T08 · Insecure Dependencies
- Location
SKILL.md:22- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Execution Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a local financial backtesting skill, not malware, but its investment outputs and install instructions need caution.
Install dependencies in a dedicated virtual environment, prefer pinned requirements, and run the skill only on CSV files and output folders you choose. Treat the reports as educational backtests, not personalized investment advice, because the implementation appears to be inverse-volatility weighting rather than a full equal-risk-contribution optimizer and it may overwrite fixed output filenames.
SKILL.md:22Unpinned Third-Party Dependencies Create a Supply-Chain Execution Risk
The README’s instructional content is predominantly in Chinese, including usage guidance, data format requirements, and cautions. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation because users are not offered an alternative locale or language choice.
The manifest presents the skill name, description, features, and changelog entirely in Chinese, indicating a fixed language choice. Under the policy, a skill should not force a specific language or locale without offering user choice or clearly documenting a justified regional constraint.
This code file contains user-facing descriptions, help text, and console output entirely in Chinese, starting with the module docstring and continuing throughout the CLI interface. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.
The module docstring and user-facing behavior are presented in Chinese, and the rest of the file continues that pattern for prompts, reports, and console output. This effectively forces a specific language/locale on users without any explicit opt-in or documented regional justification.
The skill states that rebalancing occurs monthly, but the implementation computes evolving inverse-volatility weights and applies the previous day's weights on every trading day. This creates a mismatch between documented behavior and actual portfolio logic, which can mislead users about turnover, transaction costs, and backtest validity in a financial decision-making context.
The report claims each asset contributes equally to portfolio risk, but the code only uses inverse-volatility weighting, which does not generally produce equal risk contributions when correlations are non-zero. In an investment-analysis skill, this can materially misrepresent the strategy's risk properties and cause users to rely on incorrect portfolio characterization.
The guide states that each asset contributes equally to portfolio risk, which is the defining property of risk parity. However, the later formula and code snippets describe weights computed as normalized inverse volatility (L127, L266-L268), which generally produces inverse-vol portfolios rather than true equal-risk-contribution portfolios. This is an intent/documentation contradiction about the strategy being implemented.
The document gives concrete investment suggestions, performance claims, and strategy guidance without any visible disclaimer that the content is informational only, may be inaccurate, and should not be treated as personalized financial advice. In a financial-analysis skill, this omission can cause users to over-trust backtest outputs and recommendations, increasing the risk of harmful real-world financial decisions.
The skill title and most instructions are in Chinese, and the sample output is also Chinese-language, which effectively imposes a locale by default. The file does not indicate user opt-in for Chinese nor explain that the skill is limited to a Chinese-speaking or region-specific audience.
The skill explicitly integrates third-party market data providers and mentions API-key usage, but it does not disclose that user-supplied symbols, portfolio contents, and related request metadata may be transmitted to external services. In a financial-analysis context, this can expose sensitive investment interests or internal research activity to outside providers, even if the data sent is limited.
The core features and FAQ claim automatic outlier identification/handling, but the explicit processing steps only mention reading CSVs, converting percentages, and deleting rows with NaN values (L115-L120). No outlier-detection method, parameter, or code snippet is documented, so the documentation appears to overstate behavior and may mislead users about what the skill actually does.
The guide encourages generation of reports, JSON, and charts that may embed local filesystem paths, data ranges, asset identifiers, and potentially sensitive financial results, but it does not warn users about disclosure risk. In a financial-analysis context, these artifacts can be shared, synced, or committed inadvertently, exposing proprietary market data locations or confidential analytical outputs.
This markdown file documents that the skill writes multiple output artifacts, including text, JSON, and PNG files, but does not include any user-facing warning about creating or overwriting files in the output directory. For markdown files, omissions of warnings about behaviors affecting user data or system state should be flagged when such behaviors are described.
No suspicious patterns detected.