Back to skill

Security audit

Today Earnings

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for fetching public Yahoo Finance earnings data, but its installed native host exposes an unauthenticated local socket that other local processes can abuse.

Install only if you are comfortable adding a Chrome extension plus a local Native Messaging host. Prefer a version that places its Unix socket in a user-private directory, authenticates or validates local requests, limits request sizes, and avoids the deprecated apt-key sudo pipeline in the Ubuntu instructions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
native-host/host.js:21
Finding

Unauthenticated and Unbounded Local Unix Socket Interface

Content
View full analysis
{ let buf = ''; socket.on('data', (data) => { buf += data.toString('utf8'); // Newline-delimited framing const nl = buf.indexOf('\n'); if (nl === -1) return; const line = buf.slice(0, nl).trim(); buf = buf.slice(nl + 1); let request; try { request = JSON.parse(line); } catch (_) { socket.write( JSON.stringify({ ok: false, error: { code: 'INVALID_REQUEST', message: 'Invalid JSON' } }) + '\n' ); socket.end(); return; } const id = ++requestIdCounter; pendingRequests.set(id, socket); // Forward to the Chrome extension sendToExtension({ ...request, _id: id }); }); // Disconnect after 60 seconds without a response socket.setTimeout(60000, () => socket.destroy()); socket.on('error', () => {}); }); socketServer.listen(SOCKET_PATH, () => { // Unix socket is ready for CLI connections }); socketServer.on('error', (err) => { process.stderr.write(`Socket server error: ${err.message}\n`); process.exit(1); }); } ``` ### Technical Analysis The Native Messaging host exposes a Unix socket at the fixed, predictable path `/tmp/today-earnings.sock`. The server does not explicitly create the socket inside a user-private runtime directory, set a restrictive socket mode, authenticate clients, or verify peer identity. Any local process that can access the socket may submit messages directly, bypa ...[truncated 2982 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (25)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · native-host/install.sh (reported line 275)May include surrounding context.

sh
echo "提示(Ubuntu):"
  echo "  - 如果你使用的是 snap 版 Chromium(Ubuntu 22.04+ 默认),"
  echo "    Native Messaging 支持受限,建议改用 deb 版 Google Chrome:"
  echo "    wget -q -O - https://dl.google.com/linux/linux_signing_key.pub | sudo apt-key add -"
  echo "    sudo sh -c 'echo deb [arch=amd64] http://dl.google.com/linux/chrome/deb/ stable main > /etc/apt/sources.list.d/google-chrome.list'"
  echo "    sudo apt-get update && sudo apt-get install google-chrome-stable"

Chaining Abuse

High
Category
Tool Misuse
Confidence
82% confidence
Finding

Piping network-fetched data directly into a privileged command ('wget ... | sudo apt-key add -') is dangerous because it grants root-trust material based on unverified remote content at execution time. If the download source, transport trust, or user environment is compromised, an attacker could cause the system to trust malicious packages or repositories.

Content

Scanner excerpt · references/usage_guide.md (reported line 61)May include surrounding context.

Ubuntu 注意: Ubuntu 22.04+ 默认的 snap 版 Chromium 不支持 Native Messaging。建议安装 deb 版 Google Chrome:

bash
wget -q -O - https://dl.google.com/linux/linux_signing_key.pub | sudo apt-key add -
sudo sh -c 'echo deb [arch=amd64] http://dl.google.com/linux/chrome/deb/ stable main > /etc/apt/sources.list.d/google-chrome.list'
sudo apt-get update && sudo apt-get install google-chrome-stable

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · native-host/install.sh (reported line 277)May include surrounding context.

sh
```bash
wget -q -O - https://dl.google.com/linux/linux_signing_key.pub | sudo apt-key add -
sudo sh -c 'echo deb [arch=amd64] http://dl.google.com/linux/chrome/deb/ stable main > /etc/apt/sources.list.d/google-chrome.list'
sudo apt-get update && sudo apt-get install google-chrome-stable
```

#### Windows

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/usage_guide.md (reported line 63)May include surrounding context.

bash
wget -q -O - https://dl.google.com/linux/linux_signing_key.pub | sudo apt-key add -
sudo sh -c 'echo deb [arch=amd64] http://dl.google.com/linux/chrome/deb/ stable main > /etc/apt/sources.list.d/google-chrome.list'
sudo apt-get update && sudo apt-get install google-chrome-stable

Windows

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation instructs users to run shell commands, install a native host, launch Chrome, and execute local scripts, but it does not declare any tool scope such as permissions or allowed-tools. This creates a trust and review gap: an agent or user may enable shell-capable behavior without explicit least-privilege boundaries, increasing the chance of unintended command execution or abuse if surrounding files/scripts are modified or malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description and operational instructions are presented entirely in Chinese, which effectively imposes a specific language on users. Under the policy, language constraints should either be optional or clearly justified; this file does not offer an alternative language or user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The background script opens a remote Yahoo Finance page, extracts its contents via a content script, and forwards the data to a native host process with no user-visible prompt or per-request consent in this file. In a Chrome Extension + Native Messaging design, that creates a cross-boundary data flow from web content into a local process; if the request source or extracted scope expands, it can become a covert collection channel or expose local trust to remote content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JavaScript file contains natural-language comments and at least one user-facing error message entirely in Chinese, including the timeout message returned to the caller. Under the policy rules, forcing a specific language without offering user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · native-host/install.sh (reported line 96)May include surrounding context.

sh
local wrapper="$3"
  if ! mkdir -p "$dir" 2>/dev/null; then
    echo "错误: 无法创建目录 $dir(权限不足或路径无效)" >&2
    echo "  提示: 确认当前用户对该路径有写入权限,或使用 sudo 执行。" >&2
    exit 1
  fi
  local manifest_path="$dir/com.today.earnings.host.json"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · native-host/install.sh (reported line 275)May include surrounding context.

