Back to skill

Security audit

Stock Monitor

Security checks for vulnerabilities and agentic risk

Overview

This stock-monitoring skill is mostly coherent, but it needs review because it stores financial records locally and can automatically post reports with potentially sensitive holdings data to a Feishu group.

Review the Feishu and cron behavior before installing. Use a local-only or preview workflow unless you intentionally want reports containing watchlists, holdings, trades, and analysis sent to a group. Keep the ~/.openclaw stock JSON files private, avoid the documented pip install of json, and treat outputs as informational because some market data is fetched over unauthenticated HTTP.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/troubleshooting.md:186
Finding

Unsafe Installation of an Unnecessary Package Named json

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` 5. Install dependencies in an isolated virtual environment rather than a global or administrator-owned Python environment. 6. Use a trusted package index and disable unintended fallback to public indexes in controlled deployments. 7. Add a dependency review process covering package ownership, release history, known vulnerabilities, and transitive dependencies. 8. Correct the troubleshooting guidance to distinguish standard-library modules from installable third-party packages. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/stock_monitor.py:322
Finding

Unauthenticated Plaintext HTTP Used for Financial Market Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented purpose focuses on stock monitoring and analysis, but the behavior reportedly diverges and includes undeclared capital-flow and ranking-list functions while missing promised features. This kind of description-behavior mismatch is security-relevant because users and policy engines may grant trust based on the declared purpose, while the actual behavior accesses different data sources or performs broader actions than expected.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents capabilities that require file read/write and network access, but it does not declare any explicit tool scope or permission boundary. In an agent environment, this weakens least-privilege controls and makes it easier for the skill to access local portfolio files and external services without clear user consent or policy enforcement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly includes pushing generated reports to a Feishu group chat, but there is no visible warning, consent step, or data-minimization guidance for sending watchlist, holdings, trade history, or analysis externally. Because the skill also references local files containing stock pools, positions, and trades, this creates a realistic risk of unintentional disclosure of sensitive financial preferences or trading activity to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file includes commands that modify or remove local tracking data, such as adding to the monitor pool and removing entries, but provides no user warning about persistent state changes or possible data loss. Under the markdown-specific SQP-2 criteria, documentation should disclose behaviors that can affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file documents commands for adding/removing positions and recording buy/sell trades, which directly affect stored portfolio and transaction history data. There is no accompanying warning that these commands persist financial data locally or that removals may delete records, so users are not informed of privacy and data-integrity implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file includes backup and restore commands that copy JSON files back into the active configuration directory, which can overwrite existing stock pool and position data. The section does not include any warning about verifying backups, potential data loss, or the fact that restore replaces current user data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document title and all operational instructions are presented as a Chinese-only skill reference, with no indication that users may select another language or locale. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document explicitly describes automatically pushing generated stock monitoring reports to a Feishu group, but it does not warn users that portfolio, holdings, alerts, or other potentially sensitive financial data may be sent to an external messaging platform. In the context of a scheduled automation skill, silent outbound delivery increases the risk of unintended data disclosure, misdelivery to the wrong group, and privacy or compliance issues.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a stock monitoring and analysis skill focused on custom watchlists, real-time quotes, technical indicators, trend prediction, and signal alerts. These prompts direct the agent to send full reports to a group chat, which is a communication/broadcast action not inherently required by monitoring or analysis itself and is not stated in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill automatically sends generated reports to a group chat without any user-facing disclosure or confirmation in the prompt template. Even if the content is mainly market analysis, automatic external transmission can leak portfolio holdings, watchlists, or strategy commentary to unintended recipients if the destination is misconfigured or reused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This noon-report template repeats automatic outbound sharing to a group chat with no warning or consent language. Repeated scheduled transmission increases the chance of inadvertent disclosure of sensitive watchlist or analysis data over time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The evening-report workflow includes external message delivery by default without clearly warning that report contents leave the local workflow. If portfolio-related content is included, this can expose trading interests or internal analysis to a broader audience than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Intraday monitoring reports are pushed to a group chat without warning about outbound sharing. Because intraday reports may be frequent and time-sensitive, accidental disclosure can create a larger data trail of positions, alerts, and monitoring logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Hong Kong morning report also includes automatic group-chat delivery with no explicit warning. The cross-market context does not reduce the disclosure risk; portfolio composition and strategy notes may still be sensitive business or personal financial information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Hong Kong noon-report template repeats the same undisclosed outbound-sharing behavior. Scheduled repetition magnifies the risk of persistent unintended disclosure if the group ID or audience is incorrect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Hong Kong evening report automatically sends analysis externally without warning. This is dangerous because users may assume the skill only analyzes and monitors stocks locally, while the workflow actually transmits potentially sensitive report content to a chat audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Hong Kong intraday monitoring is sent to a group chat without any warning about external disclosure. Frequent automated pushes increase exposure by continuously sharing market observations, watchlists, and signal interpretations that may be sensitive or proprietary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is entirely prescriptive in Chinese and instructs that all reports follow these templates, which imposes a specific language/locale by default. The file does not offer any user opt-in, alternative language choice, or justification for a Chinese-only requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script hard-codes Chinese stock names and emits user-facing status and analysis strings in Chinese throughout the file, with no option to select another language or locale. This is a natural-language policy issue because the skill imposes a specific language without explicit user opt-in or justification as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The command help and most returned report strings are fixed in Chinese, which imposes a specific language on users without offering a locale selection. The policy allows locale constraints only when documented and justified or when the user can opt in, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Many docstrings, output messages, and CLI labels are written in Chinese, and the script forces UTF-8 output while presenting its user-facing behavior in a single language. There is no indication that users can opt into another language or locale, which can violate language/locale choice policy for general-purpose skills.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as stock monitoring/analysis, but this section adds persistent portfolio and trade-ledger management by reading and writing files under ~/.openclaw. That expands the skill from passive analysis into stateful financial record manipulation, which can surprise users, create privacy risk, and enable unintended modification of sensitive local data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Trade and position data are persisted to predictable files in the user's home directory without prominent user-facing disclosure or opt-in. Even though this is local storage, the data is financially sensitive and could expose holdings history, trading behavior, and notes to other local processes or users depending on system permissions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code documents an 'intelligent' synchronized trade-to-position cost workflow, but the actual CLI buy/sell handlers bypass that logic and directly overwrite positions. This inconsistency can corrupt holdings state, misstate cost basis, and produce unsafe financial recommendations based on inaccurate local records.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI exposes explicit trade buy/sell and position mutation commands that go beyond the stated stock-monitoring purpose. In an agent setting, undocumented write-capable commands increase the chance of unintended invocation, silent state changes, and misleading trust assumptions about what the skill can do.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.