Back to skill

Security audit

Congress Trades Tracker

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to match its stated purpose, but it needs review because it recommends persistent per-minute execution and feeds remote API text into an agent alert channel without enough containment.

Review before installing. Use a dedicated virtual environment, pin dependencies, store only QUIVER_API_KEY and needed settings in a dedicated env file rather than sourcing ~/.profile, reduce polling if minute-level alerts are unnecessary, add an uninstall step for the cron entry, and make OpenClaw treat alert file contents strictly as untrusted data to display, not instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Warning
Location
SKILL.md:40
Finding

Persistent Minute-by-Minute Execution Through User Cron

Content
View full analysis
> /path/to/logs/scraper.log 2>&1 ``` Never inline API keys directly in crontab entries. ``` ### Technical Analysis The setup instructions direct the user to install a cron entry that survives the original Skill run, user logout, and system reboot. It executes the scraper once per minute without further interactive authorization. Recurring execution is relevant to the declared real-time monitoring function, and the entry does not use `sudo` or attempt privilege escalation. Nevertheless, installing a cross-session scheduled task grants the Skill persistent network and filesystem activity. This exceeds the privileges required for a one-time trade synchronization operation. The command also sources the user's entire `~/.profile`. Consequently, every command subsequently placed in that file will be executed by cron once per minute, even if it is unrelated to the scraper. This unnecessarily expands the execution surface. ### Attack Path 1. The user follows the setup instructions and edits their user crontab. 2. The cron entry remains registered after the Skill's interactive setup has ended. 3. Every minute, cron sources the complete `~/.profile`. 4. Cron then runs the scraper with the user's permissions. 5. The process repeatedly performs outbound API requests and writes to the configured database, state, alert, and log paths. 6. If `~/.profile` is later modified with unsafe or compromised commands, those commands are also executed every minute in the cron context. ### Impact Assessment No admi ...[truncated 624 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/scraper.py:113
Finding

Unsanitized Remote API Data Is Forwarded Into an AI Agent Input Channel

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:27
Finding

Third-Party Dependency Is Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tainted flow: 'API_KEY' from os.environ.get (line 19, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/scraper.py (reported line 67)May include surrounding context.

python
def fetch_trades(limit=200):
    """Fetch latest trades from Quiver API."""
    resp = requests.get(
        f"{API_BASE}?limit={limit}",
        headers={
            "Authorization": f"Token {API_KEY}",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents capabilities to read environment variables, write local files, and make network requests, but it does not declare any explicit tool scope or permissions boundary. This weakens reviewability and least-privilege enforcement, making it easier for a consumer to run a skill with broader access than expected.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

export QUIVER_API_KEY="your-api-key-here"

text

### 3. Schedule with user cron (no sudo needed)

Add your env vars to `~/.profile` or a `.env` file sourced by your shell, then add the cron entry:

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The skill recommends installing a cron job that persists and runs every minute, sourcing the user's profile and executing a script indefinitely. Persistent scheduled execution increases the blast radius of any later script modification, profile poisoning, or credential misuse, especially because it automatically loads environment variables and writes files on a recurring basis.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Add your env vars to ~/.profile or a .env file sourced by your shell, then add the cron entry:

bash
crontab -e
# Add this line (uses env vars from your profile):
* * * * * . "$HOME/.profile" && /usr/bin/python3 /path/to/scripts/scraper.py >> /path/to/logs/scraper.log 2>&1

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
- **Only outbound connection**: `api.quiverquant.com` (Quiver Quant API)
- **Storage**: local SQLite file + JSON alert files in `data/`
- **No external endpoints** besides the Quiver API
- Restrict file permissions on data directory (`chmod 700 data/`)

## Alert Format

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/scraper.py (reported line 18)May include surrounding context.

python
import requests

# ─── Config (override with env vars) ───────────────────────────────────────
API_BASE = "https://api.quiverquant.com/beta/live/congresstrading"
API_KEY = os.environ.get("QUIVER_API_KEY")
if not API_KEY:
    print("ERROR: QUIVER_API_KEY environment variable is required. Get one at https://www.quiverquant.com/")

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script sends an authenticated HTTP request to an external API using the QUIVER_API_KEY in the Authorization header. While the module docstring explains the scraper's purpose, it does not clearly disclose that the script will transmit credentials and request data to a third-party service during execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The script writes persistent state to multiple local files, including the SQLite database, sync state, alerts history, and pending alert text file. Although the high-level docstring mentions syncing to SQLite and writing alerts, it does not clearly enumerate these local file modifications or warn that repeated cron execution will continuously update files on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.