Back to skill

Security audit

A股数据SKILL

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent A-share market data helper, but users should treat its third-party data sources, unpinned Python dependencies, and local caches with normal caution.

Install in a virtual environment, consider pinning dependency versions, and do not rely on this skill as the sole source for financial decisions. Be aware that ticker queries are sent to third-party market-data services and that some fallback data paths may use unauthenticated HTTP.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:29
Vulnerability Type: Unpinned and integrity-unverified third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install akshare MyTT pandas numpy requests

Technical Analysis

The documented installation command does not constrain dependency versions and does not verify package hashes. Consequently, installation behavior depends on whichever package releases are served by the configured package index at execution time.

This creates a mutable supply-chain boundary: a future compromised release, package-index compromise, dependency substitution, or malicious transitive dependency could cause code not present during this audit to execute during installation or runtime. The risk is particularly relevant because Python packages may run build backends or setup logic during installation.

No evidence was found that the named dependencies are currently malicious. The vulnerability is the absence of version and integrity controls.

Attack Path

  1. An attacker compromises a named dependency, one of its transitive dependencies, or the package index used by the environment.
  2. The attacker publishes or serves a malicious package version under a dependency name accepted by the unpinned command.
  3. A user follows the installation instructions in SKILL.md.
  4. pip resolves the attacker-controlled version because no reviewed version or hash is required.
  5. Malicious installation or imported runtime code executes with the privileges of the user running pip or the Skill.

Impact Assessment

A successfully compromised dependency could execute arbitrary Python code with the invoking user's privileges. Depending on the execution environment, this could permit access to the user's files, environment variables, network credentials, and other resources available to the Skill process.

The Skill itself does not request elevated operating-sys ...[truncated 235 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the ad hoc installation command with a reviewed lockfile or requirements file containing exact versions.
  2. Generate and require cryptographic hashes for every package artifact, for example:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Pin direct and transitive dependencies rather than relying only on top-level version constraints.
  4. Document the expected package index and use HTTPS-only trusted repositories.
  5. Install dependencies in an isolated virtual environment under an unprivileged account.
  6. Add automated dependency scanning and a controlled process for reviewing and updating locked versions.
  7. Prefer binary wheels from verified sources where appropriate, and avoid unexpected source builds in production environments.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/Ashare.py:9
Finding

Unauthenticated HTTP Transport Permits Market-Data Manipulation

Content
View full analysis

Vulnerability Details

File Locations: scripts/Ashare.py:9-10, scripts/Ashare.py:20-21, scripts/Ashare.py:39-40, scripts/fetch_history_fallback.py:46-47, scripts/fetch_history_fallback.py:691-713
Vulnerability Type: Plaintext HTTP transport without server authentication or response integrity
Risk Level: Medium

Vulnerable Code

scripts/Ashare.py:9-10:

python
URL=f'http://web.ifzq.gtimg.cn/appstock/app/fqkline/get?param={code},{unit},,{end_date},{count},qfq'
st= json.loads(requests.get(URL).content);    ms='qfq'+unit;      stk=st['data'][code]

scripts/Ashare.py:20-21:

python
URL=f'http://ifzq.gtimg.cn/appstock/app/kline/mkline?param={code},m{ts},,{count}'
st= json.loads(requests.get(URL).content);       buf=st['data'][code]['m'+str(ts)]

scripts/Ashare.py:39-40:

python
URL=f'http://money.finance.sina.com.cn/quotes_service/api/json_v2.php/CN_MarketData.getKLineData?symbol={code}&scale={ts}&ma=5&datalen={count}'
dstr= json.loads(requests.get(URL).content);

scripts/fetch_history_fallback.py:46-47:

python
SINA_STOCK_LIST_COUNT = "http://vip.stock.finance.sina.com.cn/quotes_service/api/json_v2.php/Market_Center.getHQNodeStockCount"
SINA_STOCK_LIST_DATA = "http://vip.stock.finance.sina.com.cn/quotes_service/api/json_v2.php/Market_Center.getHQNodeData"

scripts/fetch_history_fallback.py:691-713:

python
def _fetch_all_stocks_sina(session: requests.Session, market: str) -> pd.DataFrame:
    node_map = {None: "hs_a", "sh": "sh_a", "sz": "sz_a"}
    node = node_map.get(market, "hs_a")
    try:
        r = session.get(SINA_STOCK_LIST_COUNT, params={"node": node}, timeout=30)
        total = int(r.text.strip('"'))
    except Exception:
        total = 5000

    rows = []
    page_size = 100
    total_pages = (total + page_size - 1) // page_size
    for page in range(1, total_pages + 1):
        params = {
            "page
...[truncated 2972 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace every http:// endpoint with its verified https:// equivalent.
  2. If a source does not support HTTPS, remove it from the fallback chain or explicitly classify its output as untrusted.
  3. Prefer established HTTPS sources already used elsewhere in the project.
  4. Add explicit connect and read timeouts to every request in scripts/Ashare.py, for example:
    python
    requests.get(url, timeout=(3, 10))
    
  5. Call raise_for_status() before parsing responses.
  6. Validate response schemas, stock identifiers, timestamps, numeric ranges, and requested record counts before accepting data.
  7. For decision-sensitive data, compare responses against an independent HTTPS source and reject material discrepancies.
  8. Disable untrusted redirects or verify that any redirect remains on an approved HTTPS hostname.
  9. Add tests that confirm no production endpoint uses plaintext HTTP.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code’s primary behavior is much narrower than the description. It only retrieves market price/K-line history (daily, weekly, monthly, and minute bars) from external web APIs and does not implement technical indicators, event data, capital flow, company/industry metadata, financial indicators, index constituent lookup, trading calendar access, or macroeconomic data. While this is related to 'historical data' and some quote-like price retrieval, the declared description substantially overstates the skill’s capabilities, so the description does not accurately represent the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

