T09 · Insecure Skill Coding Practices
- Location
scripts/generate-brief.mjs:82- Finding
Shell Command Injection Through User-Controlled Stock Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent stock-report generator, but it needs review because crafted stock inputs can be executed as local shell commands and an external search script receives the full environment.
Review before installing. Do not use this skill with untrusted stock names or symbols until it replaces shell-string execution with argument-array execution, pins or vendors the Tavily search dependency, and passes only the required environment variables to child processes.
scripts/generate-brief.mjs:82Shell Command Injection Through User-Controlled Stock Arguments
scripts/generate-brief.mjs:77Unpinned External Skill Execution With Full Environment Inheritance
The README clearly states that the tool uses the Tavily API for real-time stock data, but it does not disclose that user-supplied stock symbols, company names, and related query context will be sent to a third-party service. In an investment-analysis context, those queries may reveal user interests, watchlists, or research intent, creating a privacy and data-governance risk for users who assume processing is local.
The skill declares access to an environment variable (TAVILY_API_KEY) via metadata but does not define any explicit tool scope or allowed-tools boundary. This can lead to over-broad execution context or unclear authorization expectations, increasing the chance that a hosting agent exposes secrets or code execution capability more widely than intended.
The manifest description is a general marketing-style description of capabilities but does not specify precise trigger phrases, activation scope, or exclusion conditions. For a manifest file, this can create ambiguous or overly broad matching for when the skill should be invoked, especially around common intents like generating reports or analyzing stocks.
The user-facing description and headings are entirely in Chinese, with no indication that other languages are supported or that the user can choose their preferred language. This can violate language/locale policy if the skill implicitly constrains interaction to a specific language without documenting opt-in or justification.
The file's natural-language interface, help text, logs, and date formatting are fixed to Chinese, including use of the zh-CN locale and Asia/Shanghai timezone. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific.
The manifest describes a stock-analysis and report-generation tool with real-time price/news retrieval, which makes network access for search expected. However, this implementation invokes execSync to spawn a child process and run an external script from the local filesystem, which is a broader capability than needed for generating investment briefs and introduces command-execution behavior not declared in the description.
User-controlled values such as stock name/code are interpolated into a shell command passed to execSync. Although wrapped in double quotes, shell command substitution like $(...) still executes inside double quotes, so a crafted stock name could trigger arbitrary local command execution under the user's account.
The tavilySearch function passes search terms based on user inputs to a Tavily-powered search workflow, which constitutes transmission of user-supplied data over the network. The file contains no explicit warning in the help text or generated brief that entered stock symbols/names will be sent to an external service.
The natural-language instructions and usage guidance are presented only in Chinese, which can amount to a language-policy issue if the skill effectively forces a specific language without opt-in or documented locale limitation. The file does not mention that the skill is China-market specific or offer alternative language support.
The manifest description says the skill supports '持仓监控' (portfolio monitoring), implying an actual monitoring/reporting capability. In code, the --portfolio path immediately reports that the feature is still under development and exits, so the described behavior is not actually provided.
Detected: suspicious.dangerous_exec