Back to skill

Security audit

Stock Analysis 6

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stock-analysis purpose, but its optional Twitter/X scanners handle live session credentials and pass the full local environment to an external CLI, which creates a material review risk.

Review this before installing if you plan to use the Hot Scanner or Rumor Scanner with Twitter/X. Avoid putting broad secrets in the skill .env, treat AUTH_TOKEN and CT0 as account-session credentials, and consider using --no-social unless you trust the bird CLI and the dependency chain. Portfolio and watchlist files are stored locally under ~/.clawdbot/skills/stock-analysis and can be modified or deleted by explicit commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hot_scanner.py:22
Finding

Excessive Credential Exposure to the Third-Party bird CLI

Content
View full analysis
Remediation
View remediation
dict[str, str]: allowed = {"AUTH_TOKEN", "CT0"} credentials = {} if path.exists(): for raw_line in path.read_text(encoding="utf-8").splitlines(): line = raw_line.strip() if not line or line.startswith("#") or "=" not in line: continue key, value = line.split("=", 1) key = key.strip() if key in allowed: credentials[key] = value.strip().strip('"').strip("'") return credentials ``` 2. Do not write `.env` values into the global `os.environ`. 3. Construct a minimal environment for `bird`. Include only required credentials and narrowly selected runtime variables: ```python credentials = load_bird_credentials(ENV_FILE) bird_env = { "PATH": os.environ.get("PATH", ""), "HOME": os.environ.get("HOME", ""), "LANG": os.environ.get("LANG", "C.UTF-8"), **credentials, } result = subprocess.run( [bird_bin, "search", query, "-n", "15", "--json"], capture_output=True, text=True, timeout=30, env=bird_env, check=False, ) ``` 4. Validate that both credentials are present before enabling Twitter scanning, and otherwise skip the integration with a clear warning. 5. Use a project-local, version-pinned `bird` executable and verify its expected path and integrity before execution. 6. Restrict `.env` file permissions to the owning user and document that it must contain only Twitter-specific credentials. 7. Prefer a scoped API credential over browser session cookies when the upstream service supports one. Browser session tokens can provide broader account access than the scanner requires. 8. Avoid logging credential values, child environments, or raw subprocess diagnostic output that might contain secrets. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/analyze_stock.py:3
Finding

Mutable and Unverified Third-Party Dependencies Are Installed and Executed

Content
View full analysis
=3.10" # dependencies = [ # "yfinance>=0.2.40", # "pandas>=2.0.0", # "fear-and-greed>=0.4", # "edgartools>=2.0.0", # "feedparser>=6.0.0", # ] ``` ```markdown uv run {baseDir}/scripts/analyze_stock.py AAPL uv run {baseDir}/scripts/analyze_stock.py AAPL --fast uv run {baseDir}/scripts/analyze_stock.py AAPL MSFT GOOGL uv run {baseDir}/scripts/analyze_stock.py BTC-USD ETH-USD uv run {baseDir}/scripts/dividends.py JNJ uv run {baseDir}/scripts/dividends.py JNJ PG KO MCD --output json ``` ```markdown 1. Install bird: `npm install -g @steipete/bird` 2. Login to x.com in Safari/Chrome 3. Create `.env` with `AUTH_TOKEN` and `CT0` ``` ```markdown 1. Install bird CLI: `npm install -g @steipete/bird` 2. Login to x.com in Safari/Chrome 3. Create `.env` file: ``` AUTH_TOKEN=your_auth_token CT0=your_ct0_token ``` ``` ### Technical Analysis The inline Python dependency declarations use open-ended lower-bound constraints. For example, `yfinance>=0.2.40` permits any later version accepted by the resolver. The documented `uv run` workflow can therefore resolve, download, import, and execute dependency versions that were not part of the audited project snapshot. The social integration also instructs users to install `@steipete/bird` globally without an exact version, lockfile, package integrity value, or verified binary checksum. A global executable has broad availability in the user's shell and is subsequently launched with user-level filesystem permissions. No lockfile or vendored depend ...[truncated 2386 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (56)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill claims Yahoo Finance-based analysis, but the documentation explicitly includes additional external sources like CoinGecko, Google News, and Twitter/X, plus a local bird CLI for social scraping. Undisclosed external integrations and subprocess invocation materially expand the trust boundary, increasing privacy, supply-chain, and data-exfiltration risk beyond what users would infer from the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims Yahoo Finance-based analysis, but the documentation explicitly includes additional external sources like CoinGecko, Google News, and Twitter/X, plus a local bird CLI for social scraping. Undisclosed external integrations and subprocess invocation materially expand the trust boundary, increasing privacy, supply-chain, and data-exfiltration risk beyond what users would infer from the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims Yahoo Finance-based analysis, but the documentation explicitly includes additional external sources like CoinGecko, Google News, and Twitter/X, plus a local bird CLI for social scraping. Undisclosed external integrations and subprocess invocation materially expand the trust boundary, increasing privacy, supply-chain, and data-exfiltration risk beyond what users would infer from the description.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The documentation explicitly instructs users to store authentication tokens in a local .env file, which is a credential handling pattern that can easily lead to secret leakage through source control, backups, logs, or local compromise if protections are not specified. Because these tokens may grant account access, exposure could directly enable unauthorized use of the user's Twitter/X session.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Referencing and loading a repository-local .env file gives the script access to credentials and other sensitive configuration stored on disk. In isolation that can be legitimate, but in this skill it is unnecessary broad access and contributes directly to later secret exposure through subprocess inheritance.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Opening the .env file as part of normal execution is credential access behavior that is not clearly justified for the scanner's core purpose. The danger is contextual: this file access becomes more serious because the loaded values are later made available to a child process.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

