Back to skill

Security audit

0605-cisg-tosr2

Security checks for vulnerabilities and agentic risk

Overview

This finance-analysis skill is mostly purpose-aligned, but its optional X/Twitter integration asks users to store live session cookies locally and passes broad environment secrets to an external CLI.

Review carefully before installing. The core finance scripts are understandable, but do not use the optional X/Twitter features with a primary account unless you are comfortable placing live session cookies in a plaintext local file and trusting an unpinned external CLI. Prefer running stock analysis with --no-social, avoid storing unrelated secrets in the skill .env, and treat all recommendations as informational rather than financial advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hot_scanner.py:22
Finding

Entire process environment exposed to a network-capable third-party CLI

Content
View full analysis

Vulnerability Details

File Location: scripts/hot_scanner.py:22-30, 387-392; scripts/rumor_scanner.py:30-38, 75-81, 128-134
Vulnerability Type: Excessive environment disclosure across a subprocess trust boundary
Risk Level: High

Vulnerable Code

scripts/hot_scanner.py:22-30:

python
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:
            line = line.strip()
            if line and not line.startswith("#") and "=" in line:
                key, value = line.split("=", 1)
                os.environ[key] = value

scripts/hot_scanner.py:387-392:

python
env = os.environ.copy()
result = subprocess.run(
    [bird_bin, "search", query, "-n", "15", "--json"],
    capture_output=True, text=True, timeout=30, env=env
)

scripts/rumor_scanner.py:30-38:

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):
                key, value = line.split('=', 1)
                os.environ[key.strip()] = value.strip().strip('"').strip("'")

scripts/rumor_scanner.py:75-81:

python
try:
    cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
    env = os.environ.copy()
    
    result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

The same pattern is repeated for buzz searches at scripts/rumor_scanner.py:128-134.

Technical Analysis

The scanners parse every entry in the project-level .env file and insert it into the global process environment. They then copy and disclose the entire inherited environment to the separately installed bird executable.

The Twitter integration only requi ...[truncated 1493 chars]

Remediation
View remediation

Remediation Suggestions

  1. Parse only the explicitly required AUTH_TOKEN and CT0 keys without modifying the global os.environ.
  2. Construct a minimal subprocess environment rather than using os.environ.copy():
    python
    bird_env = {
        "PATH": trusted_path,
        "AUTH_TOKEN": auth_token,
        "CT0": ct0,
    }
    
  3. Add only runtime variables demonstrably required by the CLI, such as a controlled HOME, locale, or certificate path.
  4. Reject unknown keys in the scanner-specific credential file.
  5. Resolve bird to a configured, trusted absolute path and verify that the executable is not writable by untrusted users.
  6. Run the CLI in a constrained environment or sandbox with restricted filesystem and network access.
  7. Avoid retaining Twitter credentials in the Python process after the subprocess finishes.

T08 · Insecure Dependencies

Warning
Location
README.md:143
Finding

Unpinned globally installed Twitter CLI receives sensitive credentials

Content
View full analysis

Vulnerability Details

File Location: README.md:143-153; SKILL.md:150-154; docs/HOT_SCANNER.md:127-151
Vulnerability Type: Unsafe third-party dependency installation and execution
Risk Level: Medium

Vulnerable Code

README.md:143-153:

markdown
### Twitter/X Setup (Optional)

1. Install bird CLI: `npm install -g @steipete/bird`
2. Login to x.com in Safari/Chrome
3. Create `.env` file:

AUTH_TOKEN=your_auth_token CT0=your_ct0_token

text

Get tokens from browser DevTools → Application → Cookies → x.com

Equivalent unpinned global installation instructions appear in SKILL.md:152 and docs/HOT_SCANNER.md:129.

Technical Analysis

The documentation instructs users to retrieve the latest available release of @steipete/bird and install it globally. No exact version, lockfile, package integrity value, or isolated execution environment is specified.

The resulting executable is subsequently launched with live X session credentials. Due to the environment handling described in the separate finding, it can also receive unrelated process secrets. A mutable dependency therefore occupies a security-sensitive position without a reproducible or verified installation boundary.

The audit found no evidence that the currently named package is intentionally malicious. The vulnerability is the unsafe dependency acquisition and privilege model, not a confirmed malicious package.

Attack Path

  1. The user follows the documented npm install -g @steipete/bird command.
  2. npm resolves the current mutable package release rather than a reviewed exact version.
  3. A compromised package release, dependency, registry account, or installation environment supplies malicious executable code.
  4. The scanners invoke the globally installed executable.
  5. The executable obtains X session tokens and potentially other inherited environment secrets.
  6. Malicious package code uses its local-user and ...[truncated 493 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a reviewed exact version rather than installing the latest release.
  2. Use a project-local lockfile and verify npm integrity metadata during installation.
  3. Avoid global installation; install the dependency in an isolated, dedicated directory or container.
  4. Document the reviewed package version and an upgrade-review process.
  5. Resolve and invoke an expected absolute executable path.
  6. Verify that the executable and its parent directories are not writable by untrusted users.
  7. Pass only the two required authentication values through a minimal environment.
  8. Consider replacing the external CLI with a narrowly scoped, reviewed integration if feasible.

