Back to skill

Security audit

Skills of A-share index data released by ft.tech.

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed China A-share index data helper that calls documented market.ft.tech read-only endpoints.

Install only if you are comfortable with a skill that runs bundled Python handlers and sends requested A-share index symbols, filters, dates, and pagination parameters to market.ft.tech. It appears read-only and purpose-aligned, but its interface is primarily Chinese and depends on that external market-data service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述聚焦于A股指数行情相关能力,包括指数详情、列表、K线和分时;而代码仅提供“前N个交易日”的日期查询功能。虽然同属 market.ft.tech 域下的市场数据场景,但该功能与指数行情查询并不等价,也不属于声明中列出的任一能力。该代码的主要目的与声明的技能用途存在实质性偏差,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
`run.py` 与本文件(`SKILL.md`)位于同一目录。执行时:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to derive and execute a local run.py, and explicitly describes outbound HTTP access to https://market.ft.tech, but it declares no permissions or allowed-tools scope. That creates an under-scoped, over-capable skill where file access, shell execution, and network use are implicit rather than constrained, increasing the chance of unintended command execution or data exfiltration if the runtime grants broad defaults.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The '询问方式' table uses broad phrases such as '有哪些指数', '指数列表', and '近 N 天交易日' as activation cues without clear exclusion conditions. These overlap with ordinary finance-related conversation and do not specify when this skill should activate versus other market-data skills, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes the skill as covering index details, paginated index lists, index K-line data, and minute-level intraday prices. The module documentation includes get-nth-trade-date as a supported subskill, which is a trading-calendar/date utility rather than index data retrieval, indicating the skill exposes behavior beyond the stated manifest scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This Python file contains multiple user-facing natural-language strings in Chinese, including the module docstring, CLI description, argument help, and error output. Because the skill does not provide any language/locale opt-in or indicate that it is intentionally restricted to Chinese users, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger description includes very broad terms such as 指数行情 and 成交, which can match a wide range of index-related requests beyond a single-index detail lookup. This can cause the wrong skill to be selected, leading to overbroad data retrieval, incorrect routing, or misleading answers when the user actually needs a list, K-line, or intraday function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The natural-language description and title are entirely Chinese and frame usage around Chinese query forms, but they do not explicitly state that the skill is limited to Chinese-language or China-market contexts as an intentional locale constraint. Under the policy, forcing a specific language without user opt-in or documented justification is a violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description and document content are written entirely in Chinese, which effectively imposes a specific language on users. The file does not offer an opt-in choice of language or explain that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language strings such as the module docstring and argparse descriptions exclusively in Chinese. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description is entirely in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-only audience. Under the language/locale policy, forcing a specific language without opt-in is a policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language strings in the module docstring and CLI help are entirely in Chinese, which effectively imposes a single language/locale on users without opt-in or explanation. The policy requires flagging language or locale constraints when the skill does not offer a choice or clearly justify a region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description and the entire markdown content are written only in Chinese, and the skill text provides no indication that language is optional or region-justified. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and CLI description are written entirely in Chinese, indicating a fixed language/locale expectation. Under the policy, forcing a specific language without offering user choice or documenting a justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains natural-language usage guidance exclusively in Chinese, and later user-facing runtime messages are also Chinese-only. Under the policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script prints usage and error messages only in Chinese, which forces a specific language for interactive output. The policy allows locale constraints only when they are optional or clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language description is written entirely in Chinese and assumes Chinese query phrasing such as “前 N 个交易日” and “近 N 天”, with no indication that other languages are supported or that Chinese is a required locale. Under the policy, forcing a specific language without opt-in can be a locale-policy issue unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This Python code issues an external HTTP GET request to market.ft.tech using user-supplied parameters, but the file contains no comment, docstring detail, or explicit user-facing notice that input values will be sent to a remote service. For code files, outbound network calls that transmit user or system data should have some visible disclosure unless the warning is clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.