Back to skill

Security audit

Tai Alpha Stock

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed stock-analysis skill with local SQLite storage and market-data network calls, with one optional publishing helper that deserves caution.

Install only if you are comfortable with financial-market data being fetched from Yahoo/yfinance and optional CoinGecko, and with results being written to the documented SQLite database. Do not treat outputs as financial advice. Maintainers should run the ClawdHub publish helper only in an isolated environment with scoped credentials, or replace its runtime npm install with a locked and reviewed dependency flow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
setup/tools/clawdhub_publish.sh:22
Finding

Runtime Installation and Immediate Execution of Unverified npm Dependencies

Content
View full analysis
/dev/null 2>&1 # undici: clawdhub 0.3.0 imports it but does not declare it; keeps CLI working on current Node. npm install clawdhub@0.3.0 undici@6 >/dev/null 2>&1 # clawdhub 0.3.x hardcodes REQUEST_TIMEOUT_MS = 15_000 in dist/http.js. Multi-file # skill uploads routinely exceed 15s (multipart + registry processing), which # surfaces as: Non-error was thrown: "Timeout". Patch the temp install only. HTTP_JS="$TMP/node_modules/clawdhub/dist/http.js" if [[ -f "$HTTP_JS" ]]; then python3 -c " from pathlib import Path import sys path = Path(sys.argv[1]) text = path.read_text(encoding='utf-8') old = 'const REQUEST_TIMEOUT_MS = 15_000' new = 'const REQUEST_TIMEOUT_MS = 180_000' if old not in text: print('clawdhub_publish: expected timeout line not found; skipping patch', file=sys.stderr) sys.exit(0) text = text.replace(old, new, 1) # Undici H2 is experimental on some Node builds; disable to reduce flaky connects. text = text.replace('allowH2: true', 'allowH2: false', 1) path.write_text(text, encoding='utf-8') " "$HTTP_JS" fi exec "$TMP/node_modules/.bin/clawdhub" publish "$REPO_ROOT" \ --slug tai-alpha-stock \ --name "Tai Alpha Stock" \ --version "$VERSION" \ --changelog "$CHANGELOG" \ "$@" ``` ### Technical Analysis The publishing helper resolves packages from the npm registry each time it runs and immediately executes the downloaded `clawdhub` binary. Although `clawdhub` is pinned to version `0.3.0`, no previously reviewed lockfile or package-integrity value is supplied. The `undici@6` dependency is constrained only to a major version, and transitive dependencies are resolved according to the registry state at execution time. Package installation may also execute npm lifecycle scripts. Co ...[truncated 2039 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description focuses on stock analysis, backtesting, conviction scoring, optional ML, and SQLite persistence. The supplied code instead implements a command-line interface for watchlist target/stop alerts, delegating to an alerts store module. Alert management is a distinct capability and trigger surface not described in the declared purpose. While it may belong to the same broader project, this code chunk’s primary behavior does not match the stated functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose describes a stock-analysis pipeline centered on data collection, VectorBT backtesting, conviction scoring, optional ML, and SQLite persistence. The actual code chunk is only a command-line wrapper for a 'hot_scanner' / movers scanner and indicates different external data sources (Yahoo and optional CoinGecko). Based on the provided code, its primary purpose appears materially different from the declared backtesting-and-persistence workflow. While this is only an entrypoint and not the full implementation, the visible behavior and naming align with a scanner capability not represented in the description, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for a financial analysis skill with backtesting and SQLite persistence. The supplied code does none of that: it is a release automation script that checks repo structure and executes unit, integration, and live tests, failing the release on test failure. This is a materially different primary purpose and includes undeclared behavior related to CI/testing and live external-data test execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a stock analysis/backtesting skill with SQLite persistence. The provided code chunk is a test runner script for CI/development: it chooses a Python executable, invokes a structure checker, and runs pytest on test directories. That is a materially different primary purpose from the declared functionality. While this could be a supporting development script within the same repository, evaluated strictly against the skill description, this chunk does not implement or reflect the declared stock-analysis behavior and instead exposes an undeclared testing capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for a stock analysis and backtesting skill with optional ML and SQLite persistence. The supplied code chunk does not implement any of that functionality; it is a helper script for running the project's live pytest suite. Its primary purpose is test execution, including live yfinance-related tests, which is materially different from the declared analysis behavior. Therefore this code chunk does not accurately match the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose centers on financial data collection, technical-indicator backtesting, scoring, optional ML, and SQLite persistence. The actual code does none of those things. Instead, it traverses the repository filesystem and validates documentation/SQL file placement. This is a materially different primary purpose and introduces undeclared capabilities related to repository policy enforcement and filesystem inspection. Therefore, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk does not implement stock data collection, backtesting, conviction scoring, ML, or SQLite persistence. Its sole purpose is release/deployment automation for publishing the repository to ClawdHub. That is a materially different primary purpose and introduces undeclared external-network/package-publication behavior. While build or deployment scripts can exist in a repository, this specific chunk’s behavior is not accurately represented by the declared skill description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description emphasizes a broader stock-analysis and backtesting system with