Back to skill

Security audit

Finnhub Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small Finnhub stock-quote helper with one ordinary supply-chain caution about an unpinned Python dependency.

Before installing, consider pinning `finnhub-python` to a reviewed version and using a virtual environment. The skill needs a Finnhub API key and network access to Finnhub to work; do not run it with broader environment secrets than necessary.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 6
Vulnerability Type: Unpinned third-party package installation
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- Finnhub pip package `pip3 install finnhub-python`

Technical Analysis

The installation instructions retrieve and install finnhub-python from the configured Python package index without specifying an exact version or verifying an integrity hash. Consequently, the code installed by users may change after the Skill has been reviewed.

Python packages can execute code during installation and whenever imported. The application imports this dependency at scripts/app.py:4 and supplies the Finnhub API key to it at scripts/app.py:9. Therefore, a compromised or unexpectedly modified future release could execute with the user's privileges and access data available to the application process.

This finding concerns insufficient dependency reproducibility and integrity controls. The audited repository itself contains no evidence that the named package is currently malicious.

Attack Path

  1. An attacker compromises the upstream package, its maintainer account, or the package-index delivery path and publishes a malicious release under the legitimate package name.
  2. A user follows the documented pip3 install finnhub-python instruction.
  3. Because no version or hash is specified, pip resolves and installs the attacker-controlled release.
  4. Malicious code may execute during installation or when scripts/app.py imports finnhub.
  5. The dependency runs with the invoking user's privileges and may access the Finnhub API key provided to the client, along with other resources available to that process.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user performing the installation or running the script. The affected scope may include files, environment variables, netwo ...[truncated 283 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin finnhub-python to an exact, reviewed version rather than allowing pip to select the latest release.
  • Store dependency declarations in a version-controlled requirements or lock file.
  • Generate and enforce package hashes, for example with pip install --require-hashes -r requirements.txt.
  • Obtain packages only from a trusted, explicitly configured package index.
  • Review dependency updates before changing the pinned version and use automated vulnerability and provenance checks in CI.
  • Install the dependency in an isolated virtual environment under a non-privileged account.
  • Document a reproducible installation command, such as:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.