Back to skill

Security audit

commodity-macro-signal

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed commodity-analysis skill that uses a Finskills API key to fetch market data, with no evidence of hidden execution, persistence, or destructive behavior.

Install only if you are comfortable using a Finskills API key and sending commodity symbols or requested series to Finskills. Avoid putting sensitive portfolio, client, or proprietary trading information in prompts, and treat the generated macro signals as informational analysis rather than financial advice.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README instructs users to configure an API key and describes external API usage, but provides no warning that user prompts, requested symbols/series, or derived query inputs may be transmitted to a third-party service. This creates a realistic risk of users supplying sensitive financial context or secrets to the skill without understanding that data may leave the local environment, and it also omits basic credential-handling guidance for the API key.

Static analysis

No suspicious patterns detected.