Back to skill

Security audit

Stock Analysis

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis skill is mostly coherent, but its optional X/Twitter scanning asks users to expose live session credentials to a third-party CLI with overly broad environment access.

Review carefully before installing. The core stock and portfolio features are understandable, but avoid enabling the X/Twitter features unless you are comfortable giving a third-party CLI access to live session cookies. Do not place unrelated secrets in the skill .env or run it from a shell containing sensitive environment variables, and treat saved portfolio/watchlist files as private financial data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hot_scanner.py:22
Finding

Hot Scanner Exposes the Entire Process Environment to a Third-Party CLI

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rumor_scanner.py:30
Finding

Rumor Scanner Exposes All Environment Secrets to the Bird CLI

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:143
Finding

Unpinned Executable and Python Dependencies Create a Supply-Chain Execution Risk

Content
View full analysis
=3.10" # dependencies = [ # "yfinance>=0.2.40", # "pandas>=2.0.0", # "fear-and-greed>=0.4", # "edgartools>=2.0.0", # "feedparser>=6.0.0", # ] # /// ``` Similar open-ended inline declarations are used by other scripts for packages including `yfinance` and `pandas`. ### Technical Analysis The installation command does not specify a reviewed `bird` version or package integrity value. It also installs the executable globally, increasing its visibility and allowing unrelated processes to invoke it. The Python dependency declarations specify only minimum versions. A future release satisfying these constraints can therefore be downloaded and executed by `uv run` without any source change in this repository. Third-party package installation inherently executes package-controlled code. This becomes especially sensitive for `bird`, because the scanner supplies it with X authentication cookies and, due to the separate environment-handling flaws, potentially the full process environment. There is no evidence that the named dependencies are currently malicious. The vulnerability is the lack of reproducible, integrity-verified dependency resolution. ### Attack Path 1. An attacker c ...[truncated 1287 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (20)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
90% confidence
Finding

The script invokes an external binary (bird) from the local system, which expands the trust boundary beyond Python code and allows arbitrary behavior in that binary. Although arguments are passed safely as a list rather than a shell string, executing an externally installed CLI can expose credentials, perform unintended network activity, or behave differently across environments.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 388)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env
                    )

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises and documents execution of Python scripts, network access to external finance/social sources, and local file storage, yet the metadata declares no permissions or environment requirements beyond a binary. This creates a transparency and consent gap: a host or user may invoke the skill without realizing it can read/write local data, access the network, and execute shell commands, which increases the risk of unexpected data exposure or unsafe execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation expands the skill into a Twitter/X integration that depends on a third-party CLI, external authentication material, and broader local system access than the core stock-analysis/Yahoo Finance purpose requires. This increases the attack surface and creates a pathway for sensitive account credentials to be introduced into the skill environment, which is risky even if the feature is optional.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions tell users to place raw Twitter/X authentication tokens into a local .env file or export them directly as environment variables for the skill. Those tokens are effectively live session credentials; storing and reusing them this way can enable account takeover, leakage through logs/process inspection, or accidental inclusion in files and automation environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The roadmap explicitly plans product analytics and error tracking but does not mention any user-facing disclosure, consent flow, or privacy controls for telemetry collection. In a consumer finance app handling portfolio and behavioral data, silent analytics collection can expose sensitive usage patterns and create privacy/compliance risk even if no exploit code is present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to extract and store live Twitter/X authentication cookies (AUTH_TOKEN and CT0) from browser DevTools, but does not warn that these are highly sensitive session credentials that can grant account access if exposed. In the context of an automation-oriented skill with .env setup and cron usage, users may paste or persist these tokens insecurely, increasing the chance of account compromise or privacy leakage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description is broad enough to attract invocation for generic finance requests such as rumors, early signals, portfolio tracking, and crypto monitoring, even outside narrowly scoped commands. Over-broad triggering can cause the agent to route unrelated user queries into a skill that performs network access and stores local data, increasing unintended execution and privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents creating portfolios and watchlists and later notes their filesystem locations, but it does not clearly warn users at the point of use that sensitive holdings and trading preferences will be persisted locally. Portfolio data can reveal financial position and behavior; silent persistence increases privacy and local disclosure risk, especially on shared systems or synced home directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Twitter/X setup instructs users to place authentication tokens in a local .env file without explicit guidance on secure storage, scope, or leakage prevention. Credentials placed this way are commonly exposed through shell history, backups, logs, source control, or permissive file permissions, which could lead to account compromise or unauthorized access to social data integrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation normalizes extracting and storing sensitive Twitter/X credentials without clearly warning that these values are equivalent to high-value authentication secrets and may expose the user's account and private data. In a skill context, omission of such warnings makes unsafe operator behavior more likely and increases the chance of accidental credential compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation encourages users to create portfolios and watchlists containing holdings, quantities, cost basis, targets, and stops, but does not clearly disclose that this data is stored locally or explain the privacy/security implications. In a finance-focused skill, that omission can lead users to persist sensitive financial profiling data on shared or insecure systems without informed consent, increasing exposure if the host is compromised or multi-user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

In portfolio mode, the script sends each holding ticker to external finance services to obtain pricing and history, which can disclose a user's portfolio composition to third parties without explicit, up-front notice. In the context of an agent skill that may process sensitive personal financial data, this is a meaningful privacy issue because holdings can reveal wealth, investment strategy, and sector exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script automatically loads all key/value pairs from a local .env file into process environment variables without validation or user awareness. In combination with the later subprocess execution, this can propagate sensitive tokens or credentials to external tooling and broadens the chance of accidental credential exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The subprocess inherits a full copy of the current environment, which may include API keys, session tokens, proxy settings, or other secrets loaded from .env or the host. Passing all environment variables to an external CLI unnecessarily exposes sensitive data to another executable outside the script's control.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide explicitly instructs users to extract live authentication tokens from browser cookies and reuse them with the tool. Cookie/session-token harvesting bypasses normal delegated auth controls and trains users to expose credentials from their browser session, creating a serious risk of account hijacking, privacy loss, and secret exfiltration if the environment or tool is compromised.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

Copying the entire environment before launching an external CLI is a classic credential-exposure risk, especially because this script also imports variables from a .env file. Any tokens present become available to the bird process and any child processes or logging/debug mechanisms it uses.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
92% confidence
Finding

The code copies the entire process environment, including values loaded from a local .env file, into a child process running an external CLI. If the Bird binary is compromised, replaced, or logs its environment, API keys and unrelated secrets can be exposed to a third-party executable unnecessarily.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
92% confidence
Finding

This second subprocess path repeats the same pattern of forwarding the full environment to an external program. In a skill that depends on local credentials for social-media access, broad environment inheritance increases the blast radius if the external tool is malicious, vulnerable, or misconfigured.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

Automatically reading a repository-adjacent .env file constitutes access to potentially sensitive credentials, especially in a skill that later performs network operations and launches an external CLI. In this context, loading secrets is more dangerous because the skill's stated purpose does not require broad credential ingestion from local files.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The .env access path confirms the script is designed to consume local credential material from the project directory. Because the script also reaches out to third-party services and executes an external tool, this increases the chance of inadvertent credential exposure beyond the minimum needed for stock analysis.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Static analysis

No suspicious patterns detected.