Back to skill

Security audit

A-Share Stock Data API

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it silently uses an undocumented embedded API token and sends tokens in URL parameters.

Review before installing. The core stock-query behavior is coherent, but do not rely on the bundled default token, and avoid passing private API keys on the command line or in URL parameters. Prefer a user-supplied key stored outside the skill and sent via an authorization header if the API supports it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/astock_api.py:8
Finding

Hardcoded Undocumented API Token Transmitted in URL Query Parameters

Content
View full analysis
3 else DEFAULT_TOKEN result = call_api(endpoint, code, token) ``` The implementation's `admin_mllx_2026` default differs from the documented trial token, `trial_free_2026`, in `SKILL.md:42-50`. ### Technical Analysis The script embeds an undocumented API credential directly in source code and uses it automatically. Anyone who can obtain the Skill package can recover and reuse the credential. Its name suggests that it might have administrative or otherwise elevated scope, although its actual server-side privileges cannot be verified through static analysis. The token—whether the embedded default or a private token supplied by the user—is interpolated into the URL query string. Query strings are frequently retained in web-server access logs, reverse-proxy logs, monitoring systems, diagnostics, and command histories. TLS protects the URL while it is in transit but does not prevent the client, destination server, or authorized intermediaries from recording it. Authentication to the declared stock-data API is necessary for the Skill's functionality, so the outbound reques ...[truncated 1495 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior does not fully match the actual advertised capabilities: it includes a shared embedded trial token, broader endpoint scope than the stated purpose, and claims structured output while examples/documentation are looser. This mismatch can mislead operators, cause unintended data access, and normalize use of embedded credentials that may be copied into logs, prompts, or downstream systems.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents clear outbound network usage but does not declare any tool scope or permission boundary for that capability. Missing explicit network permissions weakens reviewability and least-privilege controls, making it easier for an agent or host environment to invoke external services without clear policy constraints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description limits the skill to A-share real-time quotes, technical indicators, fund flow, and financial data for arbitrary A-share codes. However, the same skill documentation exposes endpoints for Hong Kong company data, ETF prices, and macroeconomic indicators, which are materially broader than the stated A-share-only scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill publicly embeds and encourages use of a shared trial token, which promotes insecure credential practices and increases the chance of token leakage through prompts, logs, source control, and client telemetry. Even if the token is low-privilege, shared credentials reduce accountability, enable abuse, and can train users or agents to pass secrets in URL parameters where they are more likely to be exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script embeds a default API token in source code and automatically uses it for outbound requests, which exposes a credential to anyone who can read or reuse the skill. In a distributed skill context, this can enable unauthorized third-party use of the backend service, quota exhaustion, billing abuse, or reliance on a shared secret that cannot be rotated safely once published.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation frames the skill as 'A股数据查询 (A-Share Stock API)' and describes querying A-share market, technical, fund flow, and financial data. Yet later sections document endpoints for Hong Kong company information, ETF prices, and macroeconomic data, which contradict that narrower characterization rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-facing docstrings, help text, and formatted output are written only in Chinese, which imposes a specific language on users without opt-in. The file does not state that the skill is region-specific or otherwise justify the locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.