Back to skill

Security audit

finstep-tools

Security checks for vulnerabilities and agentic risk

Overview

This finance data skill is not clearly malicious, but it needs Review because it sends an API signature and user queries over plaintext HTTP and includes underdocumented general web/URL fetching features.

Install only if you are comfortable sending your financial queries and FINSTEP API signature to the FinStep service, and avoid using a valuable or long-lived signature until the publisher switches to HTTPS, removes query-string credentials, stops instructing users to echo the secret, documents or restricts generic web/URL features, and safely serializes inputs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common.sh:5
Finding

API Signature Transmitted over Plaintext HTTP and Exposed in the Request URL

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi ``` 6. Redact signatures from debug output, telemetry, error reports, and agent tool transcripts. 7. Rotate any signature that has already been used through these HTTP endpoints, because prior interception or logging cannot be ruled out. 8. Consider short-lived, narrowly scoped credentials and server-side rate limits to reduce the impact of credential replay. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/quote.sh:11
Finding

Unescaped User Input Permits JSON-RPC Argument Injection

Content
View full analysis
Remediation
View remediation
&2 exit 2 } (( NUM >= 1 && NUM <= 100 )) || { printf '%s\n' "NUM must be between 1 and 100" >&2 exit 2 } ``` 4. Apply explicit allowlists to enumerations such as market, K-line type, reinstatement type, holder type, and sector type. 5. Validate date arguments with a strict `YYYY-MM-DD` format and, where possible, perform semantic date validation. 6. Reject missing required parameters instead of silently sending empty strings. 7. Add regression tests containing quotes, backslashes, newlines, braces, Unicode, and JSON-looking input. Verify that each remains a single serialized string value. 8. Configure the MCP backend to reject unknown properties, duplicate keys, incorrect types, and out-of-range values. Server-side validation should supplement rather than replace safe client serialization. ]]>

other

Warning
Location
scripts/common.sh:38
Finding

Undocumented Arbitrary URL Parsing Exposes a Server-Side Request Forgery Surface

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述强调这是一个面向股票行情、板块涨跌、公司财务、宏观数据、研报公告等场景的综合金融数据服务。但代码仅根据参数调用 4 个工具:get_current_time、get_trade_info、get_trade_date 和 url_parse。前 3 项仅覆盖时间与交易日历信息,范围远窄于声明;而 url_parse 还能解析任意网页内容,这是声明中未提及的通用网页处理能力。由此看,代码实际行为与技能描述的核心用途存在明显偏差,属于实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

描述将技能表述为覆盖面很广的综合金融数据服务,但此代码块的实际功能范围明显更窄,集中在公司信息与公司财务相关数据查询。虽然描述中的“公司信息、公司财务”等部分与代码一致,但“实时行情、板块数据、宏观经济、研报新闻”等关键宣称在该代码中没有对应实现。若该技能描述是针对该代码块本身,则存在能力范围被显著夸大的不匹配。代码访问的资源也是 company_info 接口,进一步说明其主要目的偏向公司数据而非全量金融资讯。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是“全方位金融数据服务”,覆盖股票行情、板块、公司、宏观、研报新闻等广泛场景;但该代码块仅实现宏观数据相关功能,且访问的资源也是 /macro 接口,只支持若干宏观指标查询。虽然声明中包含“宏观经济”这一部分,与代码有重合,但代码的主要用途明显比声明窄得多,无法支撑其实时行情、板块、公司财务、研报公告等触发场景。因此描述对该代码实际能力有明显夸大,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是覆盖行情、板块、公司、宏观、研报新闻等“全方位金融数据”服务,但该代码块仅实现了面向资讯内容的搜索与获取:news、report、announcement、morning、opinion、weixin、community、web。它没有显示任何股票实时行情、板块涨跌、公司财务、宏观数据等核心金融数据查询逻辑,因此与声明的主要能力范围不一致。虽然研报、新闻、公告部分与声明部分重合,但整体上代码更像资讯检索服务,而不是综合金融数据服务;同时还包含微信公众号、社区、网页搜索等声明中未明确提及的能力,因此应判定为描述与实际行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README tells users to export FINSTEP_SIGNATURE but does not explicitly warn that this value is a sensitive credential that must be protected and never committed, logged, or shared. In an agent-skill context, users may paste setup commands into shells, CI, notebooks, or chat logs, increasing the chance of accidental credential disclosure and unauthorized API use.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to execute multiple shell scripts, but the manifest does not declare an explicit tool scope such as permissions or allowed-tools. That increases the chance of unintended shell access or broader-than-expected command execution, especially because the skill also handles user-supplied parameters and a credential-like API signature.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to request a user-provided API signature and export it into the environment before making requests to a remote HTTP service. Without an explicit warning about credential sensitivity, transport security, storage/echo risks, and destination trust, users may disclose secrets that can be intercepted, logged, or reused.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/common.sh (reported line 14)May include surrounding context.

sh
local tool="$1"
    local params="$2"
    
    curl -s -X POST "${BASE_URL}?signature=${SIGNATURE}" \
        -H "Content-Type: application/json" \
        -H "Accept: application/json, text/event-stream" \
        --max-time 30 \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search.sh (reported line 16)May include surrounding context.

