Back to skill

Security audit

Stock Query Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a small stock-price lookup skill with expected network use and CSV output, with some dependency and usability caveats but no hidden or purpose-mismatched behavior found.

Before installing, use an isolated virtual environment and consider pinning reviewed dependency versions. Expect the skill to contact market-data services through yfinance and to create a CSV file in the current working directory; also expect Chinese documentation/output and note that the current script appears to need a syntax fix before it will run.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:9
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: README.md, line 9
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

bash
pip install yfinance pandas

Technical Analysis

The installation command retrieves yfinance, pandas, and their transitive dependencies without exact version constraints, cryptographic hashes, or a reviewed lock file. Consequently, the installed code depends on whichever compatible package releases the package index serves at installation time.

Unpinned dependencies do not establish that the named packages are currently malicious. However, this installation pattern creates a supply-chain exposure because future releases and transitive dependency changes can enter the environment without project review. If a package distribution, maintainer account, or dependency is compromised, malicious code could execute during package installation or when stock_query.py imports the affected package.

Attack Path

  1. An attacker compromises a referenced package, one of its transitive dependencies, or the corresponding package-publishing account.
  2. The attacker publishes a malicious release that remains compatible with the unconstrained installation command.
  3. A user follows the documented setup procedure and runs pip install yfinance pandas.
  4. Package resolution selects the attacker-controlled release because the project provides no approved version or hash.
  5. Malicious package code executes during installation or when stock_query.py imports the dependency.
  6. The payload operates with the permissions of the user or automation account running the installation or script.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the account installing or running the Skill. Depending on that account and environment, the attacker could access readable files and credentials, modi ...[truncated 391 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a dependency manifest containing exact, reviewed versions for all direct and transitive dependencies.

  2. Generate cryptographic hashes for approved distributions and require hash verification during installation, for example:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Generate and review the locked dependency set with a tool such as pip-tools, then commit both the source dependency declaration and generated lock file.

  4. Use an internally controlled package mirror or allowlisted index for production deployments.

  5. Run dependency vulnerability and integrity scanning in CI, and update pinned versions through a reviewed process.

  6. Install and execute the Skill in an isolated virtual environment or container under a non-privileged account.

  7. Update the README so users install from the verified dependency file rather than resolving mutable latest releases directly.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s docstring and all user-facing strings indicate the skill is designed to communicate only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.