Back to skill

Security audit

股票技术分析

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis skill does what it claims, with normal finance-data network requests and local watchlist storage that users should understand before use.

Install in a virtual environment, review or pin dependency versions if you need reproducible security posture, and use --test for offline analysis. Live analysis sends requested securities to external market-data providers, and watchlist entries are saved locally under ~/.stock-analysis/config.json.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
requirements.txt:2
Finding

Unbounded Third-Party Dependency Versions

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:2-4
Additional Location: SKILL.md:47-51
Vulnerability Type: Unbounded dependency resolution
Risk Level: Low

Vulnerable Code

text
pandas>=1.5.0
numpy>=1.23.0
requests>=2.28.0

The installation documentation also instructs users to install dependencies without version constraints:

bash
pip install pandas numpy requests

# Optional
pip install akshare
pip install yfinance

Technical Analysis

The project specifies only minimum versions for its required packages and provides completely unconstrained installation commands for optional packages. Consequently, each installation can resolve to a different, newly published version that was not reviewed or tested by the project maintainers.

The package names are legitimate and no typosquatting, dependency confusion, custom package index, or currently malicious package was identified. Therefore, this is a supply-chain hardening weakness rather than evidence that the project intentionally installs malicious software.

If an accepted package version or one of its transitive dependencies is compromised, a subsequent installation may retrieve that compromised release automatically. Python packages can execute code during installation through build backends and can subsequently execute code when imported by scripts/stock_analysis.py.

Attack Path

  1. An attacker compromises a permitted upstream package or one of its transitive dependencies and publishes a malicious version satisfying the project's lower-bound constraint.
  2. A user follows the documented installation command or installs from requirements.txt.
  3. pip selects the latest compatible release because no exact version or integrity hash is required.
  4. Malicious code executes during package building or installation, or when the dependency is imported by the application.
  5. The payload operates with the privileges of the user or automation account ...[truncated 832 chars]
Remediation
View remediation

Remediation Suggestions

  1. Generate and commit a tested lock file containing exact versions for direct and transitive dependencies.

  2. Use integrity hashes, for example with pip-compile --generate-hashes, and deploy with:

    bash
    pip install --require-hashes -r requirements.lock
    
  3. Pin optional dependencies such as akshare and yfinance in a dedicated optional requirements or lock file rather than documenting unconstrained installation commands.

  4. Update dependencies through controlled review tooling and run automated tests before accepting new versions.

  5. Run dependency vulnerability scanning in CI using tools such as pip-audit.

  6. Install packages in an isolated virtual environment as an unprivileged user, and avoid running pip with administrative privileges.

  7. Configure trusted package indexes explicitly in controlled build environments and preserve installation logs or software bills of materials for traceability.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises and instructs use of a Python script that can read and write local files (for JSON/file output and watchlist management) and access remote data sources, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a capability/consent mismatch: an agent or user may invoke a skill with broader file and network effects than the manifest makes visible, increasing the risk of unintended data access, local file modification, or outbound requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written only in Chinese and provides no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, help text, logs, analysis summaries, and most user-visible strings are written in Chinese, and there is no option to choose output language. The presence of an ASCII replacement mode does not provide genuine language choice, since it only replaces a limited set of labels rather than offering full multilingual output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill creates and persists a config file under the user's home directory, storing watchlist and default settings beyond a single analysis session. While not inherently malicious, persistent local state introduces privacy and data-governance concerns because queried securities and preferences remain on disk without clear disclosure or consent handling.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill transmits fund codes and associated request metadata to an external Eastmoney API. In a financial-analysis context this can expose user interests or watchlist composition to third parties, making the external transmission noteworthy even though it is part of the tool's normal function.

Content

Scanner excerpt · scripts/stock_analysis.py (reported line 463)May include surrounding context.

python
return None

        try:
            url = "https://api.fund.eastmoney.com/f10/lsjz"
            params = {
                "fundCode": code,
                "pageIndex": 1,

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/stock_analysis.py (reported line 1850)May include surrounding context.

python
all_required = True
    for mod, desc, required in deps:
        try:
            __import__(mod)
            status = "OK"
            color = "OK"
        except ImportError:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script includes watchlist management features that persist user portfolio-like entries, which expands the skill's behavior beyond transient technical analysis described in the manifest. This matters because holdings/watchlists can be sensitive financial-interest data and users may not expect the skill to retain them locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

I found no natural-language policy violation in this markdown file. The documentation explicitly offers both English and Chinese, which avoids forcing a specific language without user opt-in. No other language or locale restriction is stated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file embeds Chinese and English in the core description, and the usage/examples continue to include Chinese labels throughout. Under the stated policy, forcing or assuming a specific language/locale without opt-in can be a natural-language policy concern when no language selection is offered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language comments are written only in Chinese, which indicates a fixed language choice without offering any user language or locale option. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Using a lower-bounded but unpinned dependency such as pandas>=1.5.0 makes builds non-reproducible and can silently pull in future releases with breaking changes or newly introduced vulnerabilities. In a security-sensitive or production environment, this weakens supply-chain control and makes it hard to verify whether deployed versions are safe.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
# 核心依赖(必需)
pandas>=1.5.0
numpy>=1.23.0
requests>=2.28.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
80% confidence
Finding

Because pandas is not pinned, it is impossible to determine from this manifest alone whether an affected version with known advisories could be installed. The cited advisory is disputed and older, so the immediate risk is limited, but the unverifiable dependency state still weakens assurance and auditability.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Using numpy>=1.23.0 without an exact version allows environment-dependent installations and unexpected upgrades, which increases supply-chain risk and reduces reproducibility. This is especially relevant because numerical libraries often have native components and security advisories that require precise version tracking.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
# 核心依赖(必需)
pandas>=1.5.0
numpy>=1.23.0
requests>=2.28.0

# 可选依赖

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

The manifest does not specify an exact numpy version, so a vulnerable or unsupported release could be installed depending on when and where deployment occurs. Given numpy's history of multiple advisories and its common use of compiled code, this uncertainty creates a meaningful supply-chain and patch-management risk.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

Leaving requests unpinned can cause installations to pull different versions over time, including versions affected by known HTTP/client-side security issues. Because requests commonly handles outbound network communication, lack of version pinning increases the chance of inheriting vulnerable behavior in environments that use this skill.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# 核心依赖(必需)
pandas>=1.5.0
numpy>=1.23.0
requests>=2.28.0

# 可选依赖
# akshare>=1.12.0    # A股/基金备用数据源

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Requests has multiple known advisories, and without exact pinning the installed version cannot be verified from this file. Since requests is a network-facing library, uncertainty about whether patched behavior is present can directly affect confidentiality and request-handling security in any skill functionality that fetches market data remotely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The tool sends requested symbols and request metadata to third-party providers such as Sina, yfinance, Akshare-backed sources, and Eastmoney without prominently warning users at runtime. This can leak investment interests, usage timing, IP address, and client headers to external services, which is a real privacy issue for a finance-related skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.