Back to skill

Security audit

财经新闻深度分析技能

Security checks for vulnerabilities and agentic risk

Overview

This finance-news skill is not overtly malicious, but it needs Review because it can trigger too broadly, persist reports or scheduled runs, and presents finance recommendation-like guidance despite saying it does not recommend stocks.

Install only if you want a Chinese-language finance briefing tool and are comfortable with generated non-personalized labels that may look like investment advice. Keep activation explicit, use --no-save if you do not want local reports/cache, avoid cron or watch-style recurring runs unless intentional, and install optional dependencies only in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
requirements.txt:14
Finding

Unpinned and Unnecessary Optional Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, lines 14–35
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Low

bash
pip install requests
pip install httpx

pip install beautifulsoup4
pip install lxml

pip install feedparser

pip install pandas
pip install jq

Technical Analysis

The installation instructions direct users to install third-party packages without exact version constraints, integrity hashes, or a lock file. Package installation can execute package build or installation logic under the privileges of the invoking user. Consequently, future package releases, compromised upstream distributions, or altered transitive dependencies would enter the environment without reproducible review.

These packages are described as optional and are not imported or required by the current fetch_news.py implementation. Installing them therefore expands the supply-chain attack surface beyond the minimum privileges and components necessary for the implemented functionality.

No evidence indicates that the named packages are currently malicious or that the project uses dependency confusion, typosquatting, or an untrusted package index. The risk arises from unnecessary and non-reproducible installation guidance.

Attack Path

  1. A user follows the optional dependency installation instructions.
  2. pip resolves the latest available package versions and their transitive dependencies.
  3. If an upstream release or dependency has been compromised, its build or installation code runs during installation.
  4. Malicious code executes with the permissions of the user running pip.
  5. The compromised component may subsequently access files, credentials, or network resources available to that user.

This path depends on a supply-chain compromise and is not directly triggered by running the current news script.

Impact Assessment

Successful exploitation could ...[truncated 370 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove installation instructions for packages not used by the current implementation.
  2. If dependencies become necessary, declare exact versions in a conventional dependency manifest.
  3. Generate a reviewed lock file and require package hashes, such as through pip-compile --generate-hashes.
  4. Install packages from an explicitly trusted index in an isolated virtual environment.
  5. Avoid elevated installation and use python -m pip associated with the intended interpreter.
  6. Add automated dependency vulnerability and provenance scanning to the release process.
  7. Separate required dependencies from optional feature groups so users install only the components needed for the selected functionality.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are extremely broad, including generic terms like '财经', '新闻', company names, and industry names, so the skill may auto-activate in many ordinary conversations. In an agent environment, this can unexpectedly initiate browsing, scraping, caching, and report generation without clear user intent, increasing the chance of unwanted external access or persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The later activation rules expand scope even further with generic finance, market, news, company, and industry terms. Because the skill also defines downstream actions like calling fetch_news.py and saving output, such broad matching materially raises the risk of unintended execution and data handling in response to routine chat content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documentation is entirely in Chinese and presents all commands, descriptions, and output labels in that locale, with no indication that other languages are supported or that Chinese is an optional setting. This can violate language/locale policy when a skill effectively forces one language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill describes capabilities that save reports and cache data to local storage, but it declares no explicit tool scope or permissions. That mismatch can cause the runtime to grant broader-than-expected file write behavior or leave reviewers unaware that user-triggered actions may persist data on disk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document claims '不荐股' but repeatedly instructs the system to emit '操作建议' like 关注、谨慎、回避, which are de facto investment recommendations. This inconsistency can mislead users and reviewers about the skill's behavior, increasing legal, compliance, and user-harm risk if users rely on the output for trading decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The rule "中文输出: 默认简体中文,保留英文专有名词" imposes a specific language behavior in natural language instructions. There is no indication that users can choose another language or opt in to this locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This JSON file encodes stock names, sector labels, sentiment terms, and keywords primarily in Chinese, which imposes a specific language/locale choice in the skill data. Under the policy, forcing a specific language without user choice or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module description is entirely in Chinese and presents the skill as a Chinese-language finance news tool, with no indication that users may choose another language or locale. The policy explicitly flags language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code produces explicit investment operation advice such as '关注', '谨慎', and '回避' from very weak keyword heuristics, despite the skill being framed as news analysis. In a finance context, undisclosed automated advice can materially influence user decisions and creates a harmful mismatch between user expectations and actual system behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a skill that fetches from multiple finance sources and performs sentiment analysis, impact assessment, key information extraction, and professional briefing generation. In this file, nearly all source-specific fetchers are unimplemented stubs returning empty lists, and the analysis consists only of basic keyword matching plus stock-name substring detection rather than the deeper analysis implied by the description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This requirements file is written entirely in Chinese, including headings, instructions, troubleshooting, and command explanations. The file does not offer an alternative language, opt-in choice, or justification for a Chinese-only locale, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown states that reports are automatically saved to a dated path, and later also documents a cache directory for raw source data. Because this skill persists generated reports and cached source data on disk, the description should disclose that behavior so users understand local data will be stored.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The cron examples encourage recurring execution, but the documentation does not warn users that this enables automatic periodic fetching and ongoing creation of reports/cache files. For a markdown file, this is a missing user warning about behavior that can affect system state and stored data over time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.