Back to skill

Security audit

Global Stock Analysis

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent financial-market analysis skill, but users should be careful because it installs and runs an unpinned external CLI package.

Install only if you trust the marketdata-cli package and Alpha Vantage source. Prefer pinning a reviewed version in your own environment, avoid --force unless you intend to replace an existing install, and expose only the Alpha Vantage API key needed for the requested command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 4, 14, and 27
Vulnerability Type: Unpinned external dependency and unsafe supply-chain execution
Risk Level: Medium

Vulnerable Code

yaml
compatibility: Requires marketdata-cli installed (pip install marketdata-cli) and ALPHAVANTAGE_API_KEY set.
yaml
install: "pip install marketdata-cli"
markdown
1. Install: `pip install marketdata-cli` or `uv tool install marketdata-cli --force` or run directly with `uvx marketdata-cli`

Technical Analysis

The Skill instructs users or agents to install or immediately execute the externally maintained marketdata-cli package without specifying an exact version, cryptographic hash, lockfile, signed artifact, or other integrity control. Consequently, the code executed can change after this Skill has been reviewed.

The uvx marketdata-cli option can resolve and execute the current package directly, while uv tool install marketdata-cli --force can replace an existing installation. The project does not include the dependency's implementation, so the behavior of the installed executable cannot be verified from the audited files.

This constitutes a supply-chain weakness rather than evidence that the current package is malicious. Exploitation would require compromise of the package registry, maintainer account, distribution artifact, dependency resolution process, or a future package release.

Attack Path

  1. An attacker compromises the package publication channel, maintainer account, or a transitive dependency used by marketdata-cli.
  2. The attacker publishes a malicious version under the package name that the unpinned installation commands resolve.
  3. A user or agent follows the documented setup command using pip, uv tool, or uvx.
  4. The package is installed or executed with the permissions of that user.
  5. Malicious package code reads accessible files, environment varia ...[truncated 879 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin marketdata-cli to a reviewed exact version in every installation and execution example.
  2. Require cryptographic hash verification through a constraints or requirements file using hash-checking mode.
  3. Commit a lockfile that records resolved transitive dependency versions and integrity metadata.
  4. Avoid uvx execution without an explicit version because it may retrieve and run a different release over time.
  5. Remove --force unless replacement of an existing installation is explicitly required and approved.
  6. Document the canonical package registry, publisher identity, source repository, and expected package checksums.
  7. Install and run the dependency in an isolated, least-privilege virtual environment or container.
  8. Restrict the process environment so it receives only the Alpha Vantage credential and resources required for the requested operation.
  9. Review and update the pinned version through a controlled dependency-update process that includes source review, malware scanning, and integrity validation.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill recommends running uvx marketdata-cli without pinning an exact package version, which can cause users to execute whatever version is current at install time. If the upstream package is compromised, a malicious release is published, or a breaking change introduces unsafe behavior, users may unintentionally run unreviewed code in their local environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes this skill as focused on global stock analysis across US, China, and EU stock markets, including technical and fundamental analysis. This file instead documents forex exchange rates and cryptocurrency price-history operations, which are materially different asset classes and broaden the skill's behavior beyond the stated stock-market scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description at L003 frames the skill as 'Global stock analysis' focused on US, China, and EU stock markets. However, the documented workflows explicitly extend the skill to foreign exchange and cryptocurrencies, which are distinct asset classes outside a plain-language stock-analysis scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The stated purpose in the manifest is stock analysis with technical and fundamental coverage. The documented options workflows add derivatives analysis, including greeks, options fair market value, and put/call ratios, which materially broaden the capability beyond the manifest's stated stock-analysis scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.