Copying the full process environment immediately before launching an external command is a strong indicator of secret propagation risk. Because the environment may include credentials from .env and the host, the subprocess gains access to secrets unrelated to its task, which can be stolen or leaked by the child process.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

Referencing a repository-local .env file for runtime credentials indicates the skill accesses locally stored secrets to enable an external service. In a stock-analysis skill, credential access is only weakly justified and becomes more dangerous because those secrets are then propagated to an external binary.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The code reads and parses .env contents directly, which is credential access behavior with elevated sensitivity in an agent skill. Because the skill's purpose is market scanning rather than secret management, this broad local-secret handling increases risk disproportionate to its functional need.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

Copying the full parent environment and passing it to an external CLI can expose unrelated secrets such as API keys, tokens, and service credentials to that child process. In combination with prior .env loading, this materially increases the chance of secret leakage or misuse if the Bird CLI is malicious, compromised, or verbose in diagnostics.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

This second use of os.environ.copy() repeats the same broad secret-exposure pattern on another subprocess path. Repeated full-environment inheritance makes accidental or malicious credential access more likely and harder to audit.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The plan explicitly includes Mixpanel/Amplitude and Sentry for telemetry and error tracking, but there is no corresponding user-facing disclosure, consent flow, or privacy-controls plan in the app UX. In a consumer finance app handling portfolio and behavioral data, silent telemetry collection can expose sensitive usage patterns and create privacy/compliance risk under GDPR/CCPA and app-store transparency requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to retrieve AUTH_TOKEN and CT0 from browser cookies and place them into a .env file, but it does not clearly warn that these are live session credentials equivalent to account access. If mishandled, committed to source control, shared in logs, or read by other local processes, they could enable unauthorized access to the user's Twitter/X account or abuse of the account's authenticated session.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises commands that read/write local files, invoke shell commands, and access network resources, but it does not declare an explicit tool/permission scope. That creates a transparency and containment problem: a host may grant broader capabilities than users expect, and reviewers cannot easily verify least-privilege behavior from the manifest alone.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says the skill analyzes stocks and cryptocurrencies using Yahoo Finance data, but this document presents Hot Scanner as aggregating multiple non-Yahoo sources such as CoinGecko, Google News, Twitter/X, and Reddit. That broadens the described behavior from Yahoo-finance-centric analysis into multi-source social/news trend monitoring.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation instructs users to install third-party CLI tooling and obtain Twitter/X authentication material, including browser cookies and local environment secrets. This creates credential-handling risk and expands trust to external tooling and browser-derived tokens, which could expose user accounts if mishandled or reused unsafely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions tell users to handle sensitive Twitter/X tokens and browser-derived credentials without any warning about secret sensitivity, secure storage, rotation, or account risk. Users may place long-lived credentials into plaintext files or environment history, increasing the chance of accidental disclosure or account compromise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring presents the tool as 'Stock analysis using Yahoo Finance data', but the code additionally fetches Google News RSS in check_breaking_news() and queries SEC EDGAR via edgartools in get_insider_activity(). Those are materially different data sources and capabilities, not just incidental implementation details of Yahoo Finance access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file documentation and CLI description say it analyzes stocks using Yahoo Finance data, but the code also loads named portfolios from a local PortfolioStore, computes holdings valuation, P&L, concentration warnings, and period returns. That is broader behavior than single-ticker analysis and represents a meaningful expansion of capability.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script can read local portfolio data from PortfolioStore when the --portfolio option is used, which introduces access to user-local financial holdings not obvious from a simple ticker-analysis script. In an agent skill context, this expands data access from public market lookups to sensitive local investment data, creating privacy risk if users invoke the feature without clear disclosure or if downstream components log/output that information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.