Back to skill

Security audit

Fed Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is low-privilege and does not show malicious behavior, but it materially misrepresents static sample data as live Federal Reserve tracking.

Review this skill before installing if you need accurate or current economic information. It does not appear to steal data or modify the system, but its documentation claims live Federal Reserve tracking and output options that are not implemented, so users could be misled by stale hardcoded values.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring says the script 'Tracks FOMC decisions, interest rates, inflation data, and Fed speeches' and presents CLI usage with an --output-file argument. In reality, the script uses a static in-code FED_DATA list and only prints markdown to stdout; there is no argument parsing or file writing logic. This is an active contradiction between documented behavior and implemented behavior.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/track_fed_policy.py (reported line 75)May include surrounding context.

python
"""Main entry point."""
    print("FED Agent - Federal Reserve Policy Tracker")
    print("=" * 50)
    print("Executing at:", __import__('datetime').datetime.now().strftime("%Y-%m-%d %I:%M%p"))
    
    # Build markdown table from Fed data
    output = build_markdown_table(FED_DATA)

Static analysis

No suspicious patterns detected.