Back to skill

Security audit

0602-tosr2-06

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis skill mostly matches its stated purpose, but its optional Twitter/X scanning asks users to expose active browser session credentials and passes broad environment data to a third-party CLI.

Install only if you are comfortable with the non-social stock features and avoid enabling Twitter/X scanning as written. Do not paste primary X/Twitter session cookies into this skill, do not grant Terminal Full Disk Access for it, and do not run the bird integration unless the CLI is pinned, trusted, and given only the minimum required environment variables.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
README.md:143
Finding

Unpinned Global Installation of a Credential-Handling Third-Party CLI

Content
View full analysis
Remediation
View remediation
``` 2. Avoid global installation. Install the package in a dedicated project directory and execute the pinned local binary. 3. Commit and verify an npm lockfile containing package integrity hashes. 4. Review the pinned package, its lifecycle scripts, and transitive dependencies before recommending it. 5. Disable unnecessary npm lifecycle scripts during installation where compatible: ```bash npm install --ignore-scripts ``` 6. Run the CLI in an isolated environment with access only to required credentials and files. 7. Document the package source, reviewed version, expected checksum, and upgrade-review procedure. 8. Encourage users to use a dedicated Twitter/X account or short-lived session rather than a high-value primary account. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hot_scanner.py:22
Finding

Complete Environment Exposed to an External Credential-Handling CLI

Content
View full analysis
Remediation
View remediation
dict[str, str]: allowed = {"AUTH_TOKEN", "CT0"} credentials = {} if path.exists(): for raw_line in path.read_text(encoding="utf-8").splitlines(): line = raw_line.strip() if not line or line.startswith("#") or "=" not in line: continue key, value = line.split("=", 1) key = key.strip() if key in allowed: credentials[key] = value.strip().strip('"').strip("'") return credentials ``` 2. Construct a minimal subprocess environment rather than copying the entire environment: ```python credentials = load_bird_credentials(ENV_FILE) bird_env = { "PATH": os.environ.get("PATH", ""), "HOME": os.environ.get("HOME", ""), "LANG": os.environ.get("LANG", "C.UTF-8"), "AUTH_TOKEN": credentials.get("AUTH_TOKEN", ""), "CT0": credentials.get("CT0", ""), } ``` 3. Reject missing credentials instead of falling back to unrelated environment data. 4. Store Twitter/X credentials in a dedicated file rather than a general-purpose project `.env`. 5. Require restrictive permissions on the credential file, such as owner read/write only. 6. Avoid globally mutating `os.environ`, especially at module import time. 7. Run the CLI under an isolated account or sandbox without access to portfolio data or unrelated secrets. 8. Add automated tests asserting that unrelated variables are not inherited by the subprocess. ]]>

T07 · Tool Hijacking and Spoofing

Note
Location
scripts/hot_scanner.py:363
Finding

PATH-Based Bird Executable Selection Allows Local Tool Spoofing

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (51)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill markets itself as Yahoo Finance-based, but the documentation also introduces undeclared third-party sources and tools including CoinGecko, Google News, Reddit, and Twitter/X CLI. Undisclosed external dependencies increase supply-chain, privacy, and data-handling risk because users and runners may not realize the skill reaches additional services or requires extra tooling/authentication.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill markets itself as Yahoo Finance-based, but the documentation also introduces undeclared third-party sources and tools including CoinGecko, Google News, Reddit, and Twitter/X CLI. Undisclosed external dependencies increase supply-chain, privacy, and data-handling risk because users and runners may not realize the skill reaches additional services or requires extra tooling/authentication.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill markets itself as Yahoo Finance-based, but the documentation also introduces undeclared third-party sources and tools including CoinGecko, Google News, Reddit, and Twitter/X CLI. Undisclosed external dependencies increase supply-chain, privacy, and data-handling risk because users and runners may not realize the skill reaches additional services or requires extra tooling/authentication.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill markets itself as Yahoo Finance-based, but the documentation also introduces undeclared third-party sources and tools including CoinGecko, Google News, Reddit, and Twitter/X CLI. Undisclosed external dependencies increase supply-chain, privacy, and data-handling risk because users and runners may not realize the skill reaches additional services or requires extra tooling/authentication.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Instructing users to grant Terminal Full Disk Access to retrieve browser-linked Twitter/X credentials is an overbroad privilege escalation unrelated to normal stock scanning. Full Disk Access exposes far more local data than necessary and can enable theft of unrelated secrets, browser data, documents, and tokens if the terminal session or downstream tooling is compromised.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guidance explicitly instructs users to copy live Twitter/X authentication cookies and reuse them via environment variables or a .env file, which operationalizes session hijacking mechanics. Reusing browser session tokens outside their original context is dangerous because compromise of the host, file, shell environment, or repository can directly expose active account access.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

