Back to skill

Security audit

BitSoulStockSkill

Security checks for vulnerabilities and agentic risk

Overview

The skill's code, declared environment variables, and runtime instructions are consistent with a stock-data / quant-backtest tool that uses a BITSOUL_TOKEN to fetch data and write local caches; nothing in the bundle strongly contradicts its stated purpose.

This skill appears internally consistent with a remote-stock-data + backtest tool. Before installing: (1) Review and be comfortable providing BITSOUL_TOKEN — consider using a limited/test token or account, since the skill will use it to query the provider. (2) Expect the skill to download and persist a local SQLite database and data packages into the cache directory (BITSOUL_CACHE_DIR or the skill work dir); ensure you have disk space and want that. (3) The skill will fetch data from info.aicodingyard.com (declared) and finance.sina.com.cn — if you need to audit endpoints, inspect remote_api.py and scripts/stock_api.py for exact URLs and payloads. (4) The skill enforces printing raw result['summary_text'] from the remote backtest API before any explanation — that can surface unfiltered remote text; if that concerns you, review the API responses or run the skill in a sandbox first. (5) If you need higher assurance, ask the author for source provenance or run the code in an isolated environment and inspect network traffic and downloaded files.

Static analysis

No suspicious patterns detected.