sh
local wrapper="$3"
  if ! mkdir -p "$dir" 2>/dev/null; then
    echo "错误: 无法创建目录 $dir(权限不足或路径无效)" >&2
    echo "  提示: 确认当前用户对该路径有写入权限,或使用 sudo 执行。" >&2
    exit 1
  fi
  local manifest_path="$dir/com.today.earnings.host.json"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · native-host/install.sh (reported line 276)May include surrounding context.

sh
local wrapper="$3"
  if ! mkdir -p "$dir" 2>/dev/null; then
    echo "错误: 无法创建目录 $dir(权限不足或路径无效)" >&2
    echo "  提示: 确认当前用户对该路径有写入权限,或使用 sudo 执行。" >&2
    exit 1
  fi
  local manifest_path="$dir/com.today.earnings.host.json"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · native-host/install.sh (reported line 277)May include surrounding context.

sh
local wrapper="$3"
  if ! mkdir -p "$dir" 2>/dev/null; then
    echo "错误: 无法创建目录 $dir(权限不足或路径无效)" >&2
    echo "  提示: 确认当前用户对该路径有写入权限,或使用 sudo 执行。" >&2
    exit 1
  fi
  local manifest_path="$dir/com.today.earnings.host.json"

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · native-host/install.sh (reported line 167)May include surrounding context.

sh
echo.

echo [1/2] 注册 Google Chrome Native Messaging Host...
REG ADD "HKCU\Software\Google\Chrome\NativeMessagingHosts\com.today.earnings.host" ^
    /ve /t REG_SZ /d "%MANIFEST_PATH%" /f
if %ERRORLEVEL% NEQ 0 (
  echo   警告: Chrome 注册失败(可能未安装 Chrome)

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · native-host/install.sh (reported line 177)May include surrounding context.

sh
echo.

echo [1/2] 注册 Google Chrome Native Messaging Host...
REG ADD "HKCU\Software\Google\Chrome\NativeMessagingHosts\com.today.earnings.host" ^
    /ve /t REG_SZ /d "%MANIFEST_PATH%" /f
if %ERRORLEVEL% NEQ 0 (
  echo   警告: Chrome 注册失败(可能未安装 Chrome)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing natural-language instructions exclusively in Chinese, and nowhere indicates that the skill is intended only for Chinese-speaking users or provides an opt-in/alternative language. Under the language/locale policy, forcing a specific language without user choice is a policy concern.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/usage_guide.md (reported line 61)May include surrounding context.

Ubuntu 注意: Ubuntu 22.04+ 默认的 snap 版 Chromium 不支持 Native Messaging。建议安装 deb 版 Google Chrome:

bash
wget -q -O - https://dl.google.com/linux/linux_signing_key.pub | sudo apt-key add -
sudo sh -c 'echo deb [arch=amd64] http://dl.google.com/linux/chrome/deb/ stable main > /etc/apt/sources.list.d/google-chrome.list'
sudo apt-get update && sudo apt-get install google-chrome-stable

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/usage_guide.md (reported line 62)May include surrounding context.

Ubuntu 注意: Ubuntu 22.04+ 默认的 snap 版 Chromium 不支持 Native Messaging。建议安装 deb 版 Google Chrome:

bash
wget -q -O - https://dl.google.com/linux/linux_signing_key.pub | sudo apt-key add -
sudo sh -c 'echo deb [arch=amd64] http://dl.google.com/linux/chrome/deb/ stable main > /etc/apt/sources.list.d/google-chrome.list'
sudo apt-get update && sudo apt-get install google-chrome-stable

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/usage_guide.md (reported line 63)May include surrounding context.

Ubuntu 注意: Ubuntu 22.04+ 默认的 snap 版 Chromium 不支持 Native Messaging。建议安装 deb 版 Google Chrome:

bash
wget -q -O - https://dl.google.com/linux/linux_signing_key.pub | sudo apt-key add -
sudo sh -c 'echo deb [arch=amd64] http://dl.google.com/linux/chrome/deb/ stable main > /etc/apt/sources.list.d/google-chrome.list'
sudo apt-get update && sudo apt-get install google-chrome-stable

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's natural-language interface, including usage text, errors, and operational comments, is written in Chinese only. This can violate language/locale policy when no user opt-in or documented region-specific justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file's human-readable comments and protocol description are entirely in Chinese, which can impose a single language context on maintainers or operators without any stated opt-in or locale justification. Under the policy, language constraints should either offer choice or be explicitly documented as intentionally locale-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written only in Chinese ("从 Yahoo Finance 获取财报日历数据"), which indicates a language-specific presentation without any visible user opt-in or documentation that the extension is intended solely for a Chinese-speaking or region-specific audience. Under the policy, locale or language constraints should either be optional for the user or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file’s human-readable comments are entirely in Chinese, which imposes a specific language on maintainers or reviewers without any visible opt-in or documented locale constraint. Under the stated policy, forcing a language without user choice or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s explanatory comments and operational instructions are written in Chinese, which imposes a specific language choice in the skill’s natural-language content without indicating user choice or a documented locale-specific constraint. This matches the policy category for language or locale restrictions in natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire reference file is written in Chinese, including the title and operational guidance, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for language/locale, this is a natural-language constraint that should either be optional or explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code constructs a request containing the user-supplied date and sends it over a Unix socket to another local component. While the file comments describe prerequisites and usage, they do not clearly warn the user at execution time that invoking the script will contact a Native Host process and request earnings data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.