T09 · Insecure Skill Coding Practices
- Location
scripts/portfolio.py:31- Finding
Portfolio Data Stored Without Restrictive File Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a straightforward A-share stock analysis and local portfolio helper, with privacy cautions around local plaintext portfolio storage and external market-data lookups.
Install only if you are comfortable storing portfolio positions, cost basis, quantities, and timestamps in a plaintext local file. On shared machines, restrict permissions on ~/.clawdbot/skills/a-stock-analysis and portfolio.json, keep backups if the remove command matters to you, and expect live analysis to contact Sina Finance with the stock codes being queried.
scripts/portfolio.py:31Portfolio Data Stored Without Restrictive File Permissions
The skill explicitly documents a delete operation for a local portfolio file but provides no warning, confirmation guidance, backup advice, or indication that local state will be modified. In an agent setting, users may invoke documented commands through automation or with incomplete understanding, which can lead to unintended loss of portfolio data stored under the user's home directory.
The natural-language instructions and description appear to require Chinese comprehension, but the file does not state that the skill is Chinese-only or offer an alternative language/locale option. The policy requires avoiding forced language constraints unless the locale limitation is explicit and justified.
This Python file contains natural-language strings that enforce a specific language/locale for usage instructions and interaction. Under the policy, forcing a specific language without user opt-in is a reportable natural-language policy violation unless the locale constraint is clearly justified.
The script persists sensitive portfolio holdings, costs, and quantities to a predictable file under the user's home directory without any explicit notice, consent, or controls. While this is not code execution or direct exfiltration, it creates a privacy risk because financial data remains on disk and may be accessible to other local processes, backups, or shared accounts.
The analyze command sends stock codes from the user's portfolio into another analysis module without clearly disclosing that portfolio identifiers will be processed externally. In this skill context, the downstream module may call external services, so undisclosed transmission can leak trading interests or holdings metadata even if only stock codes are shared.
No suspicious patterns detected.