Back to skill

Security audit

Stock Monitor

Security checks for vulnerabilities and agentic risk

Overview

This stock-monitoring skill is mostly purpose-aligned, but it runs a long-lived background monitor and sends portfolio/watchlist-related queries to third-party financial services without enough privacy and data-source disclosure.

Install only if you are comfortable running a user-started background stock monitor that repeatedly contacts Sina and Eastmoney with your watchlist-related queries. Keep holdings and cost-basis data local, do not commit edited config/code with portfolio details, verify any financial recommendations independently, and prefer an updated version that documents data providers, uses HTTPS for all endpoints, and clearly separates alerts from investment advice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyser.py:123
Finding

Unencrypted Financial Data API Request

Content
View full analysis

Vulnerability Details

File Location: scripts/analyser.py:123-139
Vulnerability Type: Plaintext HTTP communication
Risk Level: Medium

Vulnerable Code

python
url = f"http://datacenter-web.eastmoney.com/api/data/v1/get"
params = {
    "sortColumns": "NET_BUY_AMT",
    "sortTypes": "-1",
    "pageSize": "50",
    "pageNumber": "1",
    "reportName": "RPT_DMSK_TS",
    "columns": "ALL",
    "filter": f"(TRADE_DATE='{date}')"
}

try:
    resp = self.session.get(url, params=params, timeout=10)
    data = resp.json()
    return data.get("result", {}).get("data", [])
except:
    return []

Technical Analysis

The fetch_dragon_tiger() method retrieves financial ranking data through plaintext HTTP. HTTP does not provide transport confidentiality, server authentication, or response integrity. An attacker in a position to intercept network traffic could impersonate the data provider or modify the response in transit.

The method immediately decodes and returns the response as JSON without checking the HTTP status, validating the response schema, or authenticating the source. Consequently, a forged response containing manipulated financial records could be accepted as legitimate application data.

Attack Path

  1. A user runs the stock analysis functionality on an attacker-controlled or otherwise compromised network.
  2. The application requests the Eastmoney endpoint over plaintext HTTP.
  3. A network-positioned attacker intercepts the request through techniques such as a malicious access point, compromised gateway, or DNS manipulation.
  4. The attacker returns a syntactically valid but manipulated JSON response.
  5. resp.json() accepts the forged response, and the method returns attacker-controlled financial records.
  6. Any downstream analysis or user decision based on those records may rely on false market information.

Impact Assessment

The issue allows a network-positioned attacker to compromise the integrity and confidentiality ...[truncated 474 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the plaintext endpoint with the provider's verified HTTPS endpoint:
python
url = "https://datacenter-web.eastmoney.com/api/data/v1/get"
  1. Keep TLS certificate verification enabled. Do not introduce verify=False; where appropriate, explicitly use a trusted CA bundle.
  2. Reject unsuccessful HTTP responses before parsing:
python
resp = self.session.get(url, params=params, timeout=10)
resp.raise_for_status()
  1. Validate the response content type and enforce an expected JSON schema, including the types and permitted ranges of financial fields.
  2. Treat missing or malformed fields as an error rather than silently accepting partial data.
  3. Log failures without exposing sensitive information, and clearly mark unavailable data instead of using unverifiable results.
  4. Consider cross-checking high-impact market information against an independent authenticated data source before presenting actionable analysis.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documentation and detected behavior are inconsistent: the skill is presented as a 7-rule stock alert system, while analysis suggests additional undeclared news, sentiment, capital-flow, and macro-correlation capabilities. Undeclared functionality is dangerous because users may authorize or run the skill under false assumptions, while hidden data access and analysis paths expand the attack surface and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation and detected behavior are inconsistent: the skill is presented as a 7-rule stock alert system, while analysis suggests additional undeclared news, sentiment, capital-flow, and macro-correlation capabilities. Undeclared functionality is dangerous because users may authorize or run the skill under false assumptions, while hidden data access and analysis paths expand the attack surface and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The documentation and detected behavior are inconsistent: the skill is presented as a 7-rule stock alert system, while analysis suggests additional undeclared news, sentiment, capital-flow, and macro-correlation capabilities. Undeclared functionality is dangerous because users may authorize or run the skill under false assumptions, while hidden data access and analysis paths expand the attack surface and privacy risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents the skill's purpose and features exclusively in Chinese, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy when users are not given a choice or clear justification for the restriction.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documents a background monitoring system and references scripts that likely fetch market data, but it declares no explicit tool scope or permissions. This is dangerous because users and platform controls cannot clearly constrain or audit the network behavior the skill appears to require, increasing the risk of silent external access or overbroad capability use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description states that the system is designed to match Chinese investor habits, and later sections define China-specific display conventions and Beijing-time scheduling as defaults. This is a natural-language locale policy constraint that is imposed by the skill description rather than presented as an optional regional mode.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is declared as a monitoring/alert system but is described as an 'intelligent investment advisory system' that gives recommendation-style guidance. This is risky because it changes user expectations and may encourage higher-trust financial decision-making without explicit disclosure, safeguards, or appropriate compliance framing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill encourages running a persistent background daemon and control script without clearly disclosing the persistence, data collection cadence, or likely network access. Persistent processes are dangerous when under-documented because they can continue collecting data, consuming resources, or contacting external services beyond what a user reasonably expects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest focuses on price/technical alerting rules such as cost percentage, moving-average crosses, RSI, volume anomalies, gaps, and dynamic stop-profit. In contrast, the module docstring and implementation introduce additional analytical functions for news sentiment, capital flow, 龙虎榜 data, and macro asset correlation, which materially expands the skill's scope beyond the described alert system.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring says the function '获取东方财富个股新闻', implying it retrieves actual stock news. However, the code calls a suggest API and iterates over 'QuotationCodeTable' entries, which indicates search/suggestion results rather than a dedicated news feed, so the documentation overstates what the function does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code sends user-provided stock names and identifiers to third-party services without any user disclosure or consent mechanism. Even if stock symbols are not highly sensitive in isolation, watchlist interests and queried holdings can reveal trading intent, portfolio composition, or behavioral patterns, and this skill performs multiple outbound requests to external providers as part of analysis.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/control.sh (reported line 17)May include surrounding context.

