Back to skill

Security audit

OpenDART CLI

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent OpenDART command-line tool that uses the expected API key, network calls, and local cache for Korean financial disclosure lookups.

Before installing, provide an OpenDART API key only through the documented environment variable, expect Korean CLI output, and be aware that corp-code data is cached locally and document downloads write to the path you choose.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes capabilities that require access to environment variables, network, and local file read/write for caching and document downloads, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates a least-privilege gap: an agent platform may grant broader capabilities than users expect, increasing the chance of secret exposure, unintended filesystem access, or unreviewed outbound requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file contains natural-language status and error messages exclusively in Korean, and raised exceptions also use Korean text. This forces a specific language on users without any opt-in or documented locale constraint, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description explicitly says the CLI provides Korean error messages, which imposes a specific language/locale behavior. Under the policy rule, forcing a language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pytest has 2 known advisory(ies) (CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Multiple user-facing strings in the CLI, including the main description, subcommand help, and error messaging, are written only in Korean. This imposes a specific language on users without any opt-in, fallback, or documentation that the tool is intentionally limited to a Korean-speaking audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The client creates a cache directory and writes API-derived corporation code data to a local JSON file, but there is no confirmation prompt, print/log disclosure, or inline warning that local files will be created or updated. For a code file, local file writes are a covered safety-relevant operation when they occur without any user disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The test explicitly requires the Korean string "사업보고서" in CLI output, which suggests the skill may enforce a specific language/locale behavior. Because this file contains no indication that the language choice is optional or justified as region-specific, it matches the natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.