Back to skill

Security audit

模拟交易系统

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent paper-trading skill, but it needs review because it persists and mutates portfolio data, uses an external market-data service by default, reads an API key from the shell profile, and has validation gaps that can corrupt simulated results.

Install only if you are comfortable with a local paper-trading database that can be changed or deleted by skill commands and with holdings symbols being sent to Eastmoney during default refreshes. Prefer using --no-refresh when external calls are not wanted, provide EM_API_KEY explicitly through the environment rather than ~/.bashrc, and avoid relying on this skill for real financial decisions until price validation and recovery controls are improved.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/market_data.py:62
Finding

Unvalidated Market Prices Can Corrupt the Simulated Trading Ledger

Content
View full analysis
= od["price"]: should_match = True match_price = mp if should_match: result = _execute_single(conn, od, match_price) ``` The resulting negative cost is applied directly to the portfolio balance: ```python # scripts/matching.py:75-91 p = conn.execute("SELECT cash FROM portfolios WHERE id=?", (pid,)).fetchone() cost = qty * price if p["cash"] < cost: conn.execute( "UPDATE orders SET status='rejected',updated_at=datetime('now','localtime') WHERE id=?", (oid,), ) conn.commit() ...[truncated 3287 chars]
Remediation
View remediation
0) ``` Similar constraints should protect quantities, cash values, average costs, NAV values, and trade prices. 7. Perform all matching mutations in an explicit transaction. Roll back the cash, holding, order, and trade changes together if validation or any database operation fails. 8. Add regression tests for negative prices, zero, booleans, strings, missing fields, `NaN`, positive and negative infinity, excessively large values, and malformed remote responses. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises a full simulated-trading platform with account management, order lifecycle, matching, NAV/performance analytics, and real-time market refresh, but the analyzer reports the implementation does not provide those capabilities. This mismatch is dangerous because users or upstream agents may rely on nonexistent controls and outputs for financial decisions, causing unauthorized actions, silent failure, or deceptive behavior in a high-sensitivity domain.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope while its documented behavior relies on environment variables and external network access for market-data refresh. Missing scope declarations weaken the trust boundary: an orchestrator or reviewer cannot easily constrain what the skill may access, increasing the chance of unintended network use or secret exposure through environment reads.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

This duplicate persistence finding is also valid: the description advertises account/holding/portfolio management and trade workflows that necessarily maintain state across interactions. In a trading-like skill, such state can influence future operations and outputs, making accidental or unauthorized reuse more dangerous than in stateless informational skills.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: simulated-trading
description: 全功能模拟交易系统。创建投资组合、下单买入卖出、撤单、撮合成交、管理行情数据、计算净值与组合绩效(收益率、波动率、夏普比率、最大回撤)。支持东方财富实时行情自动刷新。Use when user wants to simulate stock/fund trading, create paper trading portfolios, place/cancel orders, match orders, calculate NAV, analyze portfolio performance, or run backtesting scenarios. 触发场景:(1) 查看我的账户/持仓/组合 (2) 模拟买卖股票/ETF (3) 下单交易 (4) 查看净值收益 (5) 模拟炒股/模拟交易 (6) 投资组合管理 (7) 交易回测。
---

# 模拟交易系统 Simulated Trading

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

This duplicate persistence finding is also valid: the description advertises account/holding/portfolio management and trade workflows that necessarily maintain state across interactions. In a trading-like skill, such state can influence future operations and outputs, making accidental or unauthorized reuse more dangerous than in stateless informational skills.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: simulated-trading
description: 全功能模拟交易系统。创建投资组合、下单买入卖出、撤单、撮合成交、管理行情数据、计算净值与组合绩效(收益率、波动率、夏普比率、最大回撤)。支持东方财富实时行情自动刷新。Use when user wants to simulate stock/fund trading, create paper trading portfolios, place/cancel orders, match orders, calculate NAV, analyze portfolio performance, or run backtesting scenarios. 触发场景:(1) 查看我的账户/持仓/组合 (2) 模拟买卖股票/ETF (3) 下单交易 (4) 查看净值收益 (5) 模拟炒股/模拟交易 (6) 投资组合管理 (7) 交易回测。
---

