Back to skill

Security audit

Synth Data

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Synthdata market-volatility API client; it has financial-use and third-party sharing caveats, but no evidence of hidden execution, credential theft, or destructive behavior.

Install only if you trust Synthdata.co with your API key and requested asset tickers. Treat the trading, options, Polymarket, alerting, and cron examples as user-controlled workflows, not automatic actions, and avoid wiring them to real trades or public messaging channels without separate review and clear financial-risk disclaimers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Tainted flow: 'req' from os.environ.get (line 48, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/synth.py (reported line 52)May include surrounding context.

python
"Authorization": f"Apikey {API_KEY}",
            "User-Agent": "SynthdataSkill/1.0"
        })
        with urllib.request.urlopen(req, timeout=10) as resp:
            return json.loads(resp.read().decode())
    except urllib.error.HTTPError as e:
        return {"error": f"HTTP {e.code}: {e.reason}"}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires environment access for SYNTHDATA_API_KEY and performs network-backed operations, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it harder for a host agent or reviewer to understand and constrain what the skill is allowed to access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
Generate probabilistic price ranges using forecast volatility (24h max - Synthdata forecast window).

### 4. Scheduled Reports
Create a cron job for daily Slack/Telegram forecasts (see examples/use-cases.md).

### 5. Risk Alerts
Monitor for assets crossing volatility thresholds and trigger notifications.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill sends requests to an external API and includes an API key in the Authorization header, which is a real external data transmission path. In context this is expected functionality, but it still creates a trust boundary: prompts, queried assets, and credentials are exposed to a third-party service if execution is not tightly constrained.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
import requests

resp = requests.get(
    "https://api.synthdata.co/insights/volatility",
    params={"asset": "BTC"},
    headers={"Authorization": f"Apikey {API_KEY}"}
)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This documentation goes beyond passive volatility querying and simulation into explicit trading and betting decision support, including Polymarket guidance and directional market-action suggestions. In a finance-related skill, that increases the chance users will operationalize the output for speculative decisions without suitability, risk, or compliance guardrails.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/use-cases.md (reported line 14)May include surrounding context.

Endpoint

text
GET https://api.synthdata.co/insights/volatility?asset={TICKER}

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 6)May include surrounding context.

Endpoint

text
GET https://api.synthdata.co/insights/volatility?asset={TICKER}

Authentication

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to set a Synthdata API key and use the skill, but it does not clearly disclose that the key will be used to make authenticated requests to an external third-party service. This can mislead users about where their credentials are being sent and reduces informed consent around credential handling, though the service name and external URL in the README make the risk relatively limited.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest frames the skill as a market-volatility query and simulation tool. The documented Slack/Telegram reporting and alert-sending examples add messaging/notification capabilities that are not part of the stated purpose and go beyond obvious implementation details of querying data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a markdown file, so SQP-2 applies to omitted warnings in documentation. The use case describes scheduling and sending reports to Slack/Telegram, but the text does not warn that generated content will be sent to external services, which has privacy and data-sharing implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

For markdown files, missing disclosure about behaviors affecting privacy is in scope. Saying the output includes a QuickChart URL implies user-selected asset data may be sent to or encoded for an external charting service, but no warning is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.