T09 · Insecure Skill Coding Practices
- Location
scripts/stock_query.py:7- Finding
Undocumented and Untrusted Market-Data Endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This stock skill is not clearly malicious, but it overstates its analysis abilities and sends financial queries to an undocumented mock data service.
Review before installing. The skill appears to be a small stock-query script, but its documentation promises more than it delivers and names reputable data sources while the code uses api.mock-stock.com. Do not rely on its prices or recommendations for financial decisions unless the provider, disclosures, validation, and data provenance are fixed.
scripts/stock_query.py:7Undocumented and Untrusted Market-Data Endpoint
scripts/stock_query.py:7Unsafe Construction and Handling of External HTTP Requests
声明强调“查询和分析”且列出基本面分析、技术指标分析等较具体能力,但代码实际仅包含4个功能:查询价格、查询股票信息、查询ETF信息、获取推荐列表。代码没有任何分析算法、指标计算、基本面处理逻辑,也没有体现对A股/港股/美股的专门支持或市场区分。高潜力股推荐也只是调用外部recommend接口,而非自身分析生成。因此描述明显超出了代码实际行为,属于能力宣称与实现不一致。
The skill declares network-backed functionality through its described stock/ETF query features and listed external data sources, but does not define any explicit tool scope such as permissions or allowed-tools. This creates an authorization and governance gap: an agent implementation may gain broader network access than intended, making outbound requests harder to constrain, review, or sandbox.
The manifest description and the entire user-facing documentation are written in Chinese, and all example commands use Chinese trigger words such as "/股票", "/关注", and "/推荐". The file does not indicate that the skill is intentionally region-specific or offer users a language/locale choice, which can violate language/locale policy requirements.
The script's docstrings and CLI output are consistently presented in Chinese, and there is no option for users to select another language or opt into this locale. This can violate language/locale policy where skills should not force a specific language without user choice or clear justification.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""
try:
# 这里使用一个模拟 API,实际应该使用真实的股票 API
response = requests.get(f"https://api.mock-stock.com/price?code={stock_code}")
data = response.json()
return data.get("price", "无法获取价格")
except Exception as e:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""
try:
# 这里使用一个模拟 API,实际应该使用真实的股票 API
response = requests.get(f"https://api.mock-stock.com/price?code={stock_code}")
data = response.json()
return data.get("price", "无法获取价格")
except Exception as e:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""
try:
# 这里使用一个模拟 API,实际应该使用真实的股票 API
response = requests.get(f"https://api.mock-stock.com/price?code={stock_code}")
data = response.json()
return data.get("price", "无法获取价格")
except Exception as e:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""
try:
# 这里使用一个模拟 API,实际应该使用真实的股票 API
response = requests.get(f"https://api.mock-stock.com/price?code={stock_code}")
data = response.json()
return data.get("price", "无法获取价格")
except Exception as e:
This code transmits the user-provided stock code to an external HTTP endpoint, but there is no user-facing disclosure near the operation indicating that input will be sent to a third-party service. Similar undisclosed outbound requests also occur in the other query functions, which may matter for privacy-sensitive usage.
The function sends the user-provided ETF name to an external network service, but the script does not warn users that their query terms will be transmitted off-system. For a command-line tool, a visible notice in help output or documentation would satisfy the disclosure expectation.
No suspicious patterns detected.