Back to skill

Security audit

股票查询 / Stock Price Query

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent stock quote lookup tool that runs a local Python script to query a public Tencent market-data endpoint, with no evidence of hidden persistence, credential access, or destructive behavior.

Install only if you are comfortable with stock symbols you query being sent to Tencent's public quote API. The skill does not trade, access brokerage accounts, store credentials, or persist background behavior, but its responses are mainly formatted for Chinese-language finance use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to run a Python script that fetches data from external public quote APIs, but the manifest does not declare any corresponding tool scope such as network permissions or allowed tools. This creates a policy/visibility gap: a reviewer or runtime may not understand that outbound network access is required, which weakens least-privilege controls and makes unexpected external access easier to hide.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation guidance includes broad phrases such as "大盘怎么样", "查股票", and "股票行情" without any exclusion conditions or tighter context. These common expressions could cause unintended activation in general financial discussions rather than only when the user clearly wants this specific skill executed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The output requirements prescribe a specific Chinese-formatted response, including Chinese units and wording, even though the skill description is bilingual and example inputs include English. This can violate language or locale policy when users have not opted into Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire API reference is written only in Chinese, including headings, field descriptions, and operational notes, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script transmits user-supplied stock symbols to Tencent's third-party quote service, but it does not clearly disclose this network egress to the user at runtime. While stock symbols are usually low-sensitivity, they can still reveal user interests, trading intent, or monitored watchlists, so undisclosed sharing creates a privacy and transparency issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.