Back to skill

Security audit

Stock Market Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a purpose-aligned stock research tool, but its optional options-flow path runs headless browser scraping with Chromium sandbox disabled and has under-scoped install/runtime risks users should review.

Install only if you are comfortable with a finance tool that downloads Python dependencies at runtime, contacts Yahoo Finance/DuckDuckGo/Unusual Whales, and may run a headless browser for options data. Prefer running it in an isolated environment, avoid the `option` scraper unless needed, keep TLS verification enabled, and treat generated `/tmp` chart files as overwrite-prone.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Error
Location
scripts/yf.py:2
Finding

Unpinned Runtime Dependencies Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/yf.py:143
Finding

Predictable User-Influenced Temporary Chart Paths

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ddg_search.py:75
Finding

Search Helper Permits TLS Certificate Verification Bypass

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/uw.py:58
Finding

Remote Web Content Is Processed by Chromium with Sandbox Disabled

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the implementation uses browser automation or scraping against external sites such as Unusual Whales while the skill is presented primarily as a Yahoo Finance/yfinance tool, the discrepancy materially changes the risk profile. Browser automation and third-party scraping introduce additional network, session, legal/compliance, and data-handling risks that are not apparent from the declared scope, so operators may grant trust or permissions they would not otherwise allow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation uses browser automation or scraping against external sites such as Unusual Whales while the skill is presented primarily as a Yahoo Finance/yfinance tool, the discrepancy materially changes the risk profile. Browser automation and third-party scraping introduce additional network, session, legal/compliance, and data-handling risks that are not apparent from the declared scope, so operators may grant trust or permissions they would not otherwise allow.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises shell-based execution (uv run, python3) but does not declare any explicit tool scope or allowed-tools restrictions. That creates an authorization and review gap: an agent may invoke shell commands and network-capable scripts without clear policy boundaries, increasing the chance of unintended command execution or external access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI sets --region to kr-kr by default, which imposes a specific locale on all searches unless the user overrides it. This is a natural-language policy concern because it silently enforces a language/locale preference without offering explicit opt-in or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/news.py (reported line 46)May include surrounding context.

python
"--out",
        "md",
    ]
    return subprocess.call(cmd)


if __name__ == "__main__":

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes the skill as a Yahoo Finance (yfinance) powered stock analysis skill with optional web add-ons for news and browser-first options/flow. This script's core behavior is Playwright-driven scraping of unusualwhales.com for option overview and live options flow, which is a materially different data source and implementation path than the manifest's primary Yahoo Finance framing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a stock analysis skill with optional web add-ons, but this file implements that feature by invoking another script via subprocess.run. Launching subprocesses is a materially broader capability than direct finance-data fetching/rendering and is not justified by the stated purpose itself.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/yf.py (reported line 324)May include surrounding context.

python
if cmd == "option":
        uw_path = f"{os.path.dirname(__file__)}/uw.py"
        try:
            cp = subprocess.run(
                ["python3", uw_path, symbol],
                capture_output=True,
                text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/yf.py (reported line 353)May include surrounding context.

python
if cmd == "option":
        uw_path = f"{os.path.dirname(__file__)}/uw.py"
        try:
            cp = subprocess.run(
                ["python3", uw_path, symbol],
                capture_output=True,
                text=True,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Creating a yfinance Ticker object and accessing ticker.info retrieves remote market data over the network. Although network access is central to the tool's purpose, the code provides no explicit notice in its CLI description or runtime output that it will contact an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script saves generated chart output to a filesystem path under /tmp, which is a file-writing operation. There is no confirmation prompt, warning comment, or user-facing disclosure before this write occurs, so users may not realize the skill creates persistent local files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.