Back to skill

Security audit

Tushare 金融数据助手

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Tushare financial-data skill, with some credential-hygiene and dependency-supply-chain cautions but no artifact-backed malicious behavior.

Install only in an environment where you are comfortable granting a Tushare API token. Prefer a secret manager or session-only environment variable instead of putting the token in ~/.bashrc, avoid running the helper where logs are shared, review any Feishu scheduled jobs before enabling them, and consider pinning dependencies before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Package Versions

Content
View full analysis
=1.2.60 pandas>=1.5.0 ``` The Skill metadata also declares a different minimum Tushare version, `tushare>=1.2.89`, making dependency resolution inconsistent and non-reproducible. ### Technical Analysis Both dependencies use minimum-version constraints without upper bounds or hashes. Consequently, an installation can resolve to any future version available from the configured Python package index rather than to the versions reviewed during this audit. The dependencies are necessary for the declared financial-data functionality. However, allowing arbitrary future versions exceeds the reviewed dependency scope and exposes installation and runtime to upstream package compromise, malicious releases, or incompatible changes. Python packages may execute code during installation or when imported. ### Attack Path 1. An attacker compromises the publisher account, distribution infrastructure, or a future permitted release of one of the dependencies. 2. The attacker publishes a malicious version satisfying the broad version constraint. 3. A user installs the Skill dependencies using `requirements.txt` or the documented installation instructions. 4. The package manager resolves the malicious future version. 5. Malicious package code executes during installation or import with the privileges of the user or Agent process. ### Impact Assessment A malicious dependency could execute arbitrary code with the current process user's privileges. Depending on the environment, this may permit access to local files, environment variables such as `TUSHARE_TOKEN`, Agent-accessible credentials, network resources, and data handled by the Skill. The issue does not itself provide elevated operating-system privileges; its scope is bounded by the privileges ...[truncated 46 chars]
Remediation
View remediation
pandas== ``` 2. Generate and commit a lock file containing transitive dependencies and cryptographic hashes. 3. Use hash-enforced installation, such as `pip install --require-hashes`. 4. Make the versions in `requirements.txt` and `SKILL.md` identical. 5. Install packages only from an explicitly configured trusted package index. 6. Review and test dependency updates before changing the lock file. 7. Run dependency installation and Skill execution in an isolated, least-privileged environment. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/tushare_helper.py:251
Finding

Tushare API Token Prefix Disclosed to Standard Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (94)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 46)May include surrounding context.

bash
git clone https://github.com/StanleyChanH/Tushare-Finance-Skill-for-Claude-Code.git
cd Tushare-Finance-Skill-for-Claude-Code
pip install -r requirements.txt

🔑 配置

获取 Tushare Token

  1. 访问 Tushare Pro 注册账号
  2. 在个人中心获取 Token
  3. 配置环境变量:
bash
export TUSHARE_TOKEN="your_token_here"

