czsc-thinking

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/example_workflow.py

The code is a stock-analysis workflow wrapper, not inherently malware based on the supplied fragment. It contains a significant command-injection vulnerability because --token and --ts_code are interpolated into os.system commands without validation or quoting. The token is additionally exposed in console output and potentially process listings. The invoked helper scripts must be reviewed separately.

Confidence: 99%Severity: 82%
Audit Metadata
Analyzed At
Sep 20, 2026, 06:22 AM
Package URL
pkg:socket/skills-sh/zengbin93%2Fczsc_skills%2Fczsc-thinking%2F@71a7ff00305e34d71e3972df5db96fe0b832599cff652c0c526bcb9797034342
Security Audit — socket — czsc-thinking