Back to skill

Security audit

Super Trend Analysis

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis skill is mostly coherent, but needs review because a crafted stock name could make it write report files outside its intended folder.

Install only if you are comfortable running local Python scripts that read stock CSV files and write reports. Avoid using untrusted stock names or output paths until filename sanitization is added, install dependencies in an isolated environment, and treat all trading signals as informational rather than financial advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyze_trend.py:250
Finding

Output Path Traversal Through Unsanitized Stock Name

Content
View full analysis

Vulnerability Details

File Location: scripts/analyze_trend.py, lines 250-252 and 271-272
Vulnerability Type: Path traversal and unintended file overwrite
Risk Level: Medium

Vulnerable Code

python
report_file = output_path / f"{stock_name}_趋势分析_{datetime.now().strftime('%Y%m%d')}.md"
with open(report_file, "w", encoding="utf-8") as f:
    f.write(report)
python
data_file = output_path / f"{stock_name}_技术指标.csv"
df_with_indicators.to_csv(data_file, index=False, encoding="utf-8-sig")

Technical Analysis

The user-controlled stock_name value is incorporated directly into two output paths without normalization or validation. The value can originate from the command-line --name argument and may contain parent-directory components such as ../, path separators, or an absolute path.

pathlib.Path does not confine the resulting path to output_path. Parent-directory components are resolved by the operating system during file access, while an absolute right-hand path can supersede the intended base directory. Both output operations use overwrite-capable behavior, so an existing file with the generated path can be replaced.

Exploitation is constrained by the fixed report and CSV filename suffixes and by the permissions of the process. Nevertheless, the intended output-directory boundary can be bypassed.

Attack Path

  1. The attacker or untrusted caller supplies a crafted stock name through --name.
  2. For example, a value containing ../target is passed to the application.
  3. The application constructs paths such as trend_reports/../target_technical-indicators.csv and a date-suffixed Markdown report path.
  4. The operating system resolves the parent-directory component outside trend_reports.
  5. The application creates or overwrites the resulting files if its process account has permission to do so.

Impact Assessment

An attacker can cause Markdown and CSV outp ...[truncated 448 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat stock_name as a display value rather than a filesystem path.
  2. Reject absolute paths, . and .. path components, directory separators, control characters, and platform-specific reserved characters.
  3. Convert the supplied name to a conservative filename token, such as characters from an explicit allowlist.
  4. Resolve both the output directory and candidate destination, then verify that the destination remains beneath the resolved output directory.
  5. Use exclusive file creation mode when replacing existing reports is not required.
  6. Keep the original stock name only inside report content and use a separately generated safe identifier for filenames.

Example confinement logic:

python
import re
from pathlib import Path

output_root = Path(output_dir).resolve()
output_root.mkdir(parents=True, exist_ok=True)

safe_name = re.sub(r"[^A-Za-z0-9._-]", "_", stock_name)
if not safe_name or safe_name in {".", ".."}:
    raise ValueError("Invalid stock name")

report_file = (
    output_root /
    f"{safe_name}_trend_analysis_{datetime.now().strftime('%Y%m%d')}.md"
).resolve()

if output_root not in report_file.parents:
    raise ValueError("Output path escapes the configured directory")

T08 · Insecure Dependencies

Note
Location
SKILL.md:129
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 129-132
Vulnerability Type: Unpinned and non-reproducible dependency installation
Risk Level: Low

Vulnerable Code

bash
# Install required libraries
pip install pandas numpy matplotlib seaborn ta

Technical Analysis

The installation instructions retrieve third-party packages without pinning reviewed versions or validating package hashes. As a result, the effective dependency set is mutable and can differ between installations based on newly published releases, transitive dependency resolution, index configuration, or package compromise.

The command does not itself demonstrate a malicious package or an active dependency-confusion condition. The risk arises from allowing future, unreviewed package versions and transitive dependencies to be downloaded and executed during installation.

Attack Path

  1. A user follows the documented installation command.
  2. pip resolves the latest compatible versions from the configured package index.
  3. A compromised, malicious, or unexpectedly changed direct or transitive package version is selected.
  4. Package build or installation logic executes with the privileges of the user running pip.
  5. The compromised dependency may subsequently execute when imported by the analysis scripts.

Impact Assessment

A compromised dependency could execute code with the privileges of the installing or invoking user. Depending on those privileges, this could expose local files, modify user-accessible data, or compromise the runtime environment.

No compromised dependency was identified during this audit. The confirmed issue is the absence of version pinning, integrity verification, and reproducible dependency resolution.

Remediation
View remediation

Remediation Suggestions

  1. Pin each direct dependency to a reviewed version.
  2. Generate and commit a lock file that includes transitive dependencies.
  3. Require cryptographic hashes for downloaded distributions, such as through pip install --require-hashes.
  4. Install packages only from a trusted, explicitly configured package index.
  5. Periodically scan locked dependencies for known vulnerabilities and review updates before changing pinned versions.
  6. Remove dependencies that are documented but not actually required by the implemented functionality.

A hash-locked requirements file should be installed with a command similar to:

bash
python3 -m pip install --require-hashes -r requirements.txt
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch is more serious because the skill is presented as single-stock analysis but also includes batch directory scanning and heuristic processing of local CSV files. Undeclared local traversal/bulk processing expands access beyond the expected user action, which can lead to unintended enumeration and processing of local datasets in an agent context.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This mismatch is more serious because the skill is presented as single-stock analysis but also includes batch directory scanning and heuristic processing of local CSV files. Undeclared local traversal/bulk processing expands access beyond the expected user action, which can lead to unintended enumeration and processing of local datasets in an agent context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documentation exposes file-writing behavior through report/chart generation but does not declare any explicit tool scope or permissions. In agent environments, undocumented write capability can enable unexpected filesystem modification, making it harder to enforce least privilege and increasing risk if the underlying scripts are invoked on attacker-controlled paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill provides buy/sell signal guidance without a clear disclaimer that outputs are informational and not financial advice. In context, this can materially influence user trading decisions, causing financial harm even if there is no traditional code-execution issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s description and all user-facing messages are written exclusively in Chinese, and there is no indication that the skill is region-specific or that users may select another language. This creates a natural-language locale policy issue because the skill implicitly forces one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language content such as the module docstring, argument descriptions, and error/output messages entirely in Chinese. Under the policy, forcing a specific language without user opt-in or clear justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The parser description, argument help text, and progress/result messages are all presented only in Chinese, which imposes a locale choice on users. The file does not offer an alternative language or explain why a Chinese-only interface is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file uses Chinese-only module documentation, docstrings, default column naming, and user-facing signal text throughout, which imposes a specific language/locale on consumers of the skill. The policy allows locale constraints only when users are given a choice or when the regional limitation is clearly documented and justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and main documentation are written entirely in Chinese, and examples and output text assume Chinese-language interaction. There is no indication that Chinese is optional, user-selectable, or required for a documented region-specific purpose, which can conflict with language-choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.