Back to skill

Security audit

expected-move-visualizer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only market-data visualizer that fetches SentiSense data and creates a local HTML chart without hidden persistence or account actions.

Install only if you are comfortable giving this skill a SentiSense API key and allowing read-only requests to app.sentisense.ai at build time. Review generated charts as educational market-data snapshots, not trading advice; the skill does not place trades or modify accounts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
node scripts/prepare_data.mjs NVDA > /tmp/nvda.json

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
75% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
- When implied sits above realized, the honest phrasing is that options are pricing more movement than the stock has recently delivered. That is an observation about pricing, not a trade.
- Never turn the band edges into targets, and never attach a probability more precise than the model supports.
- On a preview response, say the 60 and 90 day bands are missing because the free monthly dossier allowance is spent, rather than presenting a one-band chart as the whole picture.
- When the next report is unknown because the free calendar covers one week, say exactly that. Never tell the user nothing is scheduled, and say a report inside the window cannot be ruled out.

## Going further

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The money() formatter uses toLocaleString("en-US", ...), which forces U.S. locale output regardless of user preference. This is a natural-language/locale policy concern because the file imposes a specific locale without any opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/prepare_data.mjs:18