Back to skill

Security audit

IHSG Session Summary

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate IHSG market-summary skill with disclosed web lookups and scheduling, though its dependency pinning and API-key handling deserve care.

Install this only in a dedicated environment, set the Tavily key through an environment variable rather than a command-line argument, and be aware that the skill may run scheduled web searches twice per weekday and query Yahoo Finance, Tavily, and Infovesta. Prefer pinned dependencies or a lockfile before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:5
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Supply-Chain Changes

Content
View full analysis
=2.31.0 beautifulsoup4>=4.12.0 # Tavily API for web search and extract tavily-python>=0.3.0 ``` The installation instructions in `SKILL.md:430` direct users to install these dependencies: ```bash pip install -r requirements.txt ``` ### Technical Analysis Every dependency is specified using a minimum version without an upper bound or an exact version. No lock file or cryptographic package hashes are provided. Consequently, an installation can resolve to future releases or changed transitive dependencies that were not present during this audit. This creates a supply-chain risk because package installation and subsequent imports trust code retrieved from external package repositories. A compromised maintainer account, malicious future release, compromised transitive dependency, or unsafe source distribution build hook could introduce arbitrary code after the Skill itself has been reviewed. The Skill imports and executes these packages as part of its normal operation. In particular, the Tavily package operates in a process that can access `TAVILY_API_KEY`, while `requests` and Beautiful Soup process externally retrieved content. ### Attack Path 1. An attacker compromises one of the declared packages, one of its transitive dependencies, or the associated release infrastructure. 2. The attacker publishes a malicious version that still satisfies the broad `>=` constraint. 3. A user follows the documented `pip install -r requirements.txt` instruction. 4. Package resolution selects the malicious or compromised release. 5. Malicious code executes through a build hook, package initialization, or a normal runtime import. 6. The code inherits the Python process's user permissions and can access available files, environment varia ...[truncated 723 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/ihsg_session_extractor.py:677
Finding

Tavily API Credential Can Be Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The documented behavior says the skill is a constrained IHSG summary agent using Tavily, but the finding indicates the actual implementation also uses other live sources and exposes a broader arbitrary Tavily search mode. Description/behavior drift is security-relevant because reviewers may approve a narrower capability set while the code performs more expansive network actions and data retrieval than expected.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs execution of a local Python script, reads an environment variable containing an API key, and performs outbound network access, but it does not declare any explicit tool or permission scope. In an agent platform, missing scope declarations weaken least-privilege controls and can cause the skill to be run with broader capabilities than reviewers or operators expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction explicitly says output must be in Bahasa Indonesia, which forces a specific language choice. The file does not provide user opt-in, alternative language options, or a clear policy justification that this locale restriction is required.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 385)May include surrounding context.

md
"name": "ihsg_session_morning",
      "schedule": { "kind": "cron", "expr": "30 12 * * 1-5" },
      "timezone": "Asia/Jakarta",
      "prompt": "Use skill ihsg_session_summary to create MORNING session summary. Run extraction script first, then use Tavily API (search & extract) to fill any missing data. Generate SHORT insights (1 paragraph) in Bahasa Indonesia.",
      "enabled": true
    },
    {

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest specifically states the skill uses Tavily API to obtain the needed market data, which suggests Tavily-backed retrieval as the operational behavior. In code, the default top net buy/sell path performs direct HTML scraping against Infovesta as a fallback and even as the normal path unless --use-tavily is supplied, which materially differs from the described behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a cron-oriented agent for generating structured IHSG morning/closing summaries, but the --tavily-search path turns the skill into a general-purpose web search tool that returns arbitrary Tavily results for any user-supplied query. That capability is broader than and not necessary for the stated purpose of market-summary generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The formatter hardcodes Indonesian day and month names and labels the date formatting as Bahasa Indonesia, which imposes a specific locale on all users. The file does not offer a language/locale option or explain that the tool is intentionally region-specific in a way that would justify the forced localization.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with only a lower bound (requests>=2.31.0), which makes builds non-reproducible and can pull in different versions over time, including vulnerable or breaking releases. In a skill that performs web requests and scraping on a schedule, dependency drift increases supply-chain risk and makes it harder to verify whether a deployed version is affected by known advisories.

Content

Scanner excerpt · scripts/requirements.txt (reported line 5)May include surrounding context.

text
# Install with: pip install -r requirements.txt

# Web scraping
requests>=2.31.0
beautifulsoup4>=4.12.0

# Tavily API for web search and extract

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest includes requests without an exact version pin, so it is impossible to determine whether the installed version includes fixes for known advisories. In an agent that makes outbound web requests, using an affected requests release could expose credentials or weaken transport/request handling, and the unpinned requirement makes that risk unverifiable.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

beautifulsoup4>=4.12.0 is unpinned, so installations may resolve to different versions over time. While this is not an immediate exploit by itself, it creates supply-chain and stability risk because future releases could introduce vulnerabilities or incompatible behavior in a scraping workflow.

Content

Scanner excerpt · scripts/requirements.txt (reported line 6)May include surrounding context.

text
# Web scraping
requests>=2.31.0
beautifulsoup4>=4.12.0

# Tavily API for web search and extract
tavily-python>=0.3.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

tavily-python>=0.3.0 is also unpinned, which is especially relevant because this package interfaces with an external search/extract API and may handle network data and credentials. Allowing arbitrary newer versions increases supply-chain exposure and can unexpectedly change behavior in an automated cron-driven agent.

Content

Scanner excerpt · scripts/requirements.txt (reported line 9)May include surrounding context.

text
beautifulsoup4>=4.12.0

# Tavily API for web search and extract
tavily-python>=0.3.0

Static analysis

No suspicious patterns detected.