该描述将技能定位为广泛的 A 股市场数据查询工具,但代码并不提供这些通用证券数据能力。它的核心流程完全围绕 A/H 股票及赴港上市事件:获取 A/H 列表与港股资料、用东方财富 suggest 接口解析 A 股代码、抓取公告接口、依据港股上市相关关键词过滤,并按正则提取里程碑节点。虽然声明中提到“事件”,但这里的事件能力非常特定,仅限 H 股上市进程公告,不能覆盖描述中列出的实时行情、历史数据、技术指标、板块、财务、指数、日历、宏观、行业等主要用途。因此主用途与触发范围存在明显不一致,应判定为 mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个覆盖面很广的A股市场数据查询技能,重点在行情、历史、技术分析、事件、资金面和行业等信息。代码却仅调用 ak.stock_zh_ah_spot_em 和 ak.stock_hk_security_profile_em,构建A/H双重上市公司清单,并补充H股基础信息(如上市日期、板块、交易所、港股通标的等),再按上市日期筛选并缓存结果。其主要目的与声明不一致,且大量声明能力完全未体现。同时,代码还涉及港股/H股资料,不只是“A股实时行情”等范围。因此应判定为描述与实际行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description presents a broad stock information skill covering realtime quotes, historical data, technical indicators, events, capital flow, industry info, financial indicators, index constituents, trading calendar, and macro data. The supplied code chunk is much narrower: it specifically fetches K-line OHLCV data and computes technical indicators, then generates signal interpretations. That aligns with the '技术指标' portion of the description, but not with the many other declared data domains and triggers. This is a material description-behavior mismatch because the implemented primary purpose is technical indicator analysis rather than the full general stock information capability claimed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill documents execution of local Python scripts that install packages and access external market data, but it does not declare any explicit tool scope or permissions boundaries. In an agent environment, undeclared access to environment, filesystem, and network increases the chance of over-privileged execution, unintended data access, or unsafe invocation beyond the user’s expected query-only use case.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation guidance is very broad, covering many stock-, sector-, macro-, and industry-related requests without sharp exclusion boundaries. In an agentic system, broad trigger conditions can cause over-invocation of a networked skill, increasing the attack surface for prompt injection from upstream data sources, unnecessary external requests, and execution in contexts where a simpler non-executing response would be safer.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_ah_ipo_timeline.py (reported line 322)May include surrounding context.

python
def _fetch_announcements(a_code: str, begin: str, end: str, max_pages: int = 30) -> List[Dict[str, Any]]:
    headers = {
        "User-Agent": "Mozilla/5.0",
        "Referer": "https://data.eastmoney.com/",
    }
    all_items: List[Dict[str, Any]] = []

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language instructions and error messages exclusively in Chinese, including the module description and multiple printed user-facing notices. Under the stated policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The parser and output labels present --profit, --growth, --balance, --cashflow, and --dupont as separate metric-specific functions, but _financial_single_from_akshare ignores its func_name argument and always calls the same ak.stock_financial_analysis_indicator(symbol=digits) endpoint. This is an active intent/code divergence because the user-facing command names and labels claim category-specific retrieval that the implementation does not perform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing CLI help/messages in this file are written only in Chinese, which effectively imposes a specific language on users. The file does not offer a language option, bilingual output, or any explanation that the skill is intentionally limited to a Chinese-language or China-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language instructions, help text, and analysis output entirely in Chinese, starting with the module docstring and continuing through user-facing messages. The file does not offer any user opt-in, language selection, or explanation that the skill is intentionally region- or locale-specific, which conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description embeds both Chinese and English instructions ('Use when ...') but does not state whether the user can choose the response language. This can create an implicit language-policy issue if the skill behavior assumes or nudges a specific language format without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The document title and all user-facing documentation are presented exclusively in Chinese, which can amount to a language/locale constraint with no explicit opt-in or alternative described. Under the policy, forced language choice in natural-language instructions can be a violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The reference explicitly states that concept boards are not to be treated as an available skill capability and instructs users to always use --no-concepts. However, the same section later documents that concepts may still exist in output, which weakens and partially contradicts the stated intent that this capability is excluded from the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The function makes outbound requests to third-party market-data services over plain HTTP without any user-facing disclosure. This creates privacy and integrity risk because user-requested symbols, timing, and returned market data can be observed or modified in transit, and the skill description does not indicate that external network calls occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code performs additional outbound HTTP requests to Sina endpoints without informing the user, again over plain HTTP. Even though the purpose is normal market-data retrieval, undisclosed third-party calls can leak user query context and allow tampering with responses if traffic is intercepted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Natural-language strings throughout the file, including the top-level description and command-line help, are exclusively in Chinese with no opt-in or alternative locale. Under the policy, forcing a specific language without user choice is a language/locale policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python file makes multiple HTTP GET requests to Sina, Tencent, Xueqiu, and Eastmoney through shared helper functions, transmitting user-supplied stock codes and date ranges to external services. While the module docstring documents the data sources, it does not clearly warn users that their queries are sent over the network to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code file performs HTTP requests to multiple external services via requests.Session.get and returns remote data, but there is no general warning in code comments or docstrings that user-supplied stock codes, query parameters, and request metadata will be sent to third-party providers. While network access is central to the script's purpose, the DangInvest/news and direct Tencent/Sina calls are broader than a purely local data operation and would benefit from explicit disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring, help text, and user-facing output are written in Chinese, and the script does not provide any option to select another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.