval, then the declared purpose is misleading in a way that can bypass scrutiny. A skill that does something materially different from what it claims is a security concern even without overtly malicious code, because trust and approval are based on inaccurate descriptions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

If the actual implementation mainly performs local state management and incremental scheduling rather than real financial retrieval, then the declared purpose is misleading in a way that can bypass scrutiny. A skill that does something materially different from what it claims is a security concern even without overtly malicious code, because trust and approval are based on inaccurate descriptions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the actual implementation mainly performs local state management and incremental scheduling rather than real financial retrieval, then the declared purpose is misleading in a way that can bypass scrutiny. A skill that does something materially different from what it claims is a security concern even without overtly malicious code, because trust and approval are based on inaccurate descriptions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual implementation mainly performs local state management and incremental scheduling rather than real financial retrieval, then the declared purpose is misleading in a way that can bypass scrutiny. A skill that does something materially different from what it claims is a security concern even without overtly malicious code, because trust and approval are based on inaccurate descriptions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual implementation mainly performs local state management and incremental scheduling rather than real financial retrieval, then the declared purpose is misleading in a way that can bypass scrutiny. A skill that does something materially different from what it claims is a security concern even without overtly malicious code, because trust and approval are based on inaccurate descriptions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
OpenClaw 通过调用 `index.js` 中导出的 `execute` 函数来使用此 Skill:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown states that the skill supports batch pulling of all A-share data and stores results under structured data directories, which can materially affect local disk contents and resource usage. The README does not provide any warning or caution about large local writes, storage growth, or operational impact before users invoke these batch operations.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.md (reported line 113)May include surrounding context.

md
### 批量拉取参数

| 参数                 | 类型     | 必需 | 说明       | 示例                                                                                |
| ------------------ | ------ | -- | -------- | --------------------------------------------------------------------------------- |
| type               | string | 是  | 批量拉取类型   | batch\_market, batch\_north\_flow, batch\_lhb, batch\_sentiment, batch\_financial |
| batch\_market      | object | 否  | 行情拉取配置   | { default\_years: 5, max\_retries: 3 }                                            |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises installation and execution paths that imply shell execution and filesystem read/write behavior, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where a host may permit broader capabilities than users expect, especially because the skill also documents local persistence and installation steps.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest trigger uses generic keywords such as “股票”, “行情”, “财务”, and “批量”, plus a broad description saying the skill triggers whenever a user queries these topics. This lacks clear constraints or negative examples, so ordinary discussion about finance or batch work could unintentionally invoke the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill describes bulk retrieval, long-running jobs, and persistent writes but does not clearly foreground the operational cost, disk impact, or potential overwrite behavior before execution. In practice, this can lead to unexpected resource exhaustion or unintended local data growth when the skill is triggered in routine finance conversations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation describes persistent local storage, incremental state tracking, deduplication, and overwrite/write-back behavior for batch jobs, which introduces nontrivial data-handling side effects beyond ordinary querying. In a skill framed primarily as retrieval, these behaviors are dangerous because they can silently consume disk, retain sensitive or regulated datasets, and alter existing local files.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes batch collection modes that accept caller-controlled file paths such as status_file and data_path, enabling writes/reads outside a narrowly scoped market-query function. In an agent environment, this materially expands capability from simple data lookup to filesystem-affecting bulk workflows, which can be abused for unauthorized file access/overwrite or resource-intensive collection not implied by the manifest.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · install.py (reported line 21)May include surrounding context.

python
try:
        # 升级 pip
        print('升级 pip...')
        subprocess.check_call([sys.executable, '-m', 'pip', 'install', '--upgrade', 'pip'])
        
        # 安装依赖
        print(f'从 {requirements_path} 安装依赖...')

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · install.py (reported line 25)May include surrounding context.

python
# 安装依赖
        print(f'从 {requirements_path} 安装依赖...')
        subprocess.check_call([sys.executable, '-m', 'pip', 'install', '-r', requirements_path])
        
        print('依赖安装成功!')
        return 0

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains user-facing error text in Chinese, and similar Chinese-only messages appear elsewhere in the CLI flow. Because the skill does not offer a language/locale choice or document that it is intentionally limited to a Chinese-speaking or China-market context, it creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function claims to fetch public-opinion data but actually returns hardcoded mock news items. In a quantitative trading skill, fabricated sentiment data can mislead downstream agents or users into making financial decisions based on false information, creating integrity and trust risks even without code execution or direct system compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This module launches a local Python interpreter and executes an external script, which is a meaningful execution capability beyond simple in-process data formatting or HTTP retrieval. Even though spawnSync is used with an argument array rather than a shell, invoking an external interpreter increases attack surface through interpreter/script tampering, environment manipulation, and hidden capabilities not disclosed by the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code launches an external Python process and passes serialized parameters to it, which is a safety-relevant operation for a code file. While errors are logged, there is no user-facing disclosure, confirmation, or inline warning explaining that the skill executes a subprocess.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The thrown and logged error messages are hard-coded in Chinese, which imposes a specific language on users without offering a language choice or documenting a locale constraint. This is a natural-language policy issue because the skill does not provide opt-in or justification for the fixed locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This helper starts a Python subprocess with a one-hour timeout and enlarged buffer, indicating potentially heavy or prolonged execution. Although stderr is logged, there is no user-facing warning or confirmation that the skill will execute a long-running external process.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The batch functions do more than transient querying: they accept and default local filesystem paths such as status_file and data_path, enabling persistent bulk collection of market, sentiment, and financial datasets to disk. In a skill described as providing data lookup, this expands capability into local data warehousing and can cause unbounded storage growth or write sensitive/unexpected files if higher-level callers pass arbitrary paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The batch market fetch path runs a long-lived Python subprocess that can operate for up to an hour, which is a significant system action. The file contains no confirmation prompt or explicit warning to the user that a subprocess will run for an extended period.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JavaScript file contains natural-language comments and validation messages exclusively in Chinese, including strings that are likely surfaced to users such as parameter validation errors. The skill does not offer a language choice or document that it is intentionally limited to a Chinese-language or region-specific context, which creates a locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill sends requests to third-party financial/news data sources via akshare without explicit disclosure at the point of use. Even if the queried symbols are public, outbound requests can leak user interests, timing, and usage patterns to external services and may trigger compliance or privacy concerns.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lib/dataFetcher.js:10