T09 · Insecure Skill Coding Practices
- Location
scripts/hot_scanner.py:22- Finding
Third-Party X/Twitter CLI Receives the Complete Process Environment
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a stock-analysis toolkit, but it handles X/Twitter session tokens and private portfolio reports with broader access and less user control than its main description discloses.
Install only if you are comfortable with a financial-analysis skill that can store local portfolio data, call external market and social-data services, and optionally use X/Twitter session cookies. Avoid enabling the Twitter/X scanners unless bird is pinned or isolated and only AUTH_TOKEN and CT0 are passed to it. Review or remove the Feishu daily-review scripts before use, especially if your OpenClaw workspace contains private portfolio data.
scripts/hot_scanner.py:22Third-Party X/Twitter CLI Receives the Complete Process Environment
SKILL.md:152Unpinned Globally Installed Dependency Handles Authentication Credentials
scripts/daily_review_auto.py:77Hard-Coded Agent Workspace Access Stages Private Portfolio Data for External Delivery
scripts/daily_review_auto.py:58Financial Market Data Is Retrieved over Plaintext HTTP
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /portfolios
POST /portfolios
PUT /portfolios/{id}
DELETE /portfolios/{id}
GET /portfolios/{id}/assets
POST /portfolios/{id}/assets
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /portfolios/{id}/assets
POST /portfolios/{id}/assets
PUT /portfolios/{id}/assets/{ticker}
DELETE /portfolios/{id}/assets/{ticker}
GET /portfolios/{id}/performance?period=weekly
GET /portfolios/{id}/summary
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /alerts
POST /alerts
DELETE /alerts/{id}
GET /user/subscription
POST /user/subscription/upgrade
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
This finding again indicates undeclared external providers and missing claimed features, reducing transparency about network behavior and actual functionality. In a financial-analysis context, undisclosed data provenance and overclaimed capability can mislead users into taking actions or granting permissions they otherwise would not.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)
**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)
**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock
The file directs users to store Twitter/X session tokens in a local .env file, which is a credential-handling pattern that can lead to account compromise if the file is committed, logged, copied, or otherwise exposed. Because the referenced values are session-grade tokens rather than low-scope API keys, leakage could allow unauthorized use of the user's Twitter/X account until the tokens are revoked or expire.
Create .env file in the skill directory:
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here
The function docstring says it calculates put/call ratio from the options chain, implying it works from the provided StockData object. However, the implementation accesses data.ticker_obj, a field that does not exist on the StockData dataclass, so the documented capability is not actually supported by the provided object model and will fail into the exception path.
Accessing a repository-local .env file can expose credentials and secrets beyond what this scanner actually needs. In context, that access is more sensitive because the values are promoted into process-wide environment state and may later be inherited by a child subprocess.
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
The code conditionally opens and parses the .env file, which is a form of credential access not clearly justified for all scan modes. This broad secret ingestion enlarges exposure if logs, exceptions, or subprocesses later touch the environment.
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
for line in f:
Using os.environ.copy() forwards the entire process environment to the external bird CLI, which may include API keys, tokens, cloud credentials, proxies, or other secrets loaded from .env or the host environment. Because the child process is a separately installed binary discovered partly via PATH fallback, this materially increases the chance of credential exposure or abuse if that binary is malicious, replaced, or compromised.
for category, query in searches:
try:
env = os.environ.copy()
result = subprocess.run(
[bird_bin, "search", query, "-n", "15", "--json"],
capture_output=True, text=True, timeout=30, env=env
The code is explicitly designed to access a .env file containing credentials for an external service. In isolation that can be legitimate, but in this skill it becomes security-relevant because those credentials are later loaded into the environment and supplied to a subprocess, increasing exposure risk.
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"
def load_env():
"""Load environment variables from .env file."""
The load_env routine reads and parses every key-value line from .env and places them into process environment variables. This is dangerous because it normalizes unrestricted credential access and sets up later leakage to subprocesses and potentially other libraries running in the same process.
BIRD_ENV = Path(__file__).parent.parent / ".env"
def load_env():
"""Load environment variables from .env file."""
if BIRD_ENV.exists():
for line in BIRD_ENV.read_text().splitlines():
if '=' in line and not line.startswith('#'):
Copying the full process environment immediately before launching an external CLI risks forwarding unrelated secrets to that child process, including credentials loaded from .env and any ambient agent tokens. In an agent environment, this broad secret propagation materially increases the blast radius if the external tool logs, crashes, or transmits environment-derived data.
for query in queries[:4]: # Limit to avoid rate limits
try:
cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
env = os.environ.copy()
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)
No suspicious patterns detected.