Back to skill

Security audit

Stock Analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a stock-analysis toolkit, but it handles X/Twitter session tokens and private portfolio reports with broader access and less user control than its main description discloses.

Install only if you are comfortable with a financial-analysis skill that can store local portfolio data, call external market and social-data services, and optionally use X/Twitter session cookies. Avoid enabling the Twitter/X scanners unless bird is pinned or isolated and only AUTH_TOKEN and CT0 are passed to it. Review or remove the Feishu daily-review scripts before use, especially if your OpenClaw workspace contains private portfolio data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hot_scanner.py:22
Finding

Third-Party X/Twitter CLI Receives the Complete Process Environment

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:152
Finding

Unpinned Globally Installed Dependency Handles Authentication Credentials

Content
View full analysis
Remediation
View remediation
``` 2. Use a project-local installation and lockfile instead of `npm install -g`. 3. Commit and verify the package lockfile and registry integrity metadata. 4. Document the expected publisher, repository, version, and executable checksum. 5. Review the package before version updates and use automated dependency monitoring. 6. Run the executable with a minimal allowlisted environment. 7. Where possible, isolate it in a sandbox or container with restricted filesystem and network access. 8. Clearly disclose that the package receives account session credentials. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/daily_review_auto.py:77
Finding

Hard-Coded Agent Workspace Access Stages Private Portfolio Data for External Delivery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/daily_review_auto.py:58
Finding

Financial Market Data Is Retrieved over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (81)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The file directs users to store Twitter/X session tokens in a local .env file, which is a credential-handling pattern that can lead to account compromise if the file is committed, logged, copied, or otherwise exposed. Because the referenced values are session-grade tokens rather than low-scope API keys, leakage could allow unauthorized use of the user's Twitter/X account until the tokens are revoked or expire.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function docstring says it calculates put/call ratio from the options chain, implying it works from the provided StockData object. However, the implementation accesses data.ticker_obj, a field that does not exist on the StockData dataclass, so the documented capability is not actually supported by the provided object model and will fail into the exception path.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Accessing a repository-local .env file can expose credentials and secrets beyond what this scanner actually needs. In context, that access is more sensitive because the values are promoted into process-wide environment state and may later be inherited by a child subprocess.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The code conditionally opens and parses the .env file, which is a form of credential access not clearly justified for all scan modes. This broad secret ingestion enlarges exposure if logs, exceptions, or subprocesses later touch the environment.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
96% confidence
Finding

Using os.environ.copy() forwards the entire process environment to the external bird CLI, which may include API keys, tokens, cloud credentials, proxies, or other secrets loaded from .env or the host environment. Because the child process is a separately installed binary discovered partly via PATH fallback, this materially increases the chance of credential exposure or abuse if that binary is malicious, replaced, or compromised.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The code is explicitly designed to access a .env file containing credentials for an external service. In isolation that can be legitimate, but in this skill it becomes security-relevant because those credentials are later loaded into the environment and supplied to a subprocess, increasing exposure risk.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The load_env routine reads and parses every key-value line from .env and places them into process environment variables. This is dangerous because it normalizes unrestricted credential access and sets up later leakage to subprocesses and potentially other libraries running in the same process.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

Copying the full process environment immediately before launching an external CLI risks forwarding unrelated secrets to that child process, including credentials loaded from .env and any ambient agent tokens. In an agent environment, this broad secret propagation materially increases the blast radius if the external tool logs, crashes, or transmits environment-derived data.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Static analysis

No suspicious patterns detected.