Back to skill

Security audit

股票技术分析 (Stock Technical Analysis)

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent stock-analysis skill that fetches public market data and computes indicators, with ordinary dependency hygiene risks but no hidden or destructive behavior.

Install it in an isolated Python environment and consider pinning or locking dependencies before use. Treat the generated buy/hold/watch-style analysis as informational only, since the skill itself also states it is not investment advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unhashed Third-Party Dependencies

Content
View full analysis
=2.28.0 pandas>=1.5.0 numpy>=1.21.0 ``` The documented installation command in `README.md`, lines 13-15, consumes these dependency specifications directly: ```bash pip install -r requirements.txt ``` ### Technical Analysis The dependency declarations specify only minimum versions. Consequently, package installation may select any future release satisfying each constraint. No lock file, exact version pin, package hash, or trusted artifact policy is provided. This makes builds non-reproducible and allows dependency code that was not included in this audit to enter the execution environment. Python packages may execute code during installation or when imported. Therefore, compromise of an eligible future release, the configured package index, or the dependency-resolution channel could result in attacker-controlled code being installed. The package names shown are legitimate, and the project does not specify a malicious package repository. This finding represents a supply-chain exposure rather than evidence that the current dependencies or project authors are malicious. ### Attack Path 1. An attacker compromises the publication process or account for a listed dependency, compromises the package-index resolution path, or otherwise causes a malicious future version to be served under a listed package name. 2. The malicious version remains numerically compatible with the lower-bound requirement. 3. A user follows the documented installation procedure and runs: ```bash pip install -r requirements.txt ``` 4. Pip resolves and installs the attacker-controlled release because no exact version or expected artifact hash is enforced. 5. Malicious package code executes during installation or later when the application imports th ...[truncated 939 chars]
Remediation
View remediation
pandas== numpy== ``` 2. Generate a fully resolved lock file that includes transitive dependencies. 3. Record cryptographic hashes for every approved distribution and install with hash enforcement: ```bash pip install --require-hashes -r requirements.txt ``` 4. Permit installation only from explicitly trusted package indexes, preferably through an internally controlled package mirror. 5. Perform dependency updates through a reviewed process that includes vulnerability scanning, compatibility testing, provenance checks, and lock-file regeneration. 6. Install and run the project in an isolated virtual environment or container under a non-privileged account. 7. In CI/CD, reject dependency files containing unpinned packages or missing hashes. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is presented in Chinese ('股票技术分析工具 - 基于东方财富数据') with no indication that users may choose another language or that the locale restriction is intentional. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code uses Chinese-only natural-language descriptions and user-facing output strings throughout the file, beginning with the module docstring. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a lower bound only, which allows future installs to resolve to different versions over time. This weakens supply-chain reproducibility and makes it harder to ensure vulnerable or breaking releases are excluded.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0
pandas>=1.5.0
numpy>=1.21.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

Requests has multiple known advisories, and because the manifest does not pin a specific version, there is no way to verify whether deployed environments avoid affected releases. In a package that performs network communication, unresolved version drift can materially increase exposure to credential leakage, TLS/verification issues, or other client-side flaws.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is unpinned, so installation may pull different pandas releases depending on time and environment. That creates avoidable supply-chain risk and prevents reliable verification that only tested, non-vulnerable versions are used.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.28.0
pandas>=1.5.0
numpy>=1.21.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
73% confidence
Finding

Pandas has at least one advisory in its history, and the lack of version pinning makes it impossible to confirm whether the installed version is affected. The practical risk is lower here because the cited issue is disputed and exploitation often depends on unsafe deserialization patterns elsewhere in the code.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Using a minimum-version specifier for numpy permits uncontrolled upgrades to later releases. This reduces build determinism and can expose deployments to newly introduced vulnerabilities or incompatible behavior.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests>=2.28.0
pandas>=1.5.0
numpy>=1.21.0

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
82% confidence
Finding

Numpy has multiple historical advisories, and the unpinned requirement prevents determining whether an installation will resolve to a safe release. While many numpy issues are context-dependent, unpredictable version selection still creates unnecessary supply-chain and runtime risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.