Back to skill

Security audit

options-brain

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small remote financial-signal fetcher, but it is marketed as deep options analysis while relying on opaque third-party output and premium crypto payment messaging.

Review before installing. Treat outputs as unverified third-party financial signals, not transparent local analysis, and do not follow payment instructions unless you independently trust the publisher and service. The package did not show local persistence or credential access, but its remote API behavior and payment flow should be clearly understood first.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:2
Finding

Unvalidated Ticker Input Enables API Path Manipulation and Untrusted Response Propagation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose is options analysis, but the behavior appears to rely on generic remote signal retrieval and premium payment gating rather than transparent analysis logic. This mismatch is dangerous because it can mislead users into trusting an analysis tool that actually funnels them to a third-party service, potentially solicits payment, and obscures what data is processed or what remote content influences the result.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises executable usage that retrieves a signal but does not declare any tool scope or permissions, despite static analysis indicating network capability. Undeclared network access is risky because it bypasses least-privilege expectations and can enable data exfiltration, tracking, or unreviewed remote content retrieval during skill execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises deep unusual-options analysis, but the implementation only forwards a response from an external API without performing any visible analysis or validation. This is dangerous because users and downstream agents may place trust in the claimed analytical capability and act on opaque third-party output that could be inaccurate, manipulated, or unrelated to the stated purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The tool documentation states that it provides deep analysis, but the execute function merely passes user input to run(), which fetches and returns external data unchanged. This mismatch can mislead users into treating the result as expert or model-derived analysis, increasing the risk of bad financial decisions based on unverified remote content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill silently sends the user-provided ticker to an external domain and returns its response, with no disclosure that data leaves the local skill boundary. While the ticker itself is usually low sensitivity, the hidden network dependency reduces transparency, exposes usage patterns to a third party, and makes the skill dependent on untrusted remote content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.