# 模拟交易系统 Simulated Trading

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough to capture many ordinary investment-related conversations, potentially invoking this skill when the user did not ask for simulated trading operations. Over-broad activation is risky here because the skill handles persistent portfolio/order workflows and may fetch external market data, so accidental invocation could expose state or perform unintended actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The example workflow shows creation of a reusable portfolio identifier and subsequent multi-step operations, confirming durable state across commands. That persistence increases risk of cross-session confusion, replay of stale identifiers, or exposure of prior trading simulations if isolation and lifecycle controls are weak.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

bash
# 1. 创建 10 万初始资金的组合
python scripts/portfolio.py create "我的策略" 100000 "量化策略v1"
# → 返回 PTFxxxxxxxx

# 2. 录入行情

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The delete action removes market price records immediately based solely on a symbol argument, with no confirmation, soft-delete, authorization gate, or recovery path. In a simulated trading skill, market data integrity is central to pricing, valuation, and backtesting, so accidental or unauthorized deletion can disrupt account views and produce incorrect trading or performance results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python code performs safety-relevant state changes including cash balance updates, order status changes, trade insertion, and deletion of holdings records. Although the functions have internal docstrings, there is no user-facing confirmation prompt, warning print/log message, or other visible disclosure before these irreversible modifications are committed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing CLI error/success strings are written in Chinese, which imposes a specific language on all users. There is no opt-in, locale selection, or justification that this skill is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code cancels orders by updating persistent order state, and elsewhere in the file it also inserts orders, updates cash balances, modifies holdings, and deletes holdings records. Although the script returns success messages after the fact, there is no prior confirmation prompt or explicit warning comment/docstring to disclose that running these commands will immediately change trading and portfolio data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language strings such as the module docstring and CLI/help text exclusively in Chinese, and there is no indication that the user can opt into another language. Under the policy, forcing a specific language without user choice is a locale-policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's natural-language interface, including the module docstring, errors, usage text, and status messages, is entirely in Chinese. This imposes a specific language on users without any opt-in, language selection mechanism, or documented regional justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The delete_portfolio function deletes a portfolio record from storage and immediately commits the change, but there is no confirmation prompt before deletion. Although the success message is printed afterward, that does not warn the user before the irreversible action occurs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script reads EM_API_KEY from ~/.bashrc if the environment variable is absent, which expands its access to unrelated user shell configuration and secrets beyond what is necessary for a price refresh task. Even though it only matches one variable name, accessing shell startup files creates an unnecessary secret-discovery capability and can expose credentials without the user's awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill consumes a sensitive API credential from the environment and shell profile silently, with no user-facing notice that a secret will be read and used. In an agent-skill context, undisclosed secret access reduces user control and can violate least surprise, especially since the fallback scans a personal shell file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends requested symbols and portfolio holdings-derived symbols to external Eastmoney endpoints to obtain prices, but the code provides no disclosure or consent mechanism for this outbound data transfer. While symbols are not highly sensitive like passwords, portfolio composition and watchlists can reveal investment strategy and user interests, making silent exfiltration to third parties a privacy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill name and instructions are predominantly presented in Chinese, and the description does not state that the user may choose their preferred language or locale. This can violate language-choice policy when the skill is invoked by users who have not opted into Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring is entirely in Chinese, and all user-facing usage and error strings in this file are also Chinese-only, indicating the skill is designed to communicate in a fixed language without opt-in or alternative locale support. The policy allows locale constraints only when documented and justified or when users are given a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language docstrings and user-facing messages in this file are written exclusively in Chinese, and the skill does not indicate that language choice is optional or region-specific. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The module description and user-facing CLI messages are Chinese-only, which can impose a language choice on users without opt-in. Under the policy, forcing a specific language without offering a choice or documenting a justified regional scope is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.