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:143
Finding

Reusable X session cookies stored in a plaintext project file

Content
View full analysis

Vulnerability Details

File Location: README.md:143-153; SKILL.md:150-154; docs/HOT_SCANNER.md:132-158
Vulnerability Type: Insecure storage of session credentials
Risk Level: Medium

Vulnerable Code

README.md:143-153:

markdown
### Twitter/X Setup (Optional)

1. Install bird CLI: `npm install -g @steipete/bird`
2. Login to x.com in Safari/Chrome
3. Create `.env` file:

AUTH_TOKEN=your_auth_token CT0=your_ct0_token

text

Get tokens from browser DevTools → Application → Cookies → x.com

docs/HOT_SCANNER.md:146-158 additionally documents persistent or exported plaintext values:

markdown
Create `.env` file in the skill directory:

/path/to/stock-analysis/.env

AUTH_TOKEN=your_auth_token_here CT0=your_ct0_token_here

text

Or export as environment variables:

```bash
export AUTH_TOKEN="..."
export CT0="..."
text

### Technical Analysis

The documentation instructs users to copy reusable browser session cookies into a plaintext `.env` file in the Skill directory. It does not require owner-only file permissions, provide a credential-store alternative, document repository exclusion, or explain token rotation and cleanup.

The scripts then read that file directly. File access is governed by existing filesystem permissions and the user's default creation mask. If the project directory is shared, backed up, synchronized, or committed to version control, the session values can be disclosed.

### Attack Path

1. A user extracts live `auth_token` and `ct0` cookie values from the browser.
2. The user saves them in the project-level `.env` as instructed.
3. The file is created with permissions determined by the user's environment and remains in the project directory.
4. Another local account or process, a backup service, synchronization tool, archive, or accidental repository commit acquires the file.
5. An attacker reuses the disclosed values to imperso
...[truncated 522 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer an operating-system credential manager or another protected secret store.
  2. If a file is unavoidable, create it with owner-only permissions (0600) and verify permissions before reading it.
  3. Store credentials outside the project tree in a dedicated user configuration directory.
  4. Add .env to .gitignore and provide explicit warnings against committing, backing up, or sharing the file.
  5. Accept only the expected AUTH_TOKEN and CT0 keys.
  6. Document credential rotation, revocation, and cleanup procedures.
  7. Recommend using a dedicated, minimally privileged account rather than a primary social-media account.
  8. Avoid writing authentication values to logs, command lines, scanner output, or cache files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (49)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch includes undeclared local persistent storage of portfolio data, which is materially security-relevant because users may not realize financial holdings are being written to disk. In a finance-focused skill, silent or poorly disclosed storage of sensitive portfolio information increases privacy risk and can expose data if the host system or skill directory is accessible to other processes or users.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch includes undeclared local persistent storage of portfolio data, which is materially security-relevant because users may not realize financial holdings are being written to disk. In a finance-focused skill, silent or poorly disclosed storage of sensitive portfolio information increases privacy risk and can expose data if the host system or skill directory is accessible to other processes or users.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch includes undeclared local persistent storage of portfolio data, which is materially security-relevant because users may not realize financial holdings are being written to disk. In a finance-focused skill, silent or poorly disclosed storage of sensitive portfolio information increases privacy risk and can expose data if the host system or skill directory is accessible to other processes or users.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation explicitly instructs users to extract live Twitter/X authentication cookies and store them for tool reuse, which is a credential-handling anti-pattern. Those tokens can permit impersonation and account access if leaked, and documenting this process operationalizes credential theft techniques even if the stated purpose is benign.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Storing live X session tokens in a local .env file creates a straightforward credential exposure path through accidental commits, backups, local compromise, process inspection, or insecure file permissions. In this context the secrets are not app-scoped API keys but reusable session credentials, making compromise especially damaging.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Accessing a repository-local .env file is sensitive because such files commonly store credentials and tokens. In this script, reading it wholesale is not narrowly scoped to a documented need and contributes to later secret exposure through subprocess inheritance.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Opening and parsing the local .env file to populate environment variables grants the script access to potentially unrelated credentials. Because the script later invokes an external program, this local secret access meaningfully increases the chance of credential leakage beyond the stated analysis purpose.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The scanner executes an external CLI binary to access Twitter/X, which introduces arbitrary executable trust and expands the skill from passive analysis into local code execution. In this context, the risk is amplified because the binary may be resolved from PATH or user-specific locations and is executed with inherited environment data.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

Copying the full process environment and passing it into a child process can expose secrets such as API keys, tokens, and other credentials to an external executable. In this file, that risk is especially significant because the environment has already been augmented from a local .env file, increasing the chance that sensitive values are unnecessarily propagated.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

Copying the full parent environment and passing it into an external CLI exposes all environment variables available to the process, including secrets that may have been loaded from .env or the runtime host. In a skill that invokes a third-party binary to query external services, this is especially risky because any compromise, logging, plugin behavior, or unexpected child-process behavior can leak credentials.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

This second subprocess path repeats the same environment-harvesting pattern, forwarding the entire environment to the Bird CLI. Because the tool's purpose involves external network-facing collection, broad secret propagation to child processes meaningfully increases credential exposure risk.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file describes adding Mixpanel/Amplitude, Sentry, and CloