Back to skill

Security audit

Options Payoff

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate options-payoff visualizer, but its unpinned remote install command and broad financial-screenshot activation rules warrant review before installation.

Install only from a trusted, pinned version or reviewed commit. Use the skill when you explicitly want an options payoff visualization, avoid sharing broker screenshots with unrelated account details, and verify any defaults or inferred values before relying on the chart for trading decisions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:42
Finding

Unpinned Third-Party Components in Installation Command

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 42–46
Vulnerability Type: Unpinned third-party dependency and mutable source reference
Risk Level: Medium

Vulnerable Code Snippet:

markdown
## Setup

```bash
npx skills add himself65/finance-skills --skill options-payoff
text

### Technical Analysis

The documented setup command invokes `npx` without pinning the `skills` package to an exact, audited version. Depending on the local npm configuration and cache state, `npx` can download and execute the version currently resolved from the package registry.

The `himself65/finance-skills` source reference is also not pinned to an immutable commit hash or verified release artifact. Consequently, the components installed or executed in the future may differ from those reviewed during this audit.

This creates a supply-chain trust boundary in which mutable upstream content can be executed during installation. Exploitation requires compromise or malicious control of a relevant upstream package, repository, maintainer account, release process, or name-resolution source; no such compromise was observed in the audited project itself.

### Attack Path

1. An attacker compromises the npm package, its maintainer account, the referenced source repository, or another relevant upstream publishing channel.
2. The attacker publishes malicious content under the same mutable package or repository reference.
3. A user follows the documented setup instructions and runs the `npx skills add ...` command.
4. `npx` resolves and executes the unpinned package, which then retrieves or installs the mutable repository content.
5. The malicious component executes with the permissions of the user running the command.

### Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. The resulting scope may include reading or modifying files accessible to that user, a
...[truncated 467 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm package invoked through npx to an exact, reviewed version rather than relying on the registry's current resolution:
    bash
    npx skills@EXACT_AUDITED_VERSION add himself65/finance-skills@VERIFIED_COMMIT --skill options-payoff
    
  2. Replace the mutable repository reference with a full, verified commit hash or a cryptographically signed immutable release.
  3. Publish expected checksums for downloaded artifacts and verify them before installation or execution.
  4. Use npm lockfiles and integrity metadata where the installation workflow supports them.
  5. Review the selected package version and repository revision for lifecycle scripts or other install-time execution.
  6. Run installation with least privilege in an isolated environment, without unnecessary secrets or credentials.
  7. Document the trusted publisher, exact version, commit identifier, and verification procedure so users can confirm that they are installing the audited artifact.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are overly broad, causing the skill to activate on common finance discussions, partial information, or screenshots from brokers. Overbroad activation increases the chance of unintended invocation, unnecessary processing of sensitive financial context, and user confusion about when the skill is operating.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to install and execute a remote package via npx skills without pinning a specific version or immutable source. That creates a supply-chain risk: a later compromised or maliciously updated package could be fetched and executed automatically in a user's environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s trigger rules are unusually broad, including generic terms like 'spread' and instructions to always invoke even with partial information. This can cause the skill to activate on loosely related trading conversations or incomplete broker screenshots, leading to unintended data extraction, misleading financial visualizations, or over-collection of sensitive user context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.