sh
echo "🚀 启动 Stock Monitor 后台进程..."
        mkdir -p "$LOG_DIR"
        nohup python3 "$SCRIPT_DIR/monitor_daemon.py" > "$LOG_DIR/monitor.log" 2>&1 &
        echo $! > "$PID_FILE"
        echo "✅ 已启动 (PID: $!)"
        echo "📋 日志: $LOG_DIR/monitor.log"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file presents its title, comments, and alert messages in Chinese, and the runtime output strings shown to users are also Chinese-only. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring says the function '抓取个股最近新闻' (fetch recent stock news), implying it retrieves and returns news content. In practice, the function merely performs a request to an Eastmoney endpoint and always returns a placeholder string 新闻模块已就绪 (市场收盘中) instead of parsed news results, which directly contradicts the documented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring presents the skill description entirely in Chinese (e.g. '后台常驻进程', '自动运行监控'), which indicates a fixed language choice in natural-language content. The policy requires avoiding forced language/locale constraints unless the skill offers opt-in or clearly documents a justified regional limitation, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains natural-language documentation and runtime messages exclusively in Chinese, which enforces a specific language for users of the skill. The policy requires either offering a language/locale choice or clearly documenting and justifying the locale constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file tells the user to create and edit config.py with their holdings, which implies storing personal financial information locally. The README does not mention any privacy or data-handling warning, so users are not alerted that sensitive portfolio data may be written to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

These lines define red as gains and green as losses as a fixed behavior, which may conflict with users from other locales or platforms that use opposite conventions. Because no opt-in or configuration choice is offered here, it appears to force a locale-specific display policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The section title explicitly fixes the schedule to Beijing time, which is a locale-specific operational policy. Without a stated regional-only scope or a configurable timezone option, this can violate language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstrings, comments, and user-facing recommendation strings are all written in Chinese, including the generated analysis output. This imposes a specific language on users without any visible opt-in or localization choice, which is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's user-facing strings, including status messages and usage instructions, are entirely in Chinese. This imposes a specific language on all users without opt-in, which matches the language/locale policy violation category for natural-language content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a stock monitoring and alerting system with seven specific rule types: cost percentage, moving-average crossovers, RSI, volume anomalies, gap detection, and trailing-profit alerts. However, the code also implements fixed-price threshold alerts via price_above and price_below, which are not part of the stated seven-rule scope and materially expand alert behavior beyond the description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest describes the skill as a stock monitoring and alerting system, but this test suite explicitly validates a '伦敦金' / XAU market-data path. Monitoring gold may be implemented in the codebase, but that capability is not clearly justified by the stated stock-focused purpose in the manifest.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline comment states '当前是纽约时间,转换成北京时间', but the code calls datetime.now() with no timezone handling, which returns local system time rather than New York time. This is an active contradiction between the documentation comment and the actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.