Back to skill

Security audit

实时财经数据

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward live finance quote helper, but users should know it sends ticker queries to third-party finance services and uses an unencrypted Sina Finance endpoint.

Install this only if you are comfortable with finance symbols you request being sent to Sina Finance or Yahoo Finance. Treat displayed prices as informational, especially for Sina-backed data because it is fetched over unencrypted HTTP, and install `yfinance` from a trusted source in a virtual environment rather than globally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:60
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:60-63; additional occurrences at realtime_finance.py:15-21 and realtime_finance.py:347-353
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:60-63:

markdown
## 依赖

- Python 3
- yfinance: `pip3 install yfinance`

realtime_finance.py:15-21:

python
try:
    import yfinance as yf
    YFINANCE_AVAILABLE = True
except ImportError:
    YFINANCE_AVAILABLE = False
    print("⚠️  yfinance 未安装,美股数据将不可用")
    print("安装命令: pip3 install yfinance")

realtime_finance.py:347-353:

python
if yahoo_codes:
    if not YFINANCE_AVAILABLE:
        print("\n⚠️  yfinance 未安装,无法获取美股数据")
        print("安装命令: pip3 install yfinance")
        return

Technical Analysis

The project directs users to install yfinance without specifying a reviewed version or verifying package integrity. The command resolves whichever release is currently provided by the configured Python package index.

Python packages can execute installation or build-related code during installation. Consequently, compromise of the package distribution channel, a malicious package-index configuration, or an unsafe future release could result in code execution. The application itself does not automatically run the installation command; exploitation requires a user or administrator to follow the displayed instruction.

Attack Path

  1. The user invokes a Yahoo-backed query without yfinance installed.
  2. The application displays pip3 install yfinance, or the user follows the same instruction in SKILL.md.
  3. The package manager resolves the dependency from the environment's configured index without a version pin or hash verification.
  4. A compromised index or package release supplies attacker-controlled package content.
  5. Installation or subsequent import executes that content with the privilege ...[truncated 518 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin yfinance and all transitive dependencies to reviewed versions in a lock file.
  • Use hashes for downloaded distributions, such as a requirements file consumed with python3 -m pip install --require-hashes -r requirements.txt.
  • Prefer an isolated virtual environment rather than installing into the system interpreter.
  • Document and enforce a trusted HTTPS package index.
  • Integrate dependency vulnerability and provenance scanning into release workflows.
  • Replace both runtime installation messages with the secured, locked installation procedure.
  • Periodically review and deliberately update the pinned dependency set rather than resolving the latest version at installation time.

T09 · Insecure Skill Coding Practices

Warning
Location
realtime_finance.py:216
Finding

Sina Finance Data Retrieved Over Unencrypted HTTP

Content
View full analysis

Vulnerability Details

File Location: realtime_finance.py:216-234
Vulnerability Type: Unauthenticated plaintext network communication
Risk Level: Medium

Vulnerable Code

python
def fetch_sina_data(codes):
    """从新浪财经获取数据"""
    if isinstance(codes, str):
        codes = [codes]
    
    url = f"http://hq.sinajs.cn/list={','.join(codes)}"
    
    try:
        req = urllib.request.Request(
            url,
            headers={
                'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36',
                'Referer': 'https://finance.sina.com.cn'
            }
        )
        
        with urllib.request.urlopen(req, timeout=10) as response:
            data = response.read().decode('gb2312', errors='ignore')
            return parse_sina_response(data)
    except Exception as e:
        return {"error": str(e)}

Technical Analysis

The Sina Finance request uses an http:// URL. Although the Referer header contains an HTTPS address, that header does not encrypt or authenticate the actual HTTP request.

A network-positioned attacker can observe requested instrument codes and modify the response in transit. The application parses the unauthenticated response using parse_sina_response and presents the resulting prices and changes as financial data. The timeout only limits request duration and provides no confidentiality or integrity protection.

The set of outgoing Sina symbols is constrained by normalize_code, so this issue is not an arbitrary server-side request forgery vulnerability. The primary risks are traffic disclosure and response manipulation.

Attack Path

  1. A user requests an A-share or Hong Kong instrument handled by the Sina data source.
  2. The application sends the instrument codes to hq.sinajs.cn over plaintext HTTP.
  3. An attacker controlling or observing the local network, gateway, DNS path, or another ...[truncated 773 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the plaintext endpoint with a supported HTTPS market-data endpoint.
  • Retain normal TLS certificate and hostname verification; do not disable verification to accommodate an incompatible endpoint.
  • If Sina does not provide an authenticated HTTPS interface for this API, migrate to a provider that does.
  • Fail closed when secure transport cannot be established rather than falling back to HTTP.
  • Consider validating response structure, expected symbol identity, numeric ranges, and timestamps to reduce the effect of malformed or stale upstream data.
  • Clearly identify the source and retrieval time in displayed results, especially when financial data may inform user decisions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a Python script that fetches data from Sina Finance and Yahoo Finance, which implies outbound network access, but the manifest does not declare any tool scope or permissions. This creates a least-privilege and transparency problem: the host may auto-run a network-capable skill without users or policy engines being able to clearly audit or constrain that capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description, trigger phrases, and usage examples are entirely in Chinese, which implies a fixed language/locale expectation. There is no indication that users may interact in another language or that the Chinese-only behavior is an intentional, documented regional constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad terms like '实时', '指数', '涨跌', '黄金', '原油', 'A股', '美股', and '港股', which are common in ordinary finance discussions. Overbroad activation can cause the skill to run unexpectedly, leading to unprompted network access, incorrect tool routing, or disclosure of user queries to external data providers when the user did not clearly request this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language strings, prompts, and supported examples throughout the file are Chinese-only, which effectively forces a specific language/locale for use. The file does not offer an opt-in language choice or document a justified region-specific restriction, so this is a language policy issue under the stated rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends user-supplied ticker queries to Sina Finance over HTTP and also queries Yahoo Finance elsewhere in the file, but there is no confirmation prompt, warning comment, or user-facing notice that input will be transmitted to third-party services. Because the skill processes user requests by contacting external providers, a minimal disclosure would help users understand the privacy and network behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.