Back to skill

Security audit

0528-tosr2-csig

Security checks for vulnerabilities and agentic risk

Overview

The stock-analysis features are mostly coherent, but the optional Twitter/X scanners ask users to expose browser session cookies and broad local privileges to an unpinned third-party CLI.

Review this before installing if you plan to use the Twitter/X features. Avoid granting Terminal Full Disk Access, avoid copying browser session cookies into the skill directory, and prefer running the scanners with --no-social or in an isolated environment with only the required credentials. Do not run it from an environment containing unrelated secrets, and treat any .env file as sensitive.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hot_scanner.py:387
Finding

Third-Party Twitter CLI Receives the Entire Process Environment

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
docs/HOT_SCANNER.md:134
Finding

Twitter Setup Requests Unnecessary Terminal Full Disk Access

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
docs/HOT_SCANNER.md:123
Finding

Mutable and Globally Installed Third-Party Dependencies Create a Supply-Chain Exposure

Content
View full analysis
=0.2.40", # "pandas>=2.0.0", # "fear-and-greed>=0.4", # "edgartools>=2.0.0", # "feedparser>=6.0.0", # ] ``` ### Technical Analysis The installation instructions do not pin an exact `bird` version or verify package integrity. Each installation can therefore resolve to a different future package release. The Python inline dependency declarations similarly use lower bounds rather than locked versions, allowing dependency resolution to select later releases that were not included in the audited source. Global npm installation increases the impact because the package becomes available system-wide and may be invoked by unrelated workflows. The risk is amplified in this project because the `bird` executable receives Twitter session credentials and, under the current implementation, the complete inherited process environment. This finding does not establish that any listed dependency is currently malicious. It identifies an unsafe supply-chain configuration in which the code ultimately executed can change after the Skill has been reviewed. ### Attack Path 1. A package maintainer account, package registry, release pipeline, or transitive dependency is compromised. 2. The attacker publishes a malicious release under the expected package name. 3. A user follows the unversioned installation instructions or `uv` resolves depend ...[truncated 950 chars]
Remediation
View remediation
``` 2. Prefer a project-local installation over a global npm package. 3. Commit lockfiles and require integrity verification for npm dependencies. 4. Pin Python packages to reviewed exact versions in a lockfile generated by the supported package manager. 5. Use hash verification where supported. 6. Add an update process that reviews release changes before dependency versions are advanced. 7. Run social-media tooling in an isolated environment with only the required credentials and filesystem access. 8. Document the verified package source and expected executable checksum. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (61)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This mismatch becomes security-relevant because the skill claims a narrower Yahoo-Finance-style analysis role while also referencing broader external data sources and social-media scraping workflows, including subprocess-style Twitter/X access. Undisclosed external collection and tool usage can surprise operators, expand attack surface, and bypass expected review of network, shell, and data-handling behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch becomes security-relevant because the skill claims a narrower Yahoo-Finance-style analysis role while also referencing broader external data sources and social-media scraping workflows, including subprocess-style Twitter/X access. Undisclosed external collection and tool usage can surprise operators, expand attack surface, and bypass expected review of network, shell, and data-handling behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch becomes security-relevant because the skill claims a narrower Yahoo-Finance-style analysis role while also referencing broader external data sources and social-media scraping workflows, including subprocess-style Twitter/X access. Undisclosed external collection and tool usage can surprise operators, expand attack surface, and bypass expected review of network, shell, and data-handling behavior.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The example directs users to create a .env file inside the skill directory containing live auth tokens. In developer workflows, files in project directories are frequently copied, backed up, indexed, or accidentally committed, making this a practical credential exposure vector rather than a theoretical one.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
99% confidence
Finding

os.environ.copy() harvests all environment variables, including any credentials loaded from .env or supplied by the runtime, and forwards them to the external bird process. That creates a direct secret-exposure path to a separate executable that may log, transmit, or otherwise misuse those values, especially dangerous in an analysis skill that should not require broad credential handling.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

Referencing a local .env as a credential source indicates the skill is designed to access secrets from the host filesystem. In a third-party skill, that expands the privilege boundary and is dangerous because users may not expect the code to read local secret material simply to perform rumor scanning.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The code actively reads the .env file line-by-line, which confirms local credential access rather than a passive reference. Combined with subsequent subprocess execution, this creates a direct path from host-stored secrets into an external tool, making the skill materially riskier than a normal market-data utility.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
96% confidence
Finding

Copying the entire process environment and handing it to a subprocess is a classic overexposure pattern because it can leak unrelated secrets, cloud credentials, CI tokens, and API keys into a tool that only needs a small subset. In this skill, the danger is higher because the environment was just populated from a local .env file, so the child process almost certainly receives sensitive authentication material.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
96% confidence
Finding

This second environment copy repeats the same secret-propagation issue for another Bird CLI invocation. Any sensitive variable present in the parent process becomes available to the external binary, increasing the blast radius if that binary is compromised or logs its environment.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The planning document materially expands the skill from stock/crypto analysis into a full commercial platform with user accounts, portfolios, mobile apps, backend infrastructure, and monetization. Scope expansion itself is not code execution, but it increases the attack surface and introduces privileged capabilities not reflected in the manifest, which can mislead reviewers and users about what the skill is intended to do.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Adding payments and subscription processing introduces sensitive financial workflows, webhook handling, receipt validation, and account-tier changes that are outside the stated skill scope. If implemented without explicit scoping and controls, this can expose users to billing abuse, spoofed webhook events, or unauthorized subscription changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document proposes Mixpanel/Amplitude and Sentry collection but does not mention user-facing consent, privacy notice, or limits on what telemetry is sent. In a financial context, telemetry can easily capture portfolio behavior, identifiers, or sensitive usage patterns, creating privacy exposure and regulatory risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to extract and store live X/Twitter authentication cookies (AUTH_TOKEN and CT0) from browser DevTools and place them into a local .env file. Session cookies are highly sensitive credentials; exposing or mishandling them can enable account hijacking or unauthorized access, and the documentation does not clearly warn users about the risks or recommend safer alternatives. In the context of an agent skill that encourages automation and third-party CLI use, this is more dangerous because users may normalize copying privileged browser secrets into tool configs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises commands and execution examples that imply shell, network, file read/write, and environment access, but it does not declare any explicit tool scope or permissions. In an agent ecosystem, missing scope declarations weakens least-privilege controls and can cause operators or orchestrators to grant broader access than users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions tell users to place AUTH_TOKEN and CT0 in a local .env file without any warning about secret handling, file permissions, accidental commits, or reuse risk. These tokens can grant account access to Twitter/X-related tooling, so poor storage guidance increases the chance of credential theft or leakage through logs, backups, or repositories.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation simultaneously claims the system produces clear BUY/HOLD/SELL signals while later disclaiming that it is not providing trading signals. This inconsistency can mislead users or downstream agents about the tool’s purpose and level of actionability, increasing the chance that recommendations are treated as de facto financial advice or automated decision inputs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to obtain Twitter/X authentication material from browser cookies and reuse it in the skill, which is a form of credential harvesting and sidesteps safer OAuth-style flows. In the context of a stock-analysis tool, this expands the trust boundary unnecessarily and creates risk of account takeover, token leakage, and misuse of a user's social media session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown tells users to manually copy highly sensitive auth_token and ct0 values and place them into environment variables or a local .env file, but gives no security warning about secret handling, shell history, file permissions, accidental commits, or credential reuse risk. This materially increases the chance of credential disclosure and misuse, especially for less technical users following the guide verbatim.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.