Creating a local .env file containing AUTH_TOKEN and CT0 stores highly sensitive session credentials in a common plaintext location that is frequently mishandled, copied, or accidentally committed. In the context of copied browser cookies, this becomes especially risky because disclosure of the file may grant direct access to the user's Twitter/X account.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The file explicitly accesses a repository-local .env, which commonly stores credentials and tokens. In isolation that can be normal, but here it is security-relevant because the loaded secrets are promoted into global environment state and become available to downstream subprocess execution.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

Opening and iterating over .env contents gives the script credential-handling capability. Given the later environment propagation to an external executable, this is not merely configuration loading; it creates a realistic path for secret exposure beyond the skill's stated stock-analysis purpose.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Twitter/X feature executes an external CLI with the agent's privileges, which is a significant execution capability beyond ordinary HTTP-based stock analysis. Because the binary may come from PATH or user-specific locations, a malicious or trojaned bird executable could exfiltrate credentials, run arbitrary commands, or tamper with results.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

os.environ.copy() duplicates the full process environment and passes it to the bird subprocess. Because the script earlier imports arbitrary .env contents into os.environ, this can leak API keys, tokens, and unrelated secrets to the external CLI, which is especially risky when the binary is not tightly controlled.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Referencing a repo-adjacent .env file for credentials is risky because local secret files are easy to over-broaden, mishandle, or accidentally expose through subprocess inheritance and debugging. In this script, the .env is used specifically to feed an external CLI, which heightens the chance that credentials leave the immediate application boundary.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The load_env function reads arbitrary key/value pairs from .env and imports them into process environment variables without scoping. This creates a credential-access pattern where secrets become broadly available to the script and its subprocesses, which is dangerous when combined with external command execution.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
89% confidence
Finding

Copying the full current environment and passing it to an external CLI can expose unrelated secrets, tokens, and infrastructure settings to that child process. In a skill that explicitly loads a .env file first, this materially raises the risk of credential disclosure to third-party tooling or any compromised dependency in the CLI chain.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
89% confidence
Finding

This second subprocess path repeats the same secret-exposure pattern by forwarding the entire environment to an external binary. Because the scanner’s purpose is social/news collection rather than secret handling, the broad propagation of environment data is unnecessary and increases blast radius if the external tool is malicious, compromised, or overly verbose in logs/errors.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a stock and crypto analysis skill focused on analysis, watchlists, alerts, and portfolio-related functions. This document explicitly repositions it as a commercial mobile app with backend services, user authentication, subscription billing, and monetization, which is materially broader than the described skill behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The stated purpose is financial market analysis using Yahoo Finance data, but this roadmap adds Stripe subscriptions, webhook handling, receipt validation, and tier management. Billing infrastructure is a business-platform capability rather than an obvious requirement for performing stock or crypto analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The roadmap adds push notifications and product analytics without corresponding user-facing notice, consent, or data-use transparency in the feature description. In a consumer finance context, this can lead to undisclosed collection or use of behavioral and device data, creating privacy, regulatory, and trust risks even if the implementation is otherwise secure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README instructs users to extract AUTH_TOKEN and CT0 cookies from browser DevTools and store them in a .env file, but provides no warning that these are active session credentials equivalent to account access. If exposed through logs, shell history, backups, repo commits, or local compromise, an attacker could hijack the user's X/Twitter session and access or act through the account.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises commands that invoke local scripts, read/write persistent files, access network sources, and may consume environment-based credentials, yet it declares no explicit tool scope or permissions boundary. This increases the chance that an agent runtime grants broader capabilities than users expect, creating unnecessary exposure to filesystem, shell, and network misuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.