Back to skill

Security audit

Stock Forecast

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documented stock-analysis API helper that sends user-selected tickers to Intellectia and does not show hidden access, persistence, or destructive behavior.

Before installing, understand that stock symbols and request details will be sent to Intellectia's API, and the output is financial information that should not be treated as guaranteed or personalized investment advice. For stricter environments, pin or pre-approve the requests dependency before installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Third-Party Python Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 4
Vulnerability Type: Unpinned package installation and software supply-chain exposure
Risk Level: Medium

Vulnerable Code:

yaml
metadata: {"openclaw":{"requires":{"bins":["curl","python3"]},"install":[{"id":"python","kind":"pip","package":"requests","bins":[],"label":"Install requests (pip)"}]}}

Technical Analysis

The installation metadata declares the third-party Python package requests without specifying an audited version or cryptographic hash. Consequently, the package resolver may install different artifacts over time based on the state of the configured package index and dependency graph.

Although requests is a legitimate package and there is no evidence that the Skill intentionally selects a malicious dependency, the absence of version and integrity constraints weakens build reproducibility. A compromised upstream release, package index, transitive dependency, or resolver configuration could introduce attacker-controlled code during installation or subsequent execution.

Attack Path

  1. A user or automated Skill installer processes the installation metadata in SKILL.md.
  2. The installer invokes pip to resolve and install the unpinned requests package and its dependencies.
  3. An attacker compromises an eligible upstream artifact, dependency, package index, or package-resolution path.
  4. The resolver downloads the attacker-controlled artifact because no fixed version and hash are enforced.
  5. Malicious installation or runtime code executes under the identity and permissions of the account installing or invoking the Skill.

This path requires a compromise or manipulation of the dependency supply chain; the reviewed project itself contains no embedded malicious payload.

Impact Assessment

Successful exploitation could allow arbitrary code execution with the privileges of the user or service performing package installati ...[truncated 305 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin requests to a specifically reviewed version rather than allowing unrestricted resolution.
  • Enforce artifact integrity with cryptographic hashes, such as a hash-locked requirements file installed with pip --require-hashes.
  • Lock and audit all transitive dependencies, not only the direct package.
  • Configure an explicit trusted package index or an internally controlled dependency mirror.
  • Integrate dependency vulnerability and provenance checks into release maintenance.
  • Consider replacing requests with Python's standard-library HTTP client if eliminating the external dependency is practical.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Example (cURL)

bash
curl -sS "https://api.intellectia.ai/gateway/v1/stock/screener-public?ticker=TSLA&asset_type=0"

Example (Python)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Example (cURL)

bash
curl -sS "https://api.intellectia.ai/gateway/v1/stock/screener-public?ticker=TSLA&asset_type=0"

Example (Python)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Example (cURL)

bash
curl -sS "https://api.intellectia.ai/gateway/v1/stock/screener-public?ticker=TSLA&asset_type=0"

Example (Python)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

Example (cURL)

bash
curl -sS "https://api.intellectia.ai/gateway/v1/stock/screener-public?ticker=TSLA&asset_type=0"

Example (Python)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

Example (cURL)

bash
curl -sS "https://api.intellectia.ai/gateway/v1/stock/screener-public?ticker=TSLA&asset_type=0"

Example (Python)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example request body fixes locale to en, which can steer the skill toward English-only behavior. The file does not state that language is user-selectable or that English is required for a documented regional/compliance reason, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

bash
python3 - <<'PY'
import requests
r = requests.post("https://api.intellectia.ai/gateway/v1/finance/should-i-buy",
  json={"asset": {"ticker": "TSLA", "asset_type": 0, "locale": "en"}}, timeout=30)
r.raise_for_status()
d = r.json().get("data") or {}

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

bash
python3 - <<'PY'
import requests
r = requests.post("https://api.intellectia.ai/gateway/v1/finance/should-i-buy",
  json={"asset": {"ticker": "TSLA", "asset_type": 0, "locale": "en"}}, timeout=30)
r.raise_for_status()
d = r.json().get("data") or {}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Python example sends "locale": "en" without any indication that users can opt into other languages. Repeating the fixed English locale in operational examples suggests the skill may force a language setting contrary to the policy guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.