Back to skill

Security audit

A Stock Analysis.Bak

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward A-share stock analysis and local portfolio helper, with privacy cautions around local plaintext portfolio storage and external market-data lookups.

Install only if you are comfortable storing portfolio positions, cost basis, quantities, and timestamps in a plaintext local file. On shared machines, restrict permissions on ~/.clawdbot/skills/a-stock-analysis and portfolio.json, keep backups if the remove command matters to you, and expect live analysis to contact Sina Finance with the stock codes being queried.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/portfolio.py:31
Finding

Portfolio Data Stored Without Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly documents a delete operation for a local portfolio file but provides no warning, confirmation guidance, backup advice, or indication that local state will be modified. In an agent setting, users may invoke documented commands through automation or with incomplete understanding, which can lead to unintended loss of portfolio data stored under the user's home directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions and description appear to require Chinese comprehension, but the file does not state that the skill is Chinese-only or offer an alternative language/locale option. The policy requires avoiding forced language constraints unless the locale limitation is explicit and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language strings that enforce a specific language/locale for usage instructions and interaction. Under the policy, forcing a specific language without user opt-in is a reportable natural-language policy violation unless the locale constraint is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persists sensitive portfolio holdings, costs, and quantities to a predictable file under the user's home directory without any explicit notice, consent, or controls. While this is not code execution or direct exfiltration, it creates a privacy risk because financial data remains on disk and may be accessible to other local processes, backups, or shared accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The analyze command sends stock codes from the user's portfolio into another analysis module without clearly disclosing that portfolio identifiers will be processed externally. In this skill context, the downstream module may call external services, so undisclosed transmission can leak trading interests or holdings metadata even if only stock codes are shared.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.