technical indicators, scoring, optional ML, and SQLite persistence. This code does something materially different: it fetches dividend history from yfinance and computes simple dividend heuristics for a single ticker. While dividend analysis could be tangentially related to stock analysis, it is not represented in the declared purpose and the chunk lacks the core declared behaviors (VectorBT strategies, conviction scoring, ML, persistence). Therefore this is a meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a fairly specific stock-analysis system centered on collecting data, running VectorBT backtests with RSI/MACD/BB strategies, producing conviction scores, optional ML, and persisting outputs to SQLite. The supplied code chunk instead implements a standalone HTTP-based screener: it queries Yahoo predefined screeners for movers and optionally CoinGecko trending coins, then emits JSON to stdout. This is a materially different primary purpose and introduces an undeclared capability (crypto trending retrieval). The expected persistence behavior and analytic/backtesting features are absent from this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk does not implement stock collection, technical-indicator backtesting, conviction scoring logic, ML, or SQLite persistence. Its primary purpose is unrelated configuration management for persona files. While config loading can be a supporting detail in some systems, this specific functionality is centered on persona registry handling rather than the declared stock-analysis behavior, so it is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises operational workflows that imply shell, filesystem, environment-variable, database, and likely network access, but the manifest does not declare any explicit tool scope or permissions boundaries. In agent environments, missing scope declarations can cause the runtime or reviewer to underestimate what the skill may access, increasing the chance of over-privileged execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow options list --lang zh-CN|zh-HK, which indicates the skill is designed to operate only in specific Chinese locales. In this file, there is no explicit statement that users can choose other languages or that the locale restriction is required for a region-specific compliance purpose, so this appears to force a language/locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The configuration hard-codes audience_locale: zh-HK, which is a natural-language locale constraint. Under the policy, locale-specific behavior should either offer user choice or be clearly documented as a justified regional constraint; this file does not provide either.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The configuration sets audience_locale: zh-CN, which imposes a specific language/locale behavior. Under the policy, fixed locale requirements are a violation unless the skill offers user choice or clearly documents a justified region-specific constraint, neither of which is evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The configuration sets audience_locale: zh-CN, which imposes a specific language/locale preference in natural-language behavior. The file does not indicate that this locale is optional, user-selected, or justified as a region-specific tool, so it appears to violate the policy against forcing a locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The config sets audience_locale: zh-CN, which is a natural-language locale constraint. In this file there is no indication that the locale is optional, user-selected, or justified as a region-specific tool, so it may violate the policy against forcing a language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The configuration sets audience_locale: zh-HK, which imposes a specific language/locale behavior in natural-language output or interaction. The file does not indicate user opt-in, locale selection flexibility, or a documented region-specific compliance reason for this restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The configuration sets audience_locale: zh-CN, which imposes a language/locale preference in the skill configuration. Under the policy, forcing a specific locale without user opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest sets audience_locale: zh-CN, which imposes a specific language/locale behavior. Under the policy, locale constraints should either offer user choice or be clearly documented and justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration sets audience_locale: zh-CN, which indicates the skill is constrained to a specific language/locale. Under the policy, forcing a locale is a finding unless the file explicitly offers user choice or documents a justified region-specific constraint, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The guidance explicitly instructs use of --lang zh-CN or --lang zh-HK for translation, which imposes a specific language/locale in natural-language instructions. The file does not state that users may choose other languages or opt into this locale behavior, which can conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The configuration hard-codes audience_locale: zh-CN, which indicates the skill is intended to operate in a specific language/locale. The file does not show any user-selectable locale option, opt-in, or justification for restricting output to zh-CN despite supporting multiple markets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The configuration sets audience_locale: zh-CN, which forces a specific language/locale behavior in the persona. The file does not indicate that users can choose a different locale or explicitly opt in, which matches the policy's language/locale violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The configuration sets audience_locale: zh-CN, which imposes a specific language/locale behavior in a natural-language-facing persona. There is no indication in this file that users can choose a different locale or that the restriction is a documented, justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The configuration hard-codes audience_locale: zh-HK, which can create a language/locale policy issue if the persona is applied without offering the user a locale choice. There is no nearby indication that this locale restriction is optional, user-selected, or justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.