# 或添加到 ~/.bashrc
echo 'export TUSHARE_TOKEN="your_token_here"' >> ~/.bashrc
source ~/.bashrc

🚀 快速开始

Python API

python
from scripts.api_client import TushareAPI

# 初始化客户端
api = TushareAPI()

# 查询股票日线行情
df = api.get_stock_daily("000001.SZ", "2024-01-01", "2024-12-31")
print(df.head())

# 查询公司基本信息
info = api.get_stock_info("000001.SZ")
print(info)

# 批量查询多只股票
stocks = ["000001.SZ", "000002.SZ", "600000.SH"]
data = api.batch_query(stocks, "2024-01-01", "2024-12-31")

命令行工具

bash
# 查询单只股票
python

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README instructs users to persist the Tushare token in shell startup files and also shows plaintext token storage in configuration without any warning about local credential exposure. Secrets stored this way can be recovered by other local users, leaked through backups, dotfile sync, shell history, screenshots, or accidental commits if copied into project files.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires an environment secret (TUSHARE_TOKEN) and shows code that uses ambient environment access, but it does not declare any explicit tool scope or permissions boundary. This can lead to over-broad secret exposure or unclear runtime expectations, especially in agent environments where undeclared env access may bypass user understanding or policy review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill describes scheduled delivery of generated reports to Feishu, an external channel, without an explicit warning that generated content will be transmitted off-platform on a recurring basis. Even if the payload is 'just market reports', generated reports may contain user-provided prompts, proprietary analysis, or sensitive derived data, and automation increases the chance of unintended disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description forces a specific language/locale in user-facing text without offering an alternative or indicating that the skill is intentionally region- or language-specific. This can violate language/locale policy when users are not given a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document title and explanatory text are entirely in Chinese, and the file does not indicate that users may choose another language or that the locale restriction is intentional and justified. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document exposes and exemplifies collection of personal-profile data for named individuals, including name, gender, nationality, birthday, employment dates, and potentially resume content, without any warning about sensitive data handling, lawful use, minimization, or downstream privacy obligations. In a financial data skill, this increases the risk that agents or users will retrieve, store, or republish personal data without appropriate safeguards.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document describes the cb_factor_pro interface for convertible-bond technical factors, but the second usage example calls pro.hk_income(trade_date='20250724'), which is a different endpoint entirely. This is an active contradiction in the documentation, not merely an omission, and can mislead developers into invoking the wrong capability.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This documentation introduces a politically framed propaganda/ideological dataset inside a skill advertised as a financial market data capability. That mismatch can mislead downstream agents or users into retrieving and operationalizing non-financial ideological content under the trust boundary of a finance tool, increasing the risk of inappropriate content injection into analysis workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The text uses mandatory ideological framing such as urging users to study and internalize party guidance, rather than neutrally describing the dataset. In an agent skill context, this can bias model behavior, normalize propagandistic instructions, and create prompt-injection-like steering content embedded in reference documentation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

文档在输入参数部分声明使用 month、start_month 和 end_month(L24-L39),但示例代码却调用 trade_date、start_date 和 end_date。这里不是简单的省略信息,而是文档说明与示例实现对同一接口的参数定义直接不一致,容易误导开发者按错误意图调用接口。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language descriptions and user-facing messages exclusively in Chinese, including the top-level module docstring and later runtime/error text. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest frames the skill as a Tushare Pro financial data access interface focused on retrieving market and research data. In addition to querying Tushare, this file implements local file-writing capabilities for CSV, JSON, and Excel exports, which is broader behavior than a pure data-interface client and is not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language interface text and messaging are entirely in Chinese, including the module description and user-facing exceptions/prints, with no indication that the user can opt into another language. This creates a language policy concern because the skill implicitly enforces a locale/language choice rather than offering one.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations in natural-language content. This file presents all human-readable name values in Chinese across the dataset, but does not document that the skill is China/Chinese-specific or offer any language/locale opt-in, which can impose a specific language on users implicitly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese and does not indicate that language selection is optional. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions, parameters, and examples only in Chinese, with no indication that the user can choose another language or that the document is intentionally limited to a Chinese-only audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing documentation exclusively in Chinese, and there is no indication that users can choose another language or that the language restriction is intentionally limited to a region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file presents all instructions, parameter descriptions, and examples only in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no alternative language choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire skill file is written in Chinese and does not mention any option for alternative languages or a justification that the skill is intended only for a Chinese-speaking or region-specific audience. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill document is presented only in Chinese and does not indicate any user language choice or opt-in. Under the policy for natural-language violations, forcing a specific language without user opt-in is reportable unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, which can constitute a language/locale policy issue when no opt-in, alternative language, or justification is provided. The policy for SQP-3 specifically covers skills that force a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file presents all user-facing instructions and API documentation exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file is natural-language documentation, and its content is fully presented in Chinese, including headings, parameter descriptions, and examples. Under the language/locale policy rule, forcing a single language without user opt-in or justification can be a policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file documents output fields including unified social credit code, legal representative, email, and other company-identifying details, but it does not include any caution about responsible handling of potentially sensitive business contact data. Under the markdown-specific warning criterion, documentation that omits privacy-impact warnings for data-affecting behavior can merit a finding.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.