Back to skill

Security audit

CANSLIM-Top100-US

Security checks for vulnerabilities and agentic risk

Overview

This skill runs a disclosed stock-screening script that fetches public market data and writes local results, with the main caution being unpinned Python dependencies.

Install and run this only in a normal isolated Python environment, preferably with reviewed pinned dependency versions. Expect it to contact Wikipedia and market-data services through yfinance and to leave a local canslim_results.json file containing stock-screening output; do not treat the generated rankings as investment advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
Scripts/requirements.txt:1
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: Scripts/requirements.txt, lines 1-5; installation is directed by SKILL.md, lines 30-31
Vulnerability Type: Unpinned and unhashed third-party dependencies
Risk Level: Medium

Vulnerable code:

text
yfinance
pandas
lxml
tqdm
requests

The corresponding installation instruction in SKILL.md is:

markdown
2. If dependencies are missing, install them from `Scripts/requirements.txt`.

Technical Analysis

Every dependency is specified without an exact version or integrity hash. Consequently, package resolution may select different releases and transitive dependencies each time the skill is installed. The installed code has not necessarily undergone the same review as the audited project.

Python package installation can execute package-controlled build logic, while subsequent imports execute installed module code. If an upstream release, package account, distribution artifact, package index, or transitive dependency is compromised, malicious code could execute under the identity running the installation or analyzer. Unintentional breaking changes could also affect the integrity of generated financial results.

No evidence was found that the currently named packages are malicious. The vulnerability is the absence of controls ensuring that installations reproduce a reviewed dependency set.

Attack Path

  1. The skill runs in an environment where one or more required packages are unavailable.
  2. The agent follows SKILL.md and installs packages from Scripts/requirements.txt.
  3. The package resolver retrieves the latest dependency versions and their transitive dependencies rather than a reviewed, fixed set.
  4. An attacker who has compromised an upstream package release, maintainer account, distribution artifact, or dependency serves malicious package code.
  5. The malicious code executes during package build or installation, or when `analyzer. ...[truncated 753 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an exact, reviewed version, for example with package==x.y.z.
  2. Generate a lock file that fixes all transitive dependencies, using a tool such as pip-tools, Poetry, or an equivalent controlled dependency-management system.
  3. Record cryptographic hashes for all resolved distributions and install with hash verification, such as pip install --require-hashes -r requirements.txt.
  4. Prefer reviewed binary wheels from an explicitly configured trusted package index. Disable unintended extra indexes to reduce dependency-confusion exposure.
  5. Install packages inside a dedicated, non-privileged virtual environment rather than globally or as an administrator.
  6. Add automated dependency vulnerability and provenance checks to the release process.
  7. Update dependencies only through a controlled review process that regenerates the lock file and hashes, runs tests, and reviews security advisories.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill's declared purpose suggests a bounded Markdown analysis task, but its behavior includes executing code, writing JSON/CSV artifacts, and likely using external network sources that are not disclosed in the metadata. This mismatch is dangerous because reviewers or users may underestimate the operational risk, enabling unexpected code execution, supply-chain exposure from dependency installation, and data egress/ingress through third-party services.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to install dependencies, execute a local Python script, and consume generated output, which implies network and file-write capabilities without declaring any explicit tool scope or permissions. This is dangerous because it broadens the effective trust boundary: a caller may invoke what appears to be a simple analysis skill, while it can fetch remote packages/data and write files locally without transparent authorization.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill that returns a ranked shortlist in Markdown. The implementation serializes all results to a local canslim_results.json file and does not generate or return Markdown-formatted output, which is a direct mismatch in described behavior versus actual behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest frames the skill as analyzing the top 100 S&P 500 companies, while the code first fetches the full S&P 500 constituent list from Wikipedia and then derives the top 100 itself. Although related to the goal, this expands behavior beyond the plainly stated scope in the description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The inline comment says the function no longer calls stock.info, implying network-saving behavior, but the code still instantiates yf.Ticker(ticker) and requests history(period="1y"). The comment is therefore misleading about the function's actual external data access and side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script silently writes a results file to disk, which can violate least-surprise expectations for a skill and create unintended persistence of analysis output. In a hosted agent or multi-tenant environment, undisclosed filesystem writes may expose data handling risks, interfere with sandbox assumptions, or leave artifacts accessible to other components.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency list leaves yfinance unpinned, which makes builds non-reproducible and allows future installs to pull unexpected or compromised releases. While this file alone does not prove exploitation, unpinned dependencies are a real supply-chain hardening weakness because the resolved package version can change over time without review.

Content

Scanner excerpt · Scripts/requirements.txt (reported line 1)May include surrounding context.

text
yfinance
pandas
lxml
tqdm

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

pandas is unpinned, so installations may resolve to different versions across environments or over time. This increases supply-chain risk and makes it impossible to verify whether known vulnerable versions are excluded.

Content

Scanner excerpt · Scripts/requirements.txt (reported line 2)May include surrounding context.

text
yfinance
pandas
lxml
tqdm
requests

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Because pandas is not pinned, the manifest cannot demonstrate that a vulnerable version is excluded, so the dependency state is not verifiable. The cited advisory appears disputed and context-dependent, which lowers impact here, but the inability to verify installed versions is still a real security weakness.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

lxml is unpinned despite being a package with a history of security advisories, so the environment could install a vulnerable release. Because lxml often processes HTML/XML, using an unexpected version can materially increase exposure to parser or sanitizer-related flaws.

Content

Scanner excerpt · Scripts/requirements.txt (reported line 3)May include surrounding context.

text
yfinance
pandas
lxml
tqdm
requests

Unverifiable Dependency: lxml has 14 known advisory(ies) (CVE-2021-43818 (lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through); CVE-2014-3146 (lxml Cross-site Scripting Via Control Characters); CVE-2021-28957 (lxml vulnerable to Cross-Site Scripting ) +11 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
97% confidence
Finding

lxml has multiple historical advisories, and because no version is pinned, there is no assurance that deployment avoids affected releases. In a data-analysis skill that may fetch and parse remote content, this uncertainty is more concerning than for a purely local library because parser-related flaws can be reachable through external data.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

tqdm is unpinned, so dependency resolution can drift and unexpectedly introduce vulnerable or incompatible releases. Even though tqdm is often low-risk in typical use, leaving it unpinned still weakens build integrity and reproducibility.

Content

Scanner excerpt · Scripts/requirements.txt (reported line 4)May include surrounding context.

text
yfinance
pandas
lxml
tqdm
requests

Unverifiable Dependency: tqdm has 4 known advisory(ies) (CVE-2024-34062 (tqdm CLI arguments injection attack); CVE-2016-10075 (TDQM Arbitrary Code Execution); CVE-2016-10075 (The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to e) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

tqdm has known advisories in some versions, and without a version pin, the manifest cannot prove that a safe release will be installed. The practical danger depends heavily on how tqdm is used, so impact is limited here, but the unverifiable dependency state remains a valid supply-chain concern.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

requests is unpinned, which is risky because it is network-facing and has a long history of security advisories. An uncontrolled version may expose the skill to credential leakage, TLS, redirect, or request-handling flaws depending on the resolved release and usage in code.

Content

Scanner excerpt · Scripts/requirements.txt (reported line 5)May include surrounding context.

text
pandas
lxml
tqdm
requests

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
98% confidence
Finding

requests has numerous historical advisories, and the absence of version pinning means the environment may resolve to a release with known flaws. Given this skill likely retrieves market data over the network, an unverifiable requests version is more dangerous because network libraries directly mediate external input, redirects, TLS, and credential handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.