Back to skill

Security audit

finance

Security checks for vulnerabilities and agentic risk

Overview

This is a market-price helper that uses expected third-party data providers and local cache files, with some documentation overstatements and dependency hygiene issues but no hidden or destructive behavior found.

Install this only in a normal isolated Python virtual environment, and consider pinning or locking dependencies before use. Expect it to contact Yahoo/yfinance and open.er-api.com and to create local cache/watchlist files. Treat claims about crypto, provider fallbacks, and historical FX series as limited or inaccurate unless the skill is updated.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unhashed Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-3
Vulnerability Type: Supply-chain exposure through unbounded, unverified dependencies
Risk Level: Medium

Vulnerable Code:

text
yfinance>=0.2.40
pandas>=2.0.0
requests>=2.31.0

The documented installation workflow in SKILL.md:42-44 instructs the agent to install these dependencies:

text
Install:
- `python -m venv .venv && source .venv/bin/activate` (or Windows equivalent)
- `pip install -r requirements.txt`

Technical Analysis

Every dependency uses a minimum-version constraint (>=) rather than an exact, reviewed version. Consequently, the installation may resolve to any future package release accepted by the resolver. The requirements file also contains no cryptographic hashes, so package artifacts are not verified against a project-controlled allowlist.

Python packages can execute package-controlled code during installation and when imported. The scripts directly import these dependencies, including requests, pandas, and yfinance. Therefore, compromise of an eligible future release or its distribution channel could introduce code execution into the documented installation or runtime workflow.

This finding does not establish that the currently named packages or versions are malicious. It identifies the absence of version and artifact controls needed to make dependency installation reproducible and resistant to future supply-chain compromise.

Attack Path

  1. An attacker compromises the release process or distribution account for one of the listed packages and publishes a malicious version satisfying its >= constraint.
  2. A user or agent follows SKILL.md and runs pip install -r requirements.txt.
  3. The package resolver selects and downloads the malicious, project-unverified release.
  4. Attacker-controlled code executes during package installation or when the dependency is imported by a market scri ...[truncated 613 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace minimum-version constraints with exact versions that have been reviewed and tested, for example package==x.y.z.

  2. Generate and commit cryptographic hashes for all direct and transitive dependencies using a lock-file workflow such as pip-tools.

  3. Install with hash enforcement, such as:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Use a trusted or organization-controlled package index and prevent unexpected fallback to untrusted indexes.

  5. Perform dependency vulnerability and provenance scanning in CI.

  6. Update dependencies through controlled review rather than allowing automatic resolution to arbitrary future releases.

  7. Run installation and market scripts in a minimally privileged virtual environment or sandbox without access to unrelated credentials or sensitive files.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code generally aligns with quote tracking and does implement caching. However, the description claims support for crypto and provider fallbacks. In the code, there is no dedicated crypto path or explicit validation that crypto symbols are supported; only stock-style Yahoo Finance lookup and FX via ExchangeRate-API are implemented. Also, 'provider fallbacks' is overstated: FX uses a single provider, and stocks use only yfinance/Yahoo Finance, with merely internal method fallbacks (fast_info, then history), not alternate providers. Therefore the description overstates actual capabilities in material ways.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broader market-tracking capability with caching and provider fallbacks across stocks, ETFs, indices, crypto, and FX. This code chunk is narrower: it is a command-line historical series fetcher that uses only yfinance for non-FX symbols and prints CSV. For FX pairs, it does not provide tracking here; instead it terminates with a limitation message. There is also no evidence of caching or fallback logic. Therefore the supplied code does not accurately represent several key declared capabilities.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs the agent to use shell, network access, and local state files, but it does not declare any explicit tool scope or permissions boundary. This is dangerous because an agent or orchestrator may grant broader capabilities than intended, increasing the blast radius if the skill is misused, modified, or invoked in an unsafe context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The usage docstring includes an FX invocation example (USD/ZAR --days 30), which implies the script can handle that mode. In reality, the FX branch raises SystemExit and produces no series output, so the documentation actively misrepresents supported behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill manifest says it can track FX pairs, and this file's module docstring also presents an FX usage example. However, when an FX pair is provided, the code immediately terminates with a message that historical FX series is unsupported, so the advertised FX tracking behavior is not actually implemented in this script.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/market_watchlist.py (reported line 80)May include surrounding context.

python
results = []
    for sym in items:
        # Call market_quote.py to keep logic centralized
        p = subprocess.run(
            [sys.executable, os.path.join(os.path.dirname(__file__), "market_quote.py"), sym],
            capture_output=True,
            text=True,

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency specification for yfinance uses a lower-bound only constraint (>=0.2.40), which makes builds non-reproducible and allows future releases to be installed without review. This increases supply-chain risk because a breaking or compromised upstream release could be pulled into the skill at install time.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
yfinance>=0.2.40
pandas>=2.0.0
requests>=2.31.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The pandas dependency is not pinned to a specific version, so installations may resolve to different releases over time. That weakens reproducibility and makes it harder to verify whether the deployed version includes security fixes or introduces vulnerable behavior.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
yfinance>=0.2.40
pandas>=2.0.0
requests>=2.31.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The requests package is specified with only a minimum version, which permits automatic adoption of later versions that may behave differently or introduce regressions. Because requests is a network-facing library, lack of exact pinning increases supply-chain and deployment uncertainty even if no specific vulnerable version is shown here.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
yfinance>=0.2.40
pandas>=2.0.0
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code makes outbound HTTP requests to a third-party FX API and elsewhere writes fetched quote data to local cache files, but the runtime behavior is not disclosed through a prompt, log message, or comment near the operations. For a code-file review under SQP-2, these safety-relevant actions should have some visible disclosure unless they are clearly communicated as part of the skill behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.