Back to skill

Security audit

Stock Prices

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward stock-price lookup guide with a normal third-party decoder dependency risk but no hidden or destructive behavior.

Before installing, verify the @toon-format/toon package and pin a specific reviewed version in your project. Treat ticker and portfolio symbol lists as data sent to stock-prices.on99.app, and avoid placing unrelated sensitive information in the symbols parameter.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 25
Vulnerability Type: Supply-chain exposure through an unpinned package dependency
Risk Level: Medium

Vulnerable Code Snippet

markdown
Install the TOON decoder for parsing: `pnpm add @toon-format/toon`

Technical Analysis

The Skill directs users to install @toon-format/toon without specifying an exact, reviewed version or integrity constraint. Consequently, the package resolved at installation time may differ from the version that existed when the Skill was audited.

If the package registry account, package, or a future release is compromised, installation could introduce attacker-controlled code. Depending on package configuration and package-manager policy, code may execute through installation lifecycle scripts or when the decoder is imported and used. The package is relevant to the declared TOON-decoding functionality, but using an unconstrained version exceeds the minimum supply-chain trust needed.

Attack Path

  1. An attacker compromises the package publisher, registry distribution channel, or a future package release.
  2. The attacker publishes a malicious version under the expected package name.
  3. A user follows the documented pnpm add @toon-format/toon instruction.
  4. pnpm resolves and downloads the current malicious release because no exact version is pinned.
  5. Attacker-controlled code executes through a package lifecycle script or when application code imports and invokes the package.
  6. The code operates with the permissions of the package installation or application process.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the invoking user's privileges. Depending on the host environment, this may expose project files, environment variables, accessible credentials, and network resources, or allow modification of files writable by that user. The Skill itself does not request e ...[truncated 512 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin @toon-format/toon to an exact version that has been reviewed rather than relying on the latest registry release.
  • Commit and enforce a lockfile containing package integrity metadata.
  • Use pnpm's frozen-lockfile mode in automated and production installations.
  • Disable dependency lifecycle scripts with --ignore-scripts where compatible with the package's documented operation.
  • Verify package provenance, publisher identity, release history, and integrity before recommending it.
  • Run decoding in a process with minimal filesystem, credential, and network access.
  • Document that ticker symbols and portfolio symbol lists are transmitted to stock-prices.on99.app, and advise users not to include unrelated sensitive data in the query parameter.
  • Validate and URL-encode ticker input before constructing request URLs.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.