Back to skill

Security audit

China Stock Analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed China A-share analysis guide that uses public market data, with dependency and language caveats but no hidden persistence, credential handling, or destructive behavior.

Install dependencies only in a dedicated non-privileged virtual environment, consider pinning package versions, and make sure you can read the Chinese risk disclosures and assumptions before relying on the generated financial analysis. Treat outputs as informational, not investment advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23-34
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install akshare pandas numpy

The fallback installation instruction repeats the unsafe installation pattern:

bash
pip install akshare

Technical Analysis

The Skill instructs users to install third-party Python packages without specifying reviewed versions, cryptographic hashes, a lockfile, or an explicitly trusted package index. Consequently, package resolution retrieves whatever versions and transitive dependencies are available from the configured package repository at installation time.

This makes the installed code mutable after the Skill has been reviewed. A compromised package release, compromised package-maintainer account, malicious transitive dependency, or untrusted package-index configuration could introduce attacker-controlled code. Python packages may execute code during installation or when imported by the dependency check and subsequent analysis workflows.

There is no evidence in the audited artifact that the named packages are currently malicious. The issue is the absence of dependency integrity and reproducibility controls.

Attack Path

  1. An attacker compromises a referenced package, one of its transitive dependencies, or the package repository used by the victim.
  2. The attacker publishes a malicious version that remains compatible with the unconstrained dependency request.
  3. A user follows the Skill's pip install instruction.
  4. pip resolves and downloads the attacker-controlled package because no approved version or hash is enforced.
  5. Malicious code executes during package installation, package import, or a later Skill workflow.
  6. The payload operates with the privileges and environmental access of the user running pip or Python.

Impact Assessment

Successful ...[truncated 665 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed exact version, for example:
    text
    akshare==<reviewed-version>
    pandas==<reviewed-version>
    numpy==<reviewed-version>
    
  2. Generate and commit a lockfile that includes all transitive dependencies.
  3. Require cryptographic hashes during installation, such as through a hash-locked requirements file and:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Configure an explicit trusted package index or an internally controlled package mirror rather than relying on an unspecified local pip configuration.
  5. Install dependencies inside a dedicated, non-privileged virtual environment. Do not use administrator privileges or system-wide installation.
  6. Review dependency provenance, release history, and transitive dependencies before updating the lockfile.
  7. Add automated dependency vulnerability and integrity scanning to the release process.
  8. Replace the fallback pip install akshare instruction with a reference to the same reviewed, hash-locked dependency file so that all installation paths enforce identical controls.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes Chinese output for reports instead of adapting to the user's language or asking for preference. This can mislead or exclude users who cannot read Chinese, and in a financial-analysis context it may cause misunderstanding of risk disclosures or investment conclusions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Markdown report is specified as structured Chinese-only output with no language choice. For a tool that presents financial analysis and risk warnings, language forcing can reduce comprehension and informed decision-making for non-Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.