Back to skill

Security audit

EarningsFinancialsAgent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed financial-data helper that fetches public earnings and financial metrics, with the main caution being an unpinned Python dependency install.

Install this in an isolated virtual environment and consider pinning `yfinance` to a reviewed version before use. Treat the financial output as data retrieval and analysis support, not investment advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25-29
Vulnerability Type: Unpinned third-party dependency and supply-chain exposure
Risk Level: Medium

Vulnerable Code

markdown
## Setup
Before using this skill, ensure the dependencies are installed in your environment:
```bash
pip install yfinance
text

The security-relevant command is on line 28:

```bash
pip install yfinance

Technical Analysis

The installation instructions retrieve the latest available release of yfinance and its transitive dependencies without specifying reviewed versions or verifying package hashes. Consequently, installations performed at different times may resolve to different code.

This creates a supply-chain risk if a future package version or one of its dependencies is compromised. Python packages can execute installation or build-related code during installation, and package code is subsequently loaded by logic.py through import yfinance as yf. The project provides no lock file, version constraint, hash verification, or documented package-integrity control.

The reviewed source does not demonstrate that the current yfinance package is malicious. The finding concerns the unsafe and non-reproducible dependency installation process.

Attack Path

  1. An attacker compromises a future yfinance release, one of its transitive dependencies, or the associated package publishing account.
  2. A user follows the documented pip install yfinance instruction after the compromised release becomes the version selected by the package resolver.
  3. The compromised package executes code during installation, build processing, or subsequent import.
  4. The user invokes logic.py, which imports yfinance, activating malicious package code if it was not already executed during installation.
  5. The malicious code runs with the permissions of the account executing pip or the skill.

Impact Assess

...[truncated 467 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add a dependency manifest that pins yfinance and every resolved transitive dependency to reviewed versions.

  2. Generate and record cryptographic hashes for all approved distributions.

  3. Install dependencies using hash verification, for example:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  4. Use an isolated virtual environment rather than installing into the system Python environment.

  5. Review and update pinned dependencies through a controlled process that includes vulnerability scanning and release-diff inspection.

  6. Configure package installation to use only the intended trusted index and avoid unreviewed extra indexes.

  7. Do not execute package installation with administrative privileges unless explicitly required and separately justified.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.