Back to skill

Security audit

A Stock Analysis Conflict

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent A-share stock analysis and local portfolio tool, with expected network market-data access and disclosed local portfolio storage.

Install only if you are comfortable storing your tracked holdings locally at ~/.clawdbot/skills/a-stock-analysis/portfolio.json and sending requested stock codes to Sina Finance market-data endpoints. On shared machines, consider tightening permissions on the portfolio directory and file because the script relies on default filesystem permissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/portfolio.py:30
Finding

Portfolio File Created Without Explicit Restrictive Permissions

Content
View full analysis
dict: """加载持仓数据""" if PORTFOLIO_FILE.exists(): with open(PORTFOLIO_FILE, "r", encoding="utf-8") as f: return json.load(f) return {"positions": [], "updated_at": None} def save_portfolio(data: dict): """保存持仓数据""" PORTFOLIO_FILE.parent.mkdir(parents=True, exist_ok=True) data["updated_at"] = datetime.now().isoformat() with open(PORTFOLIO_FILE, "w", encoding="utf-8") as f: json.dump(data, f, ensure_ascii=False, indent=2) ``` ### Technical Analysis The portfolio file stores financial information including stock identifiers, acquisition costs, quantities, names, and timestamps. The application creates the containing directories and file without explicitly setting restrictive permissions. Consequently, permissions are determined by the process umask and any permissions already present on the parent directories or portfolio file. In an environment with a permissive umask or incorrectly configured home-directory permissions, the resulting `portfolio.json` may be readable by other local users. Opening an existing file with mode `"w"` does not correct insecure permissions already assigned to that file. The implementation also writes directly to the destination rather than creating a securely permissioned temporary file and atomically replacing the original. ### Attack Path 1. A user runs `portfolio.py add`, `portfolio.py update`, or `portfolio.py analyze`, causing `save_portfolio()` to create or update the portfolio file. 2. The process executes under a permissive umask, or the portfolio file already has group-readable or world-readable permissions. 3. Another local accou ...[truncated 962 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents commands that add, update, and remove portfolio entries, but it does not clearly warn users at the point of use that these operations persist changes to a local file and that remove is destructive. In an agent setting, unclear disclosure around local state mutation can lead to unintended file writes or data loss when a user expects read-only analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring, usage text, CLI description, help strings, and output formatting are all presented only in Chinese, which effectively imposes a specific language on users. The file does not offer an opt-in language selection or explain that the skill is intentionally region- or language-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file consistently presents the skill in Chinese and does not indicate that language selection is optional or that the skill is intentionally restricted to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code persistently writes the user's stock holdings to ~/.clawdbot/skills/a-stock-analysis/portfolio.json, which affects user data on disk. While the function has an internal docstring, there is no explicit user-facing warning at the write site or CLI flow that commands will modify and store portfolio data locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.