Back to skill

Security audit

alva

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate Alva finance integration, but it asks for broad local installation, automatic updates, persistent profile memory, and high-impact finance automation authority that users should review before installing.

Install only if you are comfortable giving this skill broad Alva account access for financial data, cloud scripts, scheduled automations, public playbook releases, memory-based personalization, and trading-related workflows. Review the global npm install/upgrade behavior, avoid automatic updates to unpinned packages, keep secrets in Alva Secret Manager, inspect memory contents periodically, and require explicit confirmation before publishing, granting public access, enabling push alerts, or executing non-paper trading actions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:131
Finding

Persistent User-Editable Memory Can Influence Future Agent Sessions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:75
Finding

Mutable Global CLI Installation Creates a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/design-components.md:133
Finding

Published Playbooks Load Third-Party JavaScript Without Subresource Integrity

Content
View full analysis
``` Generated examples also load CDN scripts without integrity metadata: ```html ``` ```html ``` None of the reviewed tags includes an `integrity` attribute. The first documented URL also omits an exact version. ### Technical Analysis The browser executes JavaScript retrieved directly from `cdn.jsdelivr.net` whenever a visitor opens an affected playbook. Without Subresource Integrity, the browser has no locally declared cryptographic expectation for the returned file. Even where a semantic version appears in the URL, the page does not verify the content hash. The unversioned `markdown-it` URL is more exposed because package resolution may change without any modification to the playbook source. This creates a supply-chain trust dependency on the CDN, npm package publication process, DNS/TLS delivery path, and upstream package maintainers. A changed CDN response becomes part of the playbook's effective runtime after the playbook itself has already been audited or released. ### Attack Path 1. An attacker compromises a CDN account, package publisher, upstream release artifact, or another part of the dependency deli ...[truncated 1342 chars]
Remediation
View remediation
``` 4. Generate integrity values from independently verified release artifacts rather than trusting the CDN response alone. 5. Apply a restrictive Content Security Policy that allowlists only necessary script origins and disallows unsafe inline execution where feasible. 6. Vendor and bundle dependencies during the controlled build process so released playbooks do not acquire executable code at page-load time. 7. Maintain a software bill of materials and a documented update-review process. 8. Add automated checks that reject unversioned script URLs or external scripts lacking `integrity`. 9. Apply the same controls consistently to all templates, examples, and generated playbook HTML. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (119)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is financial analysis, but the instructions require version checking, package installation/upgrades, and local environment/config modification. This hidden operational behavior creates a supply-chain and integrity risk because a user invoking a finance skill would not reasonably expect it to alter the local toolchain or system state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose is financial analysis, but the instructions require version checking, package installation/upgrades, and local environment/config modification. This hidden operational behavior creates a supply-chain and integrity risk because a user invoking a finance skill would not reasonably expect it to alter the local toolchain or system state.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 754)May include surrounding context.

md
| [adk.md](references/adk.md) | Agent Development Kit: `adk.agent()` API, tool calling, ReAct loop, examples |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1282)May include surrounding context.

md
| [adk.md](references/adk.md) | Agent Development Kit: `adk.agent()` API, tool calling, ReAct loop, examples |

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file documents a capability to execute arbitrary JavaScript in a V8 isolate with filesystem, SDK, and HTTP access. That is a powerful code-execution primitive that can be abused for data exfiltration, unauthorized network access, or modification of files, and it is not clearly necessary for a skill whose stated purpose is financial data, market analysis, and backtesting. The mismatch between advertised purpose and exposed capability increases the likelihood that the skill could be repurposed unsafely.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-components.md (reported line 141)May include surrounding context.

Usage

html
<!-- 1. Container with optional size modifier -->
<div class="markdown-container">
  <script type="text/markdown">
    # Heading 1

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-components.md (reported line 869)May include surrounding context.

md
>
<span class="tag">Label</span>

<!-- Solid -->
<span class="tag" style="background:var(--main-m3);color:var(--b-common-white)"
  >LONG</span
>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-components.md (reported line 1260)May include surrounding context.

md
</div>
</div>

<!-- Medium Select (filled state) -->
<div class="select filled" data-select="demo">
  <div class="select-border"></div>
  <span class="select-text">Selected Value</span>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-components.md (reported line 1424)May include surrounding context.

md
<input type="text" class="input-field" placeholder="Enter value" />
</div>

<!-- Large Input -->
<div class="input input-lg">
  <div class="input-border"></div>
  <input type="text" class="input-field" placeholder="Enter value" />

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-components.md (reported line 1611)May include surrounding context.

md
<div class="tab-item" data-tab="tab3" data-text="Tab 3">Tab 3</div>
</div>

<!-- Tab panels — data-tab-panel value must match data-tab on the trigger -->
<div data-tab-panel="tab1" data-tab-group="demo">Panel 1</div>
<div data-tab-panel="tab2" data-tab-group="demo" style="display:none;">
  Panel 2

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-widgets.md (reported line 346)May include surrounding context.