sh
local tool="$1"
    local params="$2"
    
    curl -s -X POST "${BASE_URL}?signature=${SIGNATURE}" \
        -H "Content-Type: application/json" \
        -H "Accept: application/json, text/event-stream" \
        --max-time 30 \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends a credential-like signature in the URL query string on every request without any user disclosure. Query-string secrets are more likely to be exposed through logs, proxies, monitoring systems, browser/history artifacts, or downstream error reporting than headers or request bodies.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill exposes an arbitrary URL parsing capability that is broader than the stated finance-data purpose and forwards attacker-controlled URLs to an external backend. This can enable misuse such as fetching untrusted or sensitive internal resources through the MCP service, and it expands the data-exfiltration and SSRF attack surface without clear business justification in the manifest.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The script sends data to an external endpoint over plain HTTP, including an authentication signature in the query string and user-controlled request content in the POST body. Because the transport is not encrypted, a network attacker could intercept or modify requests and responses, and the query-string credential is especially likely to leak through intermediary logs.

Content

Scanner excerpt · scripts/company.sh (reported line 15)May include surrounding context.

sh
local tool="$1"
    local params="$2"
    
    curl -s -X POST "${BASE_URL}?signature=${SIGNATURE}" \
        -H "Content-Type: application/json" \
        -H "Accept: application/json, text/event-stream" \
        --max-time 30 \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script transmits user-supplied company query data and the FINSTEP signature to a remote service without any built-in user notice, consent, or minimization. In this skill context, external transmission is expected for a financial data MCP client, but placing the signature in the URL query string increases exposure because URLs are commonly logged by proxies, servers, shells, and monitoring systems.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script performs an external POST request to fintool-mcp.finstep.cn and includes an authentication signature in the request URL. In this financial-data skill, remote access is expected, but it still creates a real data-exfiltration and credential-exposure surface because query-string secrets are commonly captured by logs, monitoring systems, and intermediaries.

Content

Scanner excerpt · scripts/macro.sh (reported line 14)May include surrounding context.

sh
local tool="$1"
    local params="$2"
    
    curl -s -X POST "${BASE_URL}?signature=${SIGNATURE}" \
        -H "Content-Type: application/json" \
        -H "Accept: application/json, text/event-stream" \
        --max-time 30 \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically sends a credential-bearing request to a remote service using the FINSTEP_SIGNATURE token without any user-facing notice, consent, or logging. In an agent-skill context, this is risky because invoking the skill can silently disclose that a secret exists and transmit authenticated requests off-host to an external domain.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This script transmits data and credentials to an external service via curl, and the transmission uses plain HTTP with the signature embedded in the URL. External transmission is expected for this skill's function, but the insecure transport and credential placement make the behavior dangerous because requests may be observed or logged outside the user's control.

Content

Scanner excerpt · scripts/plates.sh (reported line 15)May include surrounding context.

sh
local tool="$1"
    local params="$2"
    
    curl -s -X POST "${BASE_URL}?signature=${SIGNATURE}" \
        -H "Content-Type: application/json" \
        -H "Accept: application/json, text/event-stream" \
        --max-time 30 \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the FINSTEP_SIGNATURE credential as a URL query parameter over plain HTTP. Query parameters are commonly logged by proxies, servers, shell history wrappers, and monitoring systems, and using HTTP instead of HTTPS exposes the credential to interception in transit. In this skill context, the script is specifically designed to access a financial data service, so credential leakage could allow unauthorized API use or service abuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The script sends user-supplied financial queries and an authentication signature to an external host using curl, and the destination is plain HTTP rather than HTTPS. In the context of a financial-data skill, this increases sensitivity because requests may reveal user interests or workflows, while the credential can be intercepted or logged and then abused for unauthorized API access.

Content

Scanner excerpt · scripts/quote.sh (reported line 15)May include surrounding context.

sh
local tool="$1"
    local params="$2"
    
    curl -s -X POST "${BASE_URL}?signature=${SIGNATURE}" \
        -H "Content-Type: application/json" \
        -H "Accept: application/json, text/event-stream" \
        --max-time 30 \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script transmits the FINSTEP_SIGNATURE to a remote service on every request without any user disclosure, confirmation, or minimization controls. More importantly, it places the secret in the URL query string over plain HTTP, which increases exposure through logs, intermediaries, shell history, and network interception.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The request transmits an authentication signature to a remote service without any disclosure or consent mechanism, and it places the credential in the URL query string. Query-string secrets are more likely to be captured in logs, proxies, monitoring systems, or error traces, increasing credential leakage risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script exposes a web_search operation even though the skill is described as a finance-data service focused on stock, company, macro, and report information. This expands the skill beyond its declared scope and can enable broader external content retrieval than users or integrators expect, increasing data exfiltration and policy-bypass risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content and command descriptions are presented only in Chinese, which can amount to a language/locale policy violation when no user opt-in or alternative language is offered. The README does not indicate that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is entirely in Chinese and frames triggers and usage around Chinese-language financial queries, with no indication that other languages are supported or that the China-focused locale is an intentional limitation. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script requires access to a sensitive environment variable, FINSTEP_SIGNATURE, but provides no explicit disclosure to the user that a secret will be consumed for authenticated remote access. While reading an environment variable is common, doing so in a reusable agent skill without clear notice can lead to unintentional secret use and surprise external access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script's user-facing comments, usage text, and error message are all written only in Chinese, which imposes a specific language on users without opt-in or justification. Under the policy, locale-specific behavior should either offer a language choice or clearly document why the constraint exists.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.