Back to skill

Security audit

stock-analyst

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly about stock analysis and notifications, but it includes privileged scheduled installation and a hard-coded WeChat recipient that could send portfolio data to the wrong account.

Install only after reviewing and editing the scripts: replace the hard-coded WeChat USER_ID, verify or remove the preset holdings/watchlists, avoid running the root installer unless you intentionally want system cron jobs, and prefer a user-scoped scheduler or manually reviewed setup. Do not treat the generated buy/sell outputs as personalized financial advice.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (18)

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The installer executes shell commands via os.system(), which is inherently risky because it delegates parsing to the shell and can turn unexpected whitespace, metacharacters, or future variable changes into command execution issues. In this file the current command strings are mostly constant, so this is not an obvious injection sink today, but it still grants broad system-modification capability in an installer that runs as root and expands the attack surface unnecessarily.

Content

Scanner excerpt · scripts/install.py (reported line 16)May include surrounding context.

python
LOGROTATE_CONF = "/etc/logrotate.d/stock-monitor"

def run(cmd):
    r = os.system(cmd)
    if r != 0:
        print(f"❌ 命令失败: {cmd}")
        sys.exit(r)

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

Using os.system() to invoke python3 -m py_compile introduces unnecessary shell execution even for a simple syntax-check step. The immediate injection risk is limited because the filenames are hardcoded, but this still normalizes shell-based execution in a privileged installer and would become dangerous if script names or paths were ever made variable.

Content

Scanner excerpt · scripts/install.py (reported line 87)May include surrounding context.

python
# 6. 验证脚本语法
    for script in ["stock_pre.py", "stock_after.py", "stock_next.py"]:
        path = f"/root/.openclaw/workspace/skills/stock-push/scripts/{script}"
        r = os.system(f"python3 -m py_compile {path}")
        if r != 0:
            print(f"  ❌ {script} 语法检查失败")
        else:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no permissions even though its documented behavior requires environment access, file reads/writes, network access, and shell-style execution. This breaks least-privilege and informed-consent expectations: a user or platform may invoke a seemingly harmless analysis skill without realizing it can modify local files, access watchlists, and perform outbound actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose presents the skill as a stock-analysis and push assistant, but the detected behavior extends into system installation, cron and logrotate configuration, external downloads, and hardcoded message delivery. Hidden system-level persistence and external-service interaction materially increase risk because they can modify the host, exfiltrate data, or create unauthorized recurring tasks beyond what a user reasonably expects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is described as a stock analysis/push tool, but the file is an installer that performs host-level deployment actions. That mismatch matters because users may consent to financial analysis features without realizing the skill will install files, unpack archives, and configure persistent scheduled tasks on the host.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Writing directly to /etc/cron.d and /etc/logrotate.d creates persistent system-level behavior on the host, which exceeds normal expectations for a stock-analysis skill and can survive beyond a session. In the context of an agent skill, undeclared persistence is especially dangerous because it enables repeated execution as root and ongoing access to host resources without transparent user approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer uses shell commands to perform filesystem operations even though the skill's stated purpose is stock analysis. That capability mismatch is security-relevant because a finance-oriented skill does not need broad shell execution to fulfill its core function, so the presence of such power increases the blast radius if the installer or its inputs are compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installer downloads a skill package from a remote URL and then installs it, creating a supply-chain trust boundary. This is particularly dangerous here because the downloaded artifact is not pinned to a specific immutable release, signature-verified, or hash-checked before extraction and later execution, so a repository compromise or content swap could lead to arbitrary code deployment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script hard-codes a specific WeChat user ID and automatically sends portfolio-related notifications to that recipient. In a skill context, this creates unauthorized outbound data disclosure risk and can route sensitive investment information to an unintended or attacker-controlled account without runtime user consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script hard-codes a specific WeChat user identifier and uses it automatically for outbound messaging. This creates an account-targeted side effect without user/runtime consent, and if the code is reused, exposed, or triggered unexpectedly it can send market-related notifications to a real account, leaking operational details and enabling unauthorized messaging behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module claims multi-user isolation, but messages are always sent to a single hard-coded WeChat target. In a shared or multi-tenant environment, this can route one user's watchlist-derived market notifications to the wrong recipient, causing privacy leakage and cross-user data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The trigger phrases are broad enough to activate on ordinary finance conversation, which can cause the skill to run unexpectedly. In this context, over-triggering is more dangerous because the skill is not purely conversational: it is tied to data access, file operations, and push-related behavior, so unintended activation could lead to unnecessary processing or side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file contains explicit buy/sell timing, stop-loss, and position-sizing guidance framed as actionable investing rules, but it does not include any warning that the content is educational, non-personalized, or subject to market risk. In the context of a stock-analysis skill whose purpose is to issue concrete trading recommendations and scheduled pushes, this materially increases the chance that users treat the content as authoritative financial advice and act on it inappropriately.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document gives explicit buy/sell signals such as golden cross and death cross as trading actions, but it does not pair them with a clear financial-risk disclaimer or emphasize that technical indicators are fallible and not personalized investment advice. In the context of this skill, which promises direct stock recommendations and timed pushes, the omission makes users more likely to treat the content as authoritative trading instructions and incur financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installer performs privileged writes to system cron and logrotate locations without an explicit warning or interactive confirmation. For a skill whose user-facing description emphasizes stock analysis and notifications, silent persistence on the host is more dangerous because users may not understand they are granting durable root-level execution paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installer retrieves a remote archive and overwrites local files without prominently warning the user about network access and file replacement. Even if intended for convenience, silent retrieval and replacement reduce user awareness of supply-chain risk and make accidental or malicious replacement harder to detect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script hard-codes a specific WeChat recipient ID and automatically sends outbound messages to that account. In an agent skill context, this creates an undisclosed exfiltration/notification path to a fixed external destination, which can leak user portfolio information or analysis results without runtime consent or per-user configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script transmits portfolio-related stock data over an external messaging channel without any visible disclosure, consent, or access control in the file. Because the skill is positioned as a stock-analysis/push system, users may not realize their holdings and monitoring outputs are being forwarded to a fixed external endpoint, increasing privacy and data-leak risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.