Back to skill

Security audit

缠论技术分析修改版

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent stock-analysis tool that fetches public market data and writes local reports/charts, with some transparency and dependency hygiene issues users should understand.

Install in a dedicated virtual environment, avoid elevated privileges, and be aware that stock names or codes you analyze may be sent to external market-data services. The generated reports are local files and the skill's own disclaimer correctly says the analysis is not investment advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:150
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

other

Note
Location
scripts/chanlun_core.py:696
Finding

Stock Search Queries Are Sent to an Undisclosed External Service

Content
View full analysis
Optional[Dict[str, str]]: """通过股票名称搜索股票代码""" url = "https://searchapi.eastmoney.com/api/suggest/get" params = {"input": stock_name, "type": 14, "count": 5} data = _safe_get_json(url, params) ``` ### Technical Analysis The Skill documentation states that Tencent supplies the market data, but the implementation first sends the user-provided stock search term to Eastmoney's search API. The transmission is functionally related to resolving a stock name to a security code, and it uses HTTPS. However, the additional external recipient and the data sent to it are not disclosed in `SKILL.md`. The destination is a fixed HTTPS URL, so user input cannot redirect the request to an arbitrary server. The reviewed code does not attach credentials, local files, environment variables, or other sensitive system data. This finding is therefore a transparency and query-privacy issue rather than evidence of malicious exfiltration or server-side request forgery. ### Attack Path 1. A user invokes the Skill with a stock name or code. 2. `analyze_stock()` passes that input to `search_stock_code()`. 3. `search_stock_code()` places the raw input in the `input` query parameter. 4. `_safe_get_json()` sends the request to `https://searchapi.eastmoney.com/api/suggest/get`. 5. Eastmoney can observe the query, request time, browser-like User-Agent, and network metadata such as the source IP address. 6. The resolved security identifier is subsequently used in a separate request to Tencent for K-line data. ### Impact Assessment The external service can learn which securities the user searches for and correlate those queries with timing and network metadata. Repeated requests may reveal investment interests or analysis patterns. Th ...[truncated 314 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents execution of a Python script that fetches remote market data and automatically generates output files, but it does not declare any explicit tool scope such as network or file-write permissions. This creates an authorization gap: an agent or reviewer cannot easily determine the minimum required capabilities, and a broader-than-necessary runtime may silently permit network access and filesystem writes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code file contains natural-language instructions and descriptions entirely in Chinese, starting with the module docstring, with no indication that language selection is optional. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy concern unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing natural-language strings entirely in Chinese, including the module description and all CLI output, but provides no indication that the skill is region-specific or that users may choose another language. Under the policy rule for language/locale constraints, this is a natural-language policy concern because the script effectively enforces one language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file-level description states the generator produces charts with English labels, yet later code hardcodes Chinese text for pivot annotations. This creates a language/locale inconsistency and forces a specific language in output content without giving the user a choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The legend declares 'Up Stroke' as a blue solid line and 'Down Stroke' as a purple dashed line, suggesting viewers can distinguish stroke direction visually. However, _plot_strokes uses color = 'blue' and linestyle = '-' for both up and down directions at L164-L165, so the documentation embedded in the chart contradicts actual behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The chart legend communicates that directional annotations use different visual encodings, but _plot_segments also renders both segment directions with the same green solid line at L185-L186. This creates an intent-code mismatch where the chart's explanatory labeling overstates directional differentiation that the plot does not actually provide.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.