T08 · Insecure Dependencies
- Location
SKILL.md:150- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent stock-analysis tool that fetches public market data and writes local reports/charts, with some transparency and dependency hygiene issues users should understand.
Install in a dedicated virtual environment, avoid elevated privileges, and be aware that stock names or codes you analyze may be sent to external market-data services. The generated reports are local files and the skill's own disclaimer correctly says the analysis is not investment advice.
SKILL.md:150Unpinned Third-Party Dependencies Create a Supply-Chain Risk
scripts/chanlun_core.py:696Stock Search Queries Are Sent to an Undisclosed External Service
The skill documents execution of a Python script that fetches remote market data and automatically generates output files, but it does not declare any explicit tool scope such as network or file-write permissions. This creates an authorization gap: an agent or reviewer cannot easily determine the minimum required capabilities, and a broader-than-necessary runtime may silently permit network access and filesystem writes.
This code file contains natural-language instructions and descriptions entirely in Chinese, starting with the module docstring, with no indication that language selection is optional. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy concern unless the constraint is explicitly justified.
This Python file contains user-facing natural-language strings entirely in Chinese, including the module description and all CLI output, but provides no indication that the skill is region-specific or that users may choose another language. Under the policy rule for language/locale constraints, this is a natural-language policy concern because the script effectively enforces one language by default.
The file-level description states the generator produces charts with English labels, yet later code hardcodes Chinese text for pivot annotations. This creates a language/locale inconsistency and forces a specific language in output content without giving the user a choice.
The legend declares 'Up Stroke' as a blue solid line and 'Down Stroke' as a purple dashed line, suggesting viewers can distinguish stroke direction visually. However, _plot_strokes uses color = 'blue' and linestyle = '-' for both up and down directions at L164-L165, so the documentation embedded in the chart contradicts actual behavior.
The chart legend communicates that directional annotations use different visual encodings, but _plot_segments also renders both segment directions with the same green solid line at L185-L186. This creates an intent-code mismatch where the chart's explanatory labeling overstates directional differentiation that the plot does not actually provide.
No suspicious patterns detected.