Back to skill

Security audit

ValueSider Superinvestor Data

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public ValueSider portfolio pages and parses them locally, with only low-risk dependency and scoping notes.

Before installing, consider pinning dependencies or using a locked virtual environment. Expect the skill to fetch public pages from valuesider.com and parse saved page text; it should not need account credentials, persistent background access, or administrative privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Package Versions

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2
Vulnerability Type: Supply-chain risk caused by mutable dependency constraints
Risk Level: Low

text
requests>=2.28.0
beautifulsoup4>=4.11.0

The installation instructions invoking this file appear in README.md:7-10 and SKILL.md:73.

Technical Analysis

Both dependencies specify only minimum versions and provide no upper bounds, lock file, or cryptographic hashes. Consequently, the documented installation command can resolve to package releases that did not exist when the Skill was audited.

The package names are legitimate and no malicious dependency was identified. The risk arises from non-reproducible dependency resolution: a future compromised, malicious, or incompatible release accepted by these constraints could be downloaded from the configured package index. Installation from a malicious source distribution may execute attacker-controlled build logic, while malicious installed package code may execute when fetch_valuesider.py imports requests and bs4.

Attack Path

  1. An attacker compromises a permitted future release of requests or beautifulsoup4, or compromises the package index or dependency-resolution channel used by the operator.
  2. The operator follows the documented pip install -r requirements.txt instruction.
  3. Because the requirements accept any version at or above the stated minimum, pip resolves and downloads the attacker-controlled release.
  4. Malicious code executes during package build/installation or when the Skill imports the installed package.
  5. The payload operates with the privileges of the account running pip or the Skill.

This attack requires an upstream package, package-index, or dependency-distribution compromise; no direct exploitation path exists solely through ordinary Skill input.

Impact Assessment

Successful exploitation could allow arbitrary code execution under t ...[truncated 439 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin each dependency to a reviewed exact version rather than using lower-bound-only constraints.
  • Generate and commit a lock file containing all transitive dependencies.
  • Record and enforce package hashes, such as by using pip install --require-hashes -r requirements.txt.
  • Obtain packages only from a trusted, explicitly configured package index over TLS.
  • Use automated dependency monitoring and update pins only after reviewing release notes and security advisories.
  • Install dependencies in an isolated virtual environment with an unprivileged account.
  • Avoid running the documented installation command as root or with administrative privileges.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README indicates the skill may trigger on broad terms like 持仓 / 13F / ValueSider / 某基金经理, which can cause invocation on generic finance queries rather than only explicit requests for ValueSider or superinvestor data. Over-broad triggering increases the chance the agent fetches external content unnecessarily, producing unintended network access, irrelevant results, or misuse of the skill in contexts the user did not intend.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to perform network fetches and read/write temporary files, but it does not declare any explicit tool scope such as allowed-tools or permissions. This creates an authorization gap: a host system may grant broader capabilities than intended, and reviewers cannot easily verify that the skill is limited to the minimum necessary access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill documentation is entirely written in Chinese and instructs usage through Chinese example prompts, without indicating that users may interact in other languages or choose their preferred locale. This can constitute a language/locale policy issue when no opt-in or documented locale restriction is provided.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency specification uses a lower-bound range (requests>=2.28.0) instead of pinning to a specific version, which makes builds non-reproducible and can unexpectedly pull in vulnerable or breaking releases. In a skill that fetches external web data, dependency behavior matters because HTTP handling is security-sensitive and upstream package changes can affect request validation, redirects, or credential handling.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0
beautifulsoup4>=4.11.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The manifest does not pin requests, and that package has multiple known advisories across versions, so it is impossible to verify from this file whether deployments will install a safe release. In a network-facing data-fetching skill, this uncertainty is meaningful because requests directly handles outbound HTTP interactions and could expose the skill to known client-side issues if an affected version is resolved.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

beautifulsoup4>=4.11.0 is also unpinned, so installations may resolve to different versions over time, reducing reproducibility and increasing supply-chain risk if a future version introduces a vulnerability or incompatible parsing behavior. Since this skill parses third-party website content, parser behavior changes can affect safety and robustness.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.28.0
beautifulsoup4>=4.11.0

Static analysis

No suspicious patterns detected.