Back to skill

Security audit

A股实时行情数据

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed setup and reference guide for using the mootdx China stock-data library, with ordinary package-install supply-chain cautions but no hidden or destructive behavior in the artifacts.

Install this only in a virtual environment or other isolated Python environment, and consider pinning mootdx and dependencies before use. Running the default setup helper will fetch and install packages from the configured pip index and will make live TDX network requests; use --check if you only want verification without installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/setup_and_verify.py:17
Finding

Automatic Installation of an Unpinned Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: scripts/setup_and_verify.py:17-21
Additional Location: SKILL.md:14
Vulnerability Type: Unpinned and unverified third-party dependency installation
Risk Level: Medium

The default setup workflow installs the latest version of mootdx and its transitive dependencies without version constraints, integrity hashes, a lockfile, or an explicitly trusted package index.

python
def install():
    """Install mootdx via pip."""
    print("Installing mootdx...")
    subprocess.check_call([sys.executable, "-m", "pip", "install", "mootdx"])
    print()

The same behavior is presented in the installation documentation:

bash
pip install mootdx

Technical Analysis

Python packages can execute package-controlled code during installation and later when imported. Because the command requests an unpinned package name, the artifact installed by this script can change over time without any corresponding change to the audited project.

Pip also inherits package-index and resolver configuration from the execution environment. The script does not:

  • Pin a reviewed mootdx version.
  • Lock or constrain transitive dependency versions.
  • Verify package artifacts using cryptographic hashes.
  • Select an explicitly trusted package index.
  • Separate dependency installation from the default verification workflow.

Consequently, a compromised upstream release, compromised transitive dependency, or attacker-controlled package index configured in the environment could supply code that was not part of this audit.

Attack Path

  1. An attacker compromises a future mootdx release, one of its transitive dependencies, or a package index used by the target environment.
  2. A user follows the documented default command:
    bash
    python scripts/setup_and_verify.py
    
  3. Because --check was not supplied, main() invokes install().
  4. The scrip ...[truncated 1325 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin mootdx and all transitive dependencies to versions that have been reviewed and tested.
  2. Maintain dependencies in a lockfile or requirements file generated with a tool such as pip-compile.
  3. Require cryptographic hashes for every resolved artifact, for example:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Configure an explicitly trusted package index rather than silently inheriting arbitrary index configuration.
  5. Review package provenance and monitor pinned dependencies for security advisories.
  6. Remove automatic installation from the default verification path. Require an explicit option such as --install before modifying the Python environment.
  7. Run installation in an isolated virtual environment under a non-privileged account.
  8. Consider changing the implementation to:
    python
    subprocess.check_call([
        sys.executable,
        "-m",
        "pip",
        "install",
        "--require-hashes",
        "-r",
        "requirements.txt",
    ])
    
  9. Update SKILL.md so the documented installation process uses the same pinned and hash-verified dependency manifest.
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill includes executable shell usage in its installation and verification instructions, but it does not declare any tool scope such as allowed-tools or permissions. In an agent environment, this can cause the agent to invoke shell commands without explicit least-privilege constraints, increasing the risk of unintended package installation, network access, or command execution.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup_and_verify.py (reported line 20)May include surrounding context.

python
def install():
    """Install mootdx via pip."""
    print("Installing mootdx...")
    subprocess.check_call([sys.executable, "-m", "pip", "install", "mootdx"])
    print()

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/setup_and_verify.py (reported line 31)May include surrounding context.

python
ok = True
    for pkg, label in [("mootdx", "mootdx"), ("tdxpy", "tdxpy (internal dep)"), ("pandas", "pandas")]:
        try:
            mod = __import__(pkg)
            ver = getattr(mod, "__version__", "OK")
            print(f"  [OK] {label} — {ver}")
        except ImportError:

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script automatically installs a package via pip when run without --check, which modifies the user's Python environment and fetches code from a remote package index without an explicit side-effect warning or confirmation. In an agent-skill context this is more sensitive because users may execute setup helpers expecting verification, while the script can unexpectedly perform network access and install software, increasing supply-chain and environment-integrity risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.