Back to skill

Security audit

短线手术刀 (ScalpelTrade)

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it has review-worthy security and integrity issues around local file writes and unauthenticated financial data retrieval.

Review before installing. The skill appears to be a legitimate local A-share analysis/tracking tool, but run it as an unprivileged user, avoid passing untrusted stock-code strings, and treat outputs cautiously because some market data is fetched over HTTP and local recommendation/audit records may persist strategy details.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/tracker.py:98
Finding

Directory Traversal Through Unvalidated Stock Code in Tracking Filename

Content
View full analysis
7 else "", source="cli" ) ``` ### Technical Analysis The stock code is embedded directly into a filename. No allowlist, regular expression, path normalization, or containment check prevents the value from containing path separators or `..` traversal components. `os.path.join(TRACKING_DIR, filename)` only combines paths; it does not guarantee that the resulting normalized path remains inside `TRACKING_DIR`. An input containing traversal sequences can therefore cause the file operation to escape the intended tracking directory. The date and generated identifier suffix prevent reliable selection of an exact final filename, but they do not prevent creation of an attacker-influenced JSON filename in another writable directory. Exploitation is limited by the operating-system privileges of the process and requires any referenced intermediate directories to exist. ### Attack Path 1. An attacker obtains the ability to invoke the local tracking CLI or otherwise call `record_recommendation()` with controlled input. 2. The attacker supplies a stock code containing traversal components, such as a value beginning with `../../`. 3. The CLI passes the value through `sys.argv[2]` ...[truncated 1084 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetcher.py:386
Finding

Decision-Critical Financial Data Retrieved Over Unauthenticated HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documentation advertises executable Python scripts that read and write local files and make outbound network requests, but the manifest does not declare any tool scope or permissions. This creates a least-privilege and transparency problem: users and platforms cannot easily determine what capabilities the skill requires, increasing the risk of unintended file access, report generation, or external data exfiltration when the skill is run.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The top-level natural-language description is entirely Chinese and presents the skill identity and operating model in that locale without any indication that other languages are supported or that the locale is intentionally region-scoped. Per the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The inline documentation at L230 states the pattern is '前一天大涨 > 3% → 今天跌但缩量(量比<1) → 仍在MA20上方'. However, the implemented condition only checks previous gain, today's decline, and lower volume ratio; there is no MA20 comparison in this block, so the comment materially overstates what the signal means.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This script is positioned as an analysis tool, but it also persists audit trails and recommendation records to local storage. That creates a real data-governance and privacy risk because analysis inputs, stock recommendations, and rationale text may be retained without consent controls, retention limits, or access restrictions, expanding the skill from transient analysis into durable logging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The audit function writes caller-supplied content to a persistent JSONL trail without an explicit warning or consent mechanism at the write point. Even though content is truncated, it may still contain sensitive prompts, proprietary analysis, or user-derived data, creating an unnecessary privacy and data-retention surface in a finance-oriented skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language descriptions entirely in Chinese, including the module docstring that defines the skill's purpose. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command-line interface prints output and usage text only in Chinese, with no indication that users can select another language. This creates a language policy issue because the skill's interactive surface enforces one locale without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file presents its primary natural-language documentation entirely in Chinese, and the rest of the file continues with Chinese-only docstrings and comments. Under the language/locale policy, forcing a specific language without user opt-in or a documented region-specific justification is a policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The code uses plain HTTP for Eastmoney requests and even sets an HTTP Referer, which allows traffic to be intercepted or modified by a network attacker. Because the returned market data influences downstream analysis and recommendations in a trading skill, tampered responses could poison signals, rankings, or decisions without obvious detection.

Content

Scanner excerpt · scripts/fetcher.py (reported line 415)May include surrounding context.

python
"""
    try:
        url = f'http://push2.eastmoney.com/api/qt/clist/get?cb=&pn=1&pz={top_n}&po=1&np=1&ut=bd1d9ddb04089700cf9c27f6f7426281&fltt=2&invt=2&fid=f62&fs=m:90+t:2&fields=f12,f14,f62,f184,f66,f69'
        headers = {'User-Agent': 'Mozilla/5.0', 'Referer': 'http://data.eastmoney.com/'}
        req = urllib.request.Request(url, headers=headers)
        resp = urllib.request.urlopen(req, timeout=10)
        d = json.loads(resp.read().decode('utf-8'))

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language interface text that forces a specific language/locale for usage instructions and user interaction. Under the policy, locale-specific behavior should either provide user choice or be clearly documented as a justified regional constraint, neither of which is present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Recommendation records, including rationale text, are written to disk before meaningful disclosure to the user. This is a smaller version of the same persistence problem: free-form rationale may embed sensitive strategy details or user-provided content, and durable storage increases exposure if the host is shared or later compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.