Back to skill

Security audit

Einstein Research — Edge Candidate Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its research-ticket purpose, but it has review-worthy risks around arbitrary local command execution and unsafe file export paths.

Review before installing. Use it only in a constrained project workspace, avoid --llm-ideas-cmd unless the executable is trusted, do not export untrusted ticket files, and avoid --force until candidate IDs are restricted to safe names and contained under the intended strategies directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/export_candidate.py:232
Finding

Path Traversal and Arbitrary File Overwrite via Unsanitized Candidate ID

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code chunk is only a test configuration helper. It modifies sys.path so tests can import modules from the parent directory. It does not implement any of the declared business functionality around equity research ticket generation, candidate spec export, or compatibility checking. This is a materially different primary purpose, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a research-ticket generation and candidate-export skill with optional compatibility checking. The actual code chunk is not such a generator/exporter; it is a test suite for a validator. It exercises validation of strategy YAML files, pipeline-schema checks, subprocess-based UV validation parsing, and command-line error handling. While this partially aligns with the declared preflight-check aspect, the primary purpose is materially different and much narrower than the declared end-to-end research-ticket generation/export workflow. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code path broadens the skill from research-ticket generation into a generic command launcher by permitting any external program to be run for 'LLM ideas'. In the context of an agent skill, that scope expansion is security-significant: a caller or chained workflow can turn a market-analysis feature into arbitrary process execution, with access to local environment permissions and to the generated payload data.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/validate_candidate.py (reported line 83)May include surrounding context.

python
def _uv_env() -> dict[str, str]:
    """Return subprocess environment with writable uv cache."""
    env = os.environ.copy()
    env.setdefault("UV_CACHE_DIR", "/tmp/uv-cache-edge-candidate-agent")  # nosec B108
    return env

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes shell commands and file creation/export behavior but does not declare any explicit tool scope or allowed-tools policy. In an agent environment, this creates ambiguity about whether shell, file read/write, or environment access is permitted, which can lead to over-privileged execution, unsafe tool invocation, or policy bypass if a runner infers capabilities from content instead of an allowlist.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

The script accepts a user-supplied --llm-ideas-cmd, tokenizes it, and executes it with subprocess.run, allowing the skill to invoke arbitrary local programs. Even without shell=True, this is still dangerous because the command itself is fully attacker-controlled and the process receives structured market/anomaly data on stdin, enabling arbitrary code execution or unintended data exfiltration in the skill's execution environment.

Content

Scanner excerpt · scripts/auto_detect_candidates.py (reported line 528)May include surrounding context.

python
if not command_parts:
        raise AutoDetectError("--llm-ideas-cmd is empty")

    result = subprocess.run(
        command_parts,
        input=json.dumps(payload),
        text=True,

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest centers on generating/prioritizing research tickets and exporting pipeline-ready candidate specs, but this code also performs downstream artifact export through another module and pipeline-context validation. That behavior reaches into strategy-artifact generation and validation workflows rather than staying within pure candidate/ticket creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The external hint-generation command is fed market summary and anomaly data without a strong user-facing security boundary or disclosure beyond CLI help text. In an agent/skill setting, this can lead to silent transmission of potentially sensitive research context to an untrusted local tool or wrapper, especially when combined with the arbitrary executable design.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/validate_candidate.py (reported line 54)May include surrounding context.

python
]
    )

    result = subprocess.run(  # nosec B607 - uv is a known local tool
        ["uv", "run", "python", "-c", snippet],
        cwd=str(pipeline_root),
        env=_uv_env(),

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The function writes data to disk via path.write_text(), which is a safety-relevant file modification. Although the function has a technical docstring, there is no user-facing confirmation, warning, or visible disclosure about overwriting or modifying files in this code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.