T08 · Insecure Dependencies
- Location
scripts/sentiment_tools.py:48- Finding
Automatic Retrieval of Unpinned Model Artifacts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a finance search/RAG tool, but it also performs under-disclosed external enrichment, sentiment analysis, model downloads, LLM-provider use, and local database writes.
Review this skill carefully before installing. It is not just a search helper: default structured search may contact Jina Reader, cache retrieved page content locally, score sentiment, load external model artifacts, and use configured LLM providers. Install only if those third-party services, environment credentials, local database writes, and model-download behavior are acceptable for your finance data and queries.
scripts/sentiment_tools.py:48Automatic Retrieval of Unpinned Model Artifacts
scripts/search_tools.py:262Default Enrichment Discloses URLs and Content to Additional External Services
Sentiment analysis with downloaded transformer models and external LLM calls, plus writing sentiment back to a news database, is substantially broader than the declared search/RAG scope. This increases supply-chain, data-egress, and integrity risks because the skill may download code/models, send data externally, and modify local datasets without clear disclosure.
Sentiment analysis with downloaded transformer models and external LLM calls, plus writing sentiment back to a news database, is substantially broader than the declared search/RAG scope. This increases supply-chain, data-egress, and integrity risks because the skill may download code/models, send data externally, and modify local datasets without clear disclosure.
Sentiment analysis with downloaded transformer models and external LLM calls, plus writing sentiment back to a news database, is substantially broader than the declared search/RAG scope. This increases supply-chain, data-egress, and integrity risks because the skill may download code/models, send data externally, and modify local datasets without clear disclosure.
Sentiment analysis with downloaded transformer models and external LLM calls, plus writing sentiment back to a news database, is substantially broader than the declared search/RAG scope. This increases supply-chain, data-egress, and integrity risks because the skill may download code/models, send data externally, and modify local datasets without clear disclosure.
Sentiment analysis with downloaded transformer models and external LLM calls, plus writing sentiment back to a news database, is substantially broader than the declared search/RAG scope. This increases supply-chain, data-egress, and integrity risks because the skill may download code/models, send data externally, and modify local datasets without clear disclosure.
Sentiment analysis with downloaded transformer models and external LLM calls, plus writing sentiment back to a news database, is substantially broader than the declared search/RAG scope. This increases supply-chain, data-egress, and integrity risks because the skill may download code/models, send data externally, and modify local datasets without clear disclosure.
Sentiment analysis with downloaded transformer models and external LLM calls, plus writing sentiment back to a news database, is substantially broader than the declared search/RAG scope. This increases supply-chain, data-egress, and integrity risks because the skill may download code/models, send data externally, and modify local datasets without clear disclosure.
The file implements sentiment analysis and bulk database updates, which materially exceed the stated finance search/RAG behavior of the skill. This kind of hidden or undeclared capability increases attack surface, can surprise operators, and may enable unintended processing or modification of local data beyond user expectations.
The skill declares capabilities that imply network and environment access but does not define an explicit tool/permission scope. This creates ambiguity about what the skill is allowed to do and increases the risk of over-broad execution, unexpected external requests, or access to secrets through environment variables.
Broad invocation language like 'use when the user needs general finance info' lacks clear boundaries and exclusions, making accidental or overly frequent activation more likely. In combination with networked and possibly broader-than-declared behavior, vague triggers can cause the skill to run in contexts where sensitive data or unnecessary external access is involved.
Multiple docstrings and inline descriptions are exclusively in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.
This code performs a safety-relevant model load and text encoding step via SentenceTransformer, which may download models or transmit text depending on backend configuration, but there is no confirmation prompt, user-visible disclosure, or explanatory comment about that behavior. The logging present is developer-oriented and does not clearly warn users that their query/document text may be processed by an external model stack.
The manifest includes local finance retrieval, and this method specifically claims to load recent N days of history. However, the SQL query does not filter by date at all, so behavior does not match the described time-bounded retrieval semantics.
This is a direct contradiction between inline documentation and code behavior. The method documentation promises time-scoped history loading, while the implementation retrieves rows solely by descending publish_time and LIMIT.
The manifest describes a skill for finance web searches and local document retrieval, but this file implements generic LLM tool-calling capability detection and model registry caching. Probing whether an LLM supports native function calling is not an obvious requirement of finance search or local context retrieval, making this capability unjustified by the stated skill purpose.
The docstrings, tool description, and agent instruction are written only in Chinese, and the runtime test prompt also assumes Chinese input/output. This imposes a specific language/locale on use of the skill without any opt-in or documented justification, which matches the language-policy violation criteria.
The manifest describes a skill for finance web searches and local document retrieval, but this module provisions connections to several third-party LLM providers by reading credentials from environment variables and configuring remote inference endpoints. Model-provider orchestration is not an obvious or declared capability required for search/RAG itself, especially across unrelated vendors like DeepSeek, DashScope, OpenRouter, ZAI, and UST.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
return OpenAIChat(
id=model_id,
base_url="https://api.z.ai/api/paas/v4",
api_key=api_key,
timeout=60,
role_map=role_map,
The code sends user queries to external search providers and later sends result URLs to a content extraction service, but this file provides no explicit user warning, consent check, or data minimization control. For finance-related queries, this can leak sensitive research interests, company investigations, or proprietary local context to third parties.
The search tool goes beyond simple retrieval by fetching full page content and performing sentiment analysis on it, which is not disclosed by the stated skill purpose of web/local search and retrieval. This expands data processing scope, increases external data exposure, and can surprise users or operators who expect only search behavior.
Importing and invoking a separate sentiment-analysis capability introduces an additional processing function unrelated to the declared search scope. In a finance context, this can materially influence outputs while silently processing retrieved content in ways users did not request or authorize.
Core descriptive text, prompts, and user-facing documentation in this file are written only in Chinese, with no indication that users can choose another language. This can violate language/locale policy when a skill imposes one language by default rather than offering choice or documenting a justified locale restriction.
The manifest describes a skill for finance web searches and local document-store retrieval, but this file implements sentiment analysis and also inspects UST_KEY_API from the environment to decide which remote model provider to use. Reading environment-based credentials/provider secrets is not an obvious requirement of search or local RAG retrieval and represents an extra capability outside the stated purpose.
The code will automatically download a model from the network when it is not present locally. In a skill advertised only for finance search/RAG, undeclared outbound network access and execution of externally sourced model artifacts expand supply-chain and data-governance risk.
The LLM path sends analyzed text to an external model provider without any disclosure, consent flow, or warning in the method contract. If the input contains proprietary, personal, or regulated finance data, this can cause unintended data exfiltration to third-party services.
No suspicious patterns detected.