Back to skill

Security audit

multi-factor-strategy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for creating QuantCLI stock-strategy YAML files, with a normal but unpinned third-party install step users should treat carefully.

Before installing, verify that the QuantCLI package and repository are the ones you intend to trust, prefer a pinned reviewed version or commit, and run it in a virtual environment. Treat generated stock-screening strategies as decision-support material, not financial advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
skill.md:13
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 13-18
Vulnerability Type: Unpinned and unverified third-party dependency
Risk Level: Medium

Vulnerable Code

bash
# Install from PyPI (recommended)
pip install quantcli

# Or install from source
git clone https://gitcode.com/datavoid/quantcli.git
cd quantcli
pip install -e .

Technical Analysis

The skill directs users to install and execute a third-party package without pinning an audited package version or immutable source commit. It also provides no package hash, commit verification, signed-release validation, or dependency lockfile.

The PyPI command installs whichever package version currently satisfies the unqualified quantcli name. The source-based alternative clones the repository's mutable default branch and installs it in editable mode. In both cases, package-controlled build hooks and transitive dependencies may execute during installation, while the installed application executes later through documented quantcli commands.

This creates a supply-chain trust boundary outside the reviewed project. Compromise of the package registry release, source repository, maintainer credentials, or transitive dependency chain could replace the effective code after this skill has been audited.

Attack Path

  1. An attacker compromises the referenced package, repository, maintainer account, release process, or one of its dependencies.
  2. The attacker publishes malicious package or repository content under the expected identity.
  3. A user follows the documented pip install quantcli command or clones the mutable default repository branch.
  4. pip processes attacker-controlled packaging metadata, build hooks, or dependencies, potentially executing malicious installation code.
  5. The user subsequently invokes quantcli, causing any malicious installed runtime logic to execute again.
  6. That code operates with the permissions and environmental access of the invoking user.

...[truncated 581 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin QuantCLI to a specifically reviewed version, such as quantcli==X.Y.Z.
  2. Distribute a lockfile containing exact versions for all transitive dependencies.
  3. Require package hashes by installing from a hash-locked requirements file with pip install --require-hashes.
  4. For source installations, check out a reviewed immutable commit rather than installing the repository's default branch.
  5. Verify signed releases or commits where the upstream project supports signing.
  6. Document the expected repository identity, package publisher, version, commit hash, and artifact checksum.
  7. Perform installation inside a dedicated virtual environment or similarly isolated environment.
  8. Avoid privileged installation and run QuantCLI with only the filesystem and network permissions required for its stated function.
  9. Re-audit the pinned package and dependency set before updating any version or commit.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown skill is primarily written in English, but the heading on L156 includes Chinese text ("定位") with no user opt-in or explanation of a locale requirement. That creates a natural-language locale inconsistency that may violate language policy for users expecting a single language unless the skill explicitly offers a choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.