T09 · Insecure Skill Coding Practices
- Location
scripts/hot_scanner.py:22- Finding
Hot Scanner Exposes the Entire Process Environment to a Third-Party CLI
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This stock-analysis skill is mostly coherent, but its optional X/Twitter scanning asks users to expose live session credentials to a third-party CLI with overly broad environment access.
Review carefully before installing. The core stock and portfolio features are understandable, but avoid enabling the X/Twitter features unless you are comfortable giving a third-party CLI access to live session cookies. Do not place unrelated secrets in the skill .env or run it from a shell containing sensitive environment variables, and treat saved portfolio/watchlist files as private financial data.
scripts/hot_scanner.py:22Hot Scanner Exposes the Entire Process Environment to a Third-Party CLI
scripts/rumor_scanner.py:30Rumor Scanner Exposes All Environment Secrets to the Bird CLI
README.md:143Unpinned Executable and Python Dependencies Create a Supply-Chain Execution Risk
The script invokes an external binary (bird) from the local system, which expands the trust boundary beyond Python code and allows arbitrary behavior in that binary. Although arguments are passed safely as a list rather than a shell string, executing an externally installed CLI can expose credentials, perform unintended network activity, or behave differently across environments.
for category, query in searches:
try:
env = os.environ.copy()
result = subprocess.run(
[bird_bin, "search", query, "-n", "15", "--json"],
capture_output=True, text=True, timeout=30, env=env
)
The skill advertises and documents execution of Python scripts, network access to external finance/social sources, and local file storage, yet the metadata declares no permissions or environment requirements beyond a binary. This creates a transparency and consent gap: a host or user may invoke the skill without realizing it can read/write local data, access the network, and execute shell commands, which increases the risk of unexpected data exposure or unsafe execution.
The documentation expands the skill into a Twitter/X integration that depends on a third-party CLI, external authentication material, and broader local system access than the core stock-analysis/Yahoo Finance purpose requires. This increases the attack surface and creates a pathway for sensitive account credentials to be introduced into the skill environment, which is risky even if the feature is optional.
The instructions tell users to place raw Twitter/X authentication tokens into a local .env file or export them directly as environment variables for the skill. Those tokens are effectively live session credentials; storing and reusing them this way can enable account takeover, leakage through logs/process inspection, or accidental inclusion in files and automation environments.
The roadmap explicitly plans product analytics and error tracking but does not mention any user-facing disclosure, consent flow, or privacy controls for telemetry collection. In a consumer finance app handling portfolio and behavioral data, silent analytics collection can expose sensitive usage patterns and create privacy/compliance risk even if no exploit code is present.
The README instructs users to extract and store live Twitter/X authentication cookies (AUTH_TOKEN and CT0) from browser DevTools, but does not warn that these are highly sensitive session credentials that can grant account access if exposed. In the context of an automation-oriented skill with .env setup and cron usage, users may paste or persist these tokens insecurely, increasing the chance of account compromise or privacy leakage.
The description is broad enough to attract invocation for generic finance requests such as rumors, early signals, portfolio tracking, and crypto monitoring, even outside narrowly scoped commands. Over-broad triggering can cause the agent to route unrelated user queries into a skill that performs network access and stores local data, increasing unintended execution and privacy risk.
The skill documents creating portfolios and watchlists and later notes their filesystem locations, but it does not clearly warn users at the point of use that sensitive holdings and trading preferences will be persisted locally. Portfolio data can reveal financial position and behavior; silent persistence increases privacy and local disclosure risk, especially on shared systems or synced home directories.
The Twitter/X setup instructs users to place authentication tokens in a local .env file without explicit guidance on secure storage, scope, or leakage prevention. Credentials placed this way are commonly exposed through shell history, backups, logs, source control, or permissive file permissions, which could lead to account compromise or unauthorized access to social data integrations.
The documentation normalizes extracting and storing sensitive Twitter/X credentials without clearly warning that these values are equivalent to high-value authentication secrets and may expose the user's account and private data. In a skill context, omission of such warnings makes unsafe operator behavior more likely and increases the chance of accidental credential compromise.
The documentation encourages users to create portfolios and watchlists containing holdings, quantities, cost basis, targets, and stops, but does not clearly disclose that this data is stored locally or explain the privacy/security implications. In a finance-focused skill, that omission can lead users to persist sensitive financial profiling data on shared or insecure systems without informed consent, increasing exposure if the host is compromised or multi-user.
In portfolio mode, the script sends each holding ticker to external finance services to obtain pricing and history, which can disclose a user's portfolio composition to third parties without explicit, up-front notice. In the context of an agent skill that may process sensitive personal financial data, this is a meaningful privacy issue because holdings can reveal wealth, investment strategy, and sector exposure.
The script automatically loads all key/value pairs from a local .env file into process environment variables without validation or user awareness. In combination with the later subprocess execution, this can propagate sensitive tokens or credentials to external tooling and broadens the chance of accidental credential exposure.
The subprocess inherits a full copy of the current environment, which may include API keys, session tokens, proxy settings, or other secrets loaded from .env or the host. Passing all environment variables to an external CLI unnecessarily exposes sensitive data to another executable outside the script's control.
The guide explicitly instructs users to extract live authentication tokens from browser cookies and reuse them with the tool. Cookie/session-token harvesting bypasses normal delegated auth controls and trains users to expose credentials from their browser session, creating a serious risk of account hijacking, privacy loss, and secret exfiltration if the environment or tool is compromised.
Copying the entire environment before launching an external CLI is a classic credential-exposure risk, especially because this script also imports variables from a .env file. Any tokens present become available to the bird process and any child processes or logging/debug mechanisms it uses.
for category, query in searches:
try:
env = os.environ.copy()
result = subprocess.run(
[bird_bin, "search", query, "-n", "15", "--json"],
capture_output=True, text=True, timeout=30, env=env
The code copies the entire process environment, including values loaded from a local .env file, into a child process running an external CLI. If the Bird binary is compromised, replaced, or logs its environment, API keys and unrelated secrets can be exposed to a third-party executable unnecessarily.
for query in queries[:4]: # Limit to avoid rate limits
try:
cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
env = os.environ.copy()
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)
This second subprocess path repeats the same pattern of forwarding the full environment to an external program. In a skill that depends on local credentials for social-media access, broad environment inheritance increases the blast radius if the external tool is malicious, vulnerable, or misconfigured.
for query in queries[:3]:
try:
cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
env = os.environ.copy()
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)
Automatically reading a repository-adjacent .env file constitutes access to potentially sensitive credentials, especially in a skill that later performs network operations and launches an external CLI. In this context, loading secrets is more dangerous because the skill's stated purpose does not require broad credential ingestion from local files.
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
The .env access path confirms the script is designed to consume local credential material from the project directory. Because the script also reaches out to third-party services and executes an external tool, this increases the chance of inadvertent credential exposure beyond the minimum needed for stock analysis.
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
for line in f:
No suspicious patterns detected.