Back to skill

Security audit

Smc Trading Signal

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a local trading-signal tool, but it overstates what it implements and can generate financial signals from unverified or simulated market data.

Review before installing or scheduling this skill. It does not appear to steal data or place trades, but do not rely on its signals as production financial advice: it may analyze only gold despite broader claims, uses simplified logic, accepts an unverified data feed, and can fall back to random mock data when feeds fail.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/monitor_v2.py:45
Finding

TLS Certificate Verification Disabled for Financial Market Data

Content
View full analysis

Vulnerability Details

File Location: scripts/monitor_v2.py, line 45
Vulnerability Type: Improper TLS certificate validation
Risk Level: High

python
response = requests.get(url, headers=headers, timeout=10, verify=False)

Technical Analysis

The Sina market-data request explicitly sets verify=False, disabling validation of the server's TLS certificate. Although the connection uses HTTPS, the client does not verify that it is communicating with the legitimate Sina endpoint.

An attacker capable of intercepting or redirecting network traffic can consequently present an arbitrary certificate and return forged market data. Values parsed from this response directly influence trend classification, signal detection, entry prices, stop-loss values, and take-profit targets.

Attack Path

  1. The skill runs on a network controlled or observable by an attacker, or the attacker compromises DNS, a proxy, or another network intermediary.
  2. The attacker intercepts the request to https://hq.sinajs.cn/list=hf_GC.
  3. Because certificate verification is disabled, the attacker presents an untrusted certificate without causing the request to fail.
  4. The attacker returns a syntactically valid response containing manipulated price, high, low, and previous-close values.
  5. The application accepts and parses the forged response.
  6. The manipulated values produce an attacker-influenced trend, trade direction, entry price, stop loss, and take-profit targets.
  7. The resulting signal is displayed or saved and may be acted upon by a user.

Impact Assessment

The vulnerability compromises the integrity and authenticity of the Sina financial data feed. An attacker can influence trading recommendations generated from that feed, potentially causing financial loss if a user relies on the resulting signal.

This issue does not, by itself, grant local code execution, filesystem access beyond the application's normal ou ...[truncated 155 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove verify=False and use Requests' default certificate verification:
    python
    response = requests.get(url, headers=headers, timeout=10)
    
  • Do not suppress or bypass certificate-validation failures.
  • Ensure the runtime uses a maintained CA trust store, such as the current certifi bundle.
  • If stronger endpoint authentication is required, implement carefully maintained certificate or public-key pinning with a documented rotation process.
  • Validate the response structure and enforce plausible bounds and relationships for all financial values before generating signals.
  • Log TLS failures as production data-source errors and fail closed rather than treating unverified data as trustworthy.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/monitor_v2.py:149
Finding

Production Data-Feed Failures Silently Fall Back to Random Trading Data

Content
View full analysis

Vulnerability Details

File Location: scripts/monitor_v2.py, lines 149–166
Vulnerability Type: Unsafe fail-open behavior and untrusted synthetic-data handling
Risk Level: High

python
def get_gold_price(symbol_source="sina"):
    """获取黄金价格(多源切换)"""
    # 尝试新浪财经
    if symbol_source != "mock":
        price = get_gold_price_sina()
        if price:
            return price
        
        # 新浪财经失败,尝试雅虎财经
        price = get_gold_price_yahoo()
        if price:
            return price
    
    # 都失败,使用模拟数据
    print("  ⚠️ 使用模拟数据(测试模式)")
    return get_gold_price_mock()

The synthetic data returned by this path is randomly generated:

python
def get_gold_price_mock():
    """模拟黄金价格(测试/备用)"""
    import random
    base_price = 2156.80
    change = random.uniform(-20, 20)
    return {
        "price": base_price + change,
        "change": change,
        "change_pct": change / base_price * 100,
        "high": base_price + random.uniform(10, 30),
        "low": base_price - random.uniform(10, 30),
        "open": base_price + random.uniform(-5, 5),
        "prev_close": base_price,
        "volume": random.uniform(10000, 50000),
        "time": datetime.now().strftime('%Y-%m-%d %H:%M:%S'),
        "source": "模拟数据"
    }

Technical Analysis

The production data-retrieval function automatically returns randomized mock prices whenever both external feeds fail. The caller treats the returned dictionary as valid market data and does not reject records whose source is synthetic.

As a result, network outages, response-format changes, certificate failures, endpoint blocking, or deliberate feed disruption can cause the program to generate apparently actionable trade plans from invented prices. The fallback is not restricted to an explicit test mode and does not require deliberate operator confirmation.

Because signal detection uses percentage moveme ...[truncated 1588 chars]

Remediation
View remediation

Remediation Suggestions

  • Fail closed when all production feeds fail by returning None, raising a dedicated exception, and exiting with a nonzero status.
  • Permit mock data only through an explicit test-only option, such as --mock, that is disabled by default.
  • Propagate data provenance through the processing pipeline and enforce a policy that synthetic data cannot produce persisted or notified trading signals.
  • Display an unmistakable test banner on every mock-mode output.
  • Separate production and test entry points to prevent accidental activation of synthetic data in scheduled monitoring.
  • Add freshness checks, schema validation, numeric type checks, null handling, and plausible market-value bounds before analyzing any response.
  • Record feed failures in structured logs and alert operators instead of silently continuing.
  • Add automated tests verifying that simultaneous provider failure never results in a production signal.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A second independent mismatch report reinforces that the skill's published purpose does not match likely runtime behavior, particularly around unsupported assets, simplified non-SMC logic, and undisclosed persistence to the output directory. In security terms, description-behavior mismatch undermines informed consent and can conceal risky actions that would otherwise be reviewed or restricted.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A second independent mismatch report reinforces that the skill's published purpose does not match likely runtime behavior, particularly around unsupported assets, simplified non-SMC logic, and undisclosed persistence to the output directory. In security terms, description-behavior mismatch undermines informed consent and can conceal risky actions that would otherwise be reviewed or restricted.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This wrapper silently executes a second file's contents without transparent user notice at the point of execution, which is dangerous because it hides arbitrary code execution behind a version-redirection mechanism. In a skill context, this makes code review and trust decisions harder, since the actual runtime behavior may reside in another file and can be swapped independently.

Content

No source excerpt is available for this finding.

exec() call detected

High
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

The script reads and executes the contents of monitor_v2.py with exec(), which grants full code execution to whatever is in that file. If monitor_v2.py is modified, replaced, or sourced from an untrusted repository state, running this wrapper executes arbitrary Python in the current process with the user's privileges.

Content

Scanner excerpt · scripts/monitor.py (reported line 17)May include surrounding context.

python
v2_script = Path(__file__).parent / "monitor_v2.py"
if v2_script.exists():
    with open(v2_script, "r", encoding="utf-8") as f:
        exec(f.read())
else:
    print("错误:monitor_v2.py 不存在")
    sys.exit(1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

整个技能说明从标题到操作指引均仅以中文呈现,没有说明语言限制的适用范围,也没有提供其他语言选项或用户可选择语言的机制。按照规则,未经用户选择而强制特定语言属于自然语言层面的语言/地区策略问题。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares required binaries but does not declare an explicit tool/permission scope even though the described workflow implies local file access, scheduled execution, and external data retrieval. In an agent ecosystem, missing scope boundaries increases the chance of over-broad execution or undisclosed capabilities being granted without user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description and the entire skill documentation are written in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This creates a natural-language locale constraint without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's docstring, status messages, and generated signal content are all hardcoded in Chinese, indicating a fixed language behavior. Under the language-policy rule, forcing a specific language without user choice or clearly documented regional justification is a policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment and control flow indicate this script should hand off to the v2 implementation by exec'ing monitor_v2.py. However, after exec completes, the rest of this file is still parsed and later defines and runs its own main(), so the documented 'redirect to v2' behavior contradicts the actual behavior of also retaining and executing local code.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill supports 黄金/加密货币/外汇, but the only concrete market data function here is get_gold_price_akshare(), which fetches COMEX gold specifically. No code paths implement crypto or forex retrieval, so the behavior falls short of the stated cross-asset support.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest and module docstring claim a strategy using 1H trend determination and 15M entry with ATR-based risk management. In practice, trend, signals, and ATR are all derived from a single current price snapshot/high-low range rather than distinct 1H and 15M candle data, so the implemented behavior does not match the described multi-timeframe strategy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script creates an output directory and writes generated trading signal content to a markdown file, which is a file-write operation covered by the warning requirement. While it logs success after writing, there is no warning or disclosure before the write, and no docstring or comment at the write site explaining that user-visible artifacts will be created on disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language description and all user-facing strings are written in Chinese, indicating the skill is designed to operate in a fixed language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

Disabling TLS certificate verification allows a man-in-the-middle attacker to spoof the Sina Finance endpoint and feed arbitrary market data to the script. In this skill's trading context, that can directly manipulate generated signals, causing unsafe trading decisions and undermining data integrity.

Content

Scanner excerpt · scripts/monitor_v2.py (reported line 45)May include surrounding context.

python
"Referer": "https://futures.sina.com.cn/"
        }
        
        response = requests.get(url, headers=headers, timeout=10, verify=False)
        
        if response.status_code == 200:
            # 解析返回:var hq_str_hf_GC="COMEX 黄金,2156.80,..."

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill supports 黄金/加密货币/外汇, implying symbol-specific monitoring across multiple asset classes. However, get_gold_price always calls hardcoded gold-specific fetchers (hf_GC and GC=F), and check_signal passes symbol configuration that is never used to select a different instrument, so non-gold symbols would still analyze gold prices.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description claims a multi-timeframe strategy with 1H directional bias and 15M entry conditions plus ATR-based management. In practice, analyze_trend and detect_signals use only current/high/low/open/prev_close values from one fetched response, with no retrieval or processing of distinct 1H and 15M candles, so the stated trading methodology is not actually implemented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code creates an output directory and writes a markdown file containing generated signals, which is a file-write operation. Although it logs after saving, there is no prior confirmation prompt, no comment/docstring warning near the write path, and no evidence in this file that the user is warned beforehand about persistent file creation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON config uses non-English symbol names such as "黄金" and "比特币" in user-facing values, which implies a fixed locale choice. There is no accompanying indication in this file that users can select a language or that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The top-level docstring presents the file as a production SMC monitor using ATR-based dynamic risk management. But calculate_atr does not compute ATR over a period; it just uses high-low from current data and clamps it between 10 and 80, which materially contradicts the documented strategy representation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.