T09 · Insecure Skill Coding Practices
- Location
scripts/hot_scanner.py:387- Finding
Third-Party Twitter CLI Receives the Entire Process Environment
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The stock-analysis features are mostly coherent, but the optional Twitter/X scanners ask users to expose browser session cookies and broad local privileges to an unpinned third-party CLI.
Review this before installing if you plan to use the Twitter/X features. Avoid granting Terminal Full Disk Access, avoid copying browser session cookies into the skill directory, and prefer running the scanners with --no-social or in an isolated environment with only the required credentials. Do not run it from an environment containing unrelated secrets, and treat any .env file as sensitive.
scripts/hot_scanner.py:387Third-Party Twitter CLI Receives the Entire Process Environment
docs/HOT_SCANNER.md:134Twitter Setup Requests Unnecessary Terminal Full Disk Access
docs/HOT_SCANNER.md:123Mutable and Globally Installed Third-Party Dependencies Create a Supply-Chain Exposure
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /portfolios
POST /portfolios
PUT /portfolios/{id}
DELETE /portfolios/{id}
GET /portfolios/{id}/assets
POST /portfolios/{id}/assets
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /portfolios/{id}/assets
POST /portfolios/{id}/assets
PUT /portfolios/{id}/assets/{ticker}
DELETE /portfolios/{id}/assets/{ticker}
GET /portfolios/{id}/performance?period=weekly
GET /portfolios/{id}/summary
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /alerts
POST /alerts
DELETE /alerts/{id}
GET /user/subscription
POST /user/subscription/upgrade
This mismatch becomes security-relevant because the skill claims a narrower Yahoo-Finance-style analysis role while also referencing broader external data sources and social-media scraping workflows, including subprocess-style Twitter/X access. Undisclosed external collection and tool usage can surprise operators, expand attack surface, and bypass expected review of network, shell, and data-handling behavior.
This mismatch becomes security-relevant because the skill claims a narrower Yahoo-Finance-style analysis role while also referencing broader external data sources and social-media scraping workflows, including subprocess-style Twitter/X access. Undisclosed external collection and tool usage can surprise operators, expand attack surface, and bypass expected review of network, shell, and data-handling behavior.
This mismatch becomes security-relevant because the skill claims a narrower Yahoo-Finance-style analysis role while also referencing broader external data sources and social-media scraping workflows, including subprocess-style Twitter/X access. Undisclosed external collection and tool usage can surprise operators, expand attack surface, and bypass expected review of network, shell, and data-handling behavior.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)
**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)
**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock
The example directs users to create a .env file inside the skill directory containing live auth tokens. In developer workflows, files in project directories are frequently copied, backed up, indexed, or accidentally committed, making this a practical credential exposure vector rather than a theoretical one.
Create .env file in the skill directory:
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
for line in f:
os.environ.copy() harvests all environment variables, including any credentials loaded from .env or supplied by the runtime, and forwards them to the external bird process. That creates a direct secret-exposure path to a separate executable that may log, transmit, or otherwise misuse those values, especially dangerous in an analysis skill that should not require broad credential handling.
for category, query in searches:
try:
env = os.environ.copy()
result = subprocess.run(
[bird_bin, "search", query, "-n", "15", "--json"],
capture_output=True, text=True, timeout=30, env=env
Referencing a local .env as a credential source indicates the skill is designed to access secrets from the host filesystem. In a third-party skill, that expands the privilege boundary and is dangerous because users may not expect the code to read local secret material simply to perform rumor scanning.
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"
def load_env():
"""Load environment variables from .env file."""
The code actively reads the .env file line-by-line, which confirms local credential access rather than a passive reference. Combined with subsequent subprocess execution, this creates a direct path from host-stored secrets into an external tool, making the skill materially riskier than a normal market-data utility.
BIRD_ENV = Path(__file__).parent.parent / ".env"
def load_env():
"""Load environment variables from .env file."""
if BIRD_ENV.exists():
for line in BIRD_ENV.read_text().splitlines():
if '=' in line and not line.startswith('#'):
Copying the entire process environment and handing it to a subprocess is a classic overexposure pattern because it can leak unrelated secrets, cloud credentials, CI tokens, and API keys into a tool that only needs a small subset. In this skill, the danger is higher because the environment was just populated from a local .env file, so the child process almost certainly receives sensitive authentication material.
for query in queries[:4]: # Limit to avoid rate limits
try:
cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
env = os.environ.copy()
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)
This second environment copy repeats the same secret-propagation issue for another Bird CLI invocation. Any sensitive variable present in the parent process becomes available to the external binary, increasing the blast radius if that binary is compromised or logs its environment.
for query in queries[:3]:
try:
cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
env = os.environ.copy()
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)
The planning document materially expands the skill from stock/crypto analysis into a full commercial platform with user accounts, portfolios, mobile apps, backend infrastructure, and monetization. Scope expansion itself is not code execution, but it increases the attack surface and introduces privileged capabilities not reflected in the manifest, which can mislead reviewers and users about what the skill is intended to do.
Adding payments and subscription processing introduces sensitive financial workflows, webhook handling, receipt validation, and account-tier changes that are outside the stated skill scope. If implemented without explicit scoping and controls, this can expose users to billing abuse, spoofed webhook events, or unauthorized subscription changes.
The document proposes Mixpanel/Amplitude and Sentry collection but does not mention user-facing consent, privacy notice, or limits on what telemetry is sent. In a financial context, telemetry can easily capture portfolio behavior, identifiers, or sensitive usage patterns, creating privacy exposure and regulatory risk.
The README instructs users to extract and store live X/Twitter authentication cookies (AUTH_TOKEN and CT0) from browser DevTools and place them into a local .env file. Session cookies are highly sensitive credentials; exposing or mishandling them can enable account hijacking or unauthorized access, and the documentation does not clearly warn users about the risks or recommend safer alternatives. In the context of an agent skill that encourages automation and third-party CLI use, this is more dangerous because users may normalize copying privileged browser secrets into tool configs.
The skill advertises commands and execution examples that imply shell, network, file read/write, and environment access, but it does not declare any explicit tool scope or permissions. In an agent ecosystem, missing scope declarations weakens least-privilege controls and can cause operators or orchestrators to grant broader access than users expect.
The instructions tell users to place AUTH_TOKEN and CT0 in a local .env file without any warning about secret handling, file permissions, accidental commits, or reuse risk. These tokens can grant account access to Twitter/X-related tooling, so poor storage guidance increases the chance of credential theft or leakage through logs, backups, or repositories.
The documentation simultaneously claims the system produces clear BUY/HOLD/SELL signals while later disclaiming that it is not providing trading signals. This inconsistency can mislead users or downstream agents about the tool’s purpose and level of actionability, increasing the chance that recommendations are treated as de facto financial advice or automated decision inputs.
The documentation instructs users to obtain Twitter/X authentication material from browser cookies and reuse it in the skill, which is a form of credential harvesting and sidesteps safer OAuth-style flows. In the context of a stock-analysis tool, this expands the trust boundary unnecessarily and creates risk of account takeover, token leakage, and misuse of a user's social media session.
The markdown tells users to manually copy highly sensitive auth_token and ct0 values and place them into environment variables or a local .env file, but gives no security warning about secret handling, shell history, file permissions, accidental commits, or credential reuse risk. This materially increases the chance of credential disclosure and misuse, especially for less technical users following the guide verbatim.
No suspicious patterns detected.