Template

html
<!-- Chart Card — copy this structure exactly -->
<div class="widget-card">
  <div class="widget-title">
    <span class="widget-title-text">Chart Title</span>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-widgets.md (reported line 354)May include surrounding context.

md
<!-- optional -->
  </div>
  <div class="chart-body chart-dotted-background">
    <!-- optional: HTML legend (use when ECharts legend is insufficient) -->
    <div class="chart-legend">
      <div class="legend-item">
        <span class="legend-line" style="background:#5f75c9;"></span>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-widgets.md (reported line 592)May include surrounding context.

md
class="widget-body"
    style="background:var(--grey-g01);padding:var(--spacing-l);flex-direction:column;align-items:flex-start;"
  >
    <!-- Single Metric -->
    <div style="font-size:11px;color:var(--text-n7);letter-spacing:0.11px;">
      Label
    </div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-widgets.md (reported line 674)May include surrounding context.

md
<div class="table-cell">Side</div>
      <div class="table-cell">Quantity</div>
    </div>
    <!-- Body rows -->
    <div class="table-row table-body-row">
      <div class="table-cell">AAPL</div>
      <div class="table-cell">LONG</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-widgets.md (reported line 1080)May include surrounding context.

Youtube thumbnails show a play button.

html
<!-- Feed Card (Podcast / Youtube / News) — copy this structure exactly -->
<div class="widget-card">
  <div class="widget-title">
    <span class="widget-title-text">Feed Title</span>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-widgets.md (reported line 1115)May include surrounding context.

md
</div>
          </div>
        </div>
        <!-- optional thumbnail (Podcast / Youtube get play button) -->
        <div class="feed-thumb">
          <img src="thumb.jpg" alt="" />
          <img

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-widgets.md (reported line 1125)May include surrounding context.

md
/>
        </div>
      </div>
      <!-- Youtube item (avatar = CDN platform logo, no-radius) -->
      <div class="feed-item">
        <div class="feed-item-main">
          <div class="feed-header">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-widgets.md (reported line 1258)May include surrounding context.

Template — Reddit

html
<!-- Feed Card (Reddit) — copy this structure exactly -->
<div class="feed-item">
  <div class="feed-item-main">
    <div class="feed-header">

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/version_check.sh (reported line 10)May include surrounding context.

sh
REPO="alva-ai/skills"
SKILL_MD="$SKILL_DIR/SKILL.md"
CONFIG_FILE="$SKILL_DIR/.env"
CHECK_INTERVAL=28800 # 8 hours in seconds

# Read version from SKILL.md frontmatter (metadata.version)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/version_check.sh (reported line 22)May include surrounding context.

sh
sed -n 's/^[[:space:]]*version:[[:space:]]*\(.*\)/\1/p' "$SKILL_MD" 2>/dev/null | head -1
}

# Load last_check timestamp from .env
last_check=0
if [ -f "$CONFIG_FILE" ]; then
  last_check=$(sed -n 's/^last_check=\(.*\)/\1/p' "$CONFIG_FILE" 2>/dev/null | head -1 || echo "0")

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

Although the script is not stealing credentials, rewriting a shared .env file is security-relevant because .env commonly stores secrets and local configuration. Replacing the file via temp file + mv can accidentally alter permissions, clobber formatting/comments, or overwrite concurrent user changes, potentially causing secret loss or configuration corruption in a finance-related skill where environment files may be sensitive.

Content

Scanner excerpt · scripts/version_check.sh (reported line 45)May include surrounding context.

sh
exit 0 # Network error or no releases, skip silently
fi

# Update last_check timestamp in .env
# Use a tmpfile rewrite instead of `sed -i` — BSD and GNU sed disagree on the
# -i flag's argument form, and the portable approach avoids that pitfall.
tmp_config=$(mktemp 2>/dev/null || echo "${CONFIG_FILE}.tmp.$$")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/version_check.sh (reported line 70)May include surrounding context.

sh
Update with one of:
  npx skills add https://github.com/alva-ai/skills/tree/${remote_tag}/skills/alva --skill alva -y
  clawhub update alva
  git clone --branch ${remote_tag} --depth 1 https://github.com/alva-ai/skills ./tmp/alva-skills && cp -r ./tmp/alva-skills/skills/alva/* "${SKILL_DIR}/" && rm -rf ./tmp/alva-skills
EOF
fi

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/version_check.sh (reported line 70)May include surrounding context.

sh
Update with one of:
  npx skills add https://github.com/alva-ai/skills/tree/${remote_tag}/skills/alva --skill alva -y
  clawhub update alva
  git clone --branch ${remote_tag} --depth 1 https://github.com/alva-ai/skills ./tmp/alva-skills && cp -r ./tmp/alva-skills/skills/alva/* "${SKILL_DIR}/" && rm -rf ./tmp/alva-skills
EOF
fi

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · templates/ai-digest/template.md (reported line 1118)May include surrounding context.

md
budgets and citation discipline spelled out, (5) a final self-check
("count words, verify citations are 1-indexed and contiguous"). The
self-check goes last because models follow checklists best when they
sit immediately before the output instruction.

### 14.3 Server-side gates after `ask()`

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/screener/example/index.html (reported line 1114)May include surrounding context.

html
</head>
<body>

<!-- ═══════════════ PLAYBOOK INFO ═══════════════ -->
<div class="playbook-container">
  <!-- Tabs -->
  <div class="tab-wrapper">

Static analysis

No suspicious patterns detected.