Back to skill

Security audit

Medici Investments — Position Sizer

Security checks for vulnerabilities and agentic risk

Overview

This is a local stock position-size calculator with disclosed financial inputs and report generation, and I found no hidden network, credential, destructive, or system-persistence behavior.

Install only if you are comfortable running a local Python calculator and having position-sizing reports saved on disk. Treat its outputs as risk-management math, not investment advice, and confirm the inputs before using the result for a real trade.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no allowed tool scope, yet its workflow instructs the agent to execute a local Python script via shell. That creates a permissions/behavior mismatch: an orchestrator or reviewer cannot clearly determine that shell execution is intended, which increases the risk of unintended command execution or over-privileged invocation if the skill is enabled.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The implicit triggers are broad enough that the skill could activate for general discussion about buying stocks or managing risk, even when the user did not explicitly request position sizing. In financial contexts, unintended invocation can lead to overconfident, tool-driven outputs or premature calculations based on incomplete assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill persists user-supplied financial calculation outputs to disk even though its stated purpose is a calculation utility. Writing reports creates an unnecessary side effect that can expose sensitive portfolio/account data, leave recoverable artifacts on shared systems, or enable storage abuse if invoked repeatedly. In this context, the behavior is not overtly malicious, but it expands the skill's data-handling surface beyond what users may reasonably expect from a position-sizing tool.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/tests/test_position_sizer.py (reported line 373)May include surrounding context.

python
def test_risk_pct_and_kelly_mutual_exclusive(self):
        """Both risk_pct and win_rate via CLI -> SystemExit (argparse error)."""
        script = "skills/position-sizer/scripts/position_sizer.py"
        result = subprocess.run(
            [
                sys.executable,
                script,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/tests/test_position_sizer.py (reported line 440)May include surrounding context.

python
def test_risk_pct_and_kelly_mutual_exclusive(self):
        """Both risk_pct and win_rate via CLI -> SystemExit (argparse error)."""
        script = "skills/position-sizer/scripts/position_sizer.py"
        result = subprocess.run(
            [
                sys.executable,
                script,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/tests/test_position_sizer.py (reported line 465)May include surrounding context.

python
def test_cli_missing_required(self):
        """Missing --account-size -> SystemExit."""
        script = "skills/position-sizer/scripts/position_sizer.py"
        result = subprocess.run(
            [
                sys.executable,
                script,

Static analysis

No suspicious patterns detected.