Back to skill

Security audit

stock-analysis-aisa

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis skill is coherent and purpose-aligned, but users should treat its API key and optional endpoint override carefully.

Install only if you are comfortable providing an AISA_API_KEY and sending requested ticker analysis to the configured AISA-compatible API. Do not set AISA_BASE_URL unless you fully trust that endpoint, and prefer running it in a minimal environment with only the needed API key exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyze_stock.py:106
Finding

API Credential and Query Redirection Through an Unrestricted Endpoint Override

Content
View full analysis
OpenAI: api_key = os.environ.get("AISA_API_KEY") if not api_key: print("❌ Error: AISA_API_KEY environment variable is not set.", file=sys.stderr) print(" Set it with: export AISA_API_KEY=your_key_here", file=sys.stderr) sys.exit(1) base_url = os.environ.get("AISA_BASE_URL", "https://api.aisa.one/v1") return OpenAI(api_key=api_key, base_url=base_url) ``` The configured client subsequently transmits an authenticated request: ```python response = client.chat.completions.create( model=model, messages=[ {"role": "system", "content": SYSTEM_PROMPT}, {"role": "user", "content": prompt}, ], temperature=0.1, ) ``` ### Technical Analysis The `AISA_BASE_URL` environment variable completely controls the destination used by the OpenAI-compatible client. The value is not validated to ensure that it uses HTTPS or belongs to an approved host. The client is initialized with `AISA_API_KEY`, so requests to the configured destination are authenticated using that credential. The request body also includes the generated analysis prompt and user-supplied ticker symbols. Consequently, an actor capable of modifying the process environment can redirect sensitive authenticated traffic to an attacker-controlled endpoint. Network communication with the default AISA service is necessary for the Skill's declared live-analysis functionality. However, allowing unrestricted destination replacement exceeds the minimum privilege required when only the official AISA endpoint is intended. ### Attack Path 1. An attacker gains control over the environment used to launch the Skill, such as through a poisoned wrapper script, CI co ...[truncated 1178 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/analyze_stock.py:2
Finding

Unbounded Third-Party Dependency Resolution

Content
View full analysis
=3.10" # dependencies = [ # "openai>=1.0.0", # ] # /// ``` ### Technical Analysis The script declares `openai>=1.0.0` without an upper version bound, exact version, lockfile, or package hash. A compatible runner such as `uv run` may therefore resolve and install a future release that was not reviewed with this Skill. The package name is legitimate, and the project does not configure a suspicious package source. There is no evidence that the current dependency is malicious. The risk arises from permitting future or environment-dependent package resolution rather than installing a reproducible, audited version. Python packages can execute code during installation or import. If a newly matching package release or configured package index is compromised, running the Skill could execute that dependency's code with the privileges of the invoking user. ### Attack Path 1. The Skill is invoked through a runner that resolves dependencies from a Python package index. 2. The resolver selects a future version satisfying `openai>=1.0.0`. 3. That release is compromised, malicious, or otherwise contains unsafe initialization behavior. 4. The runner installs the selected package without validating it against a reviewed lockfile and cryptographic hash. 5. The script imports `OpenAI` from the package. 6. Malicious installation or import-time code executes with the permissions of the user running the Skill. This path requires compromise or poisoning of an accepted package release or dependency source; the audited project itself does not provide evidence that such a compromise has already occurred. ### Impact Assessment A compromised dependency could act with the invoking process's permissions. Depending on the runtime environment, this could pe ...[truncated 370 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
## When NOT to Use

- Do not use this skill for browser-cookie extraction, passwords, Keychain access, or other local sensitive credential access.
- Prefer a different skill when the user request is outside this skill's domain.

## Capabilities

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to a sensitive environment variable (AISA_API_KEY) and invokes a Python runtime, but it does not define any explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and can allow broader-than-intended execution or secret exposure depending on the hosting agent framework.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/analyze_stock.py (reported line 115)May include surrounding context.

python
print("❌ Error: AISA_API_KEY environment variable is not set.", file=sys.stderr)
        print("   Set it with: export AISA_API_KEY=your_key_here", file=sys.stderr)
        sys.exit(1)
    base_url = os.environ.get("AISA_BASE_URL", "https://api.aisa.one/v1")
    return OpenAI(api_key=api_key, base_url=base_url)

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest describes an analysis skill for tickers and investment comparison, but this file additionally depends on environment-based secret and endpoint configuration. While needed for this implementation, accessing runtime credentials is a capability not reflected in the stated skill purpose and is not directly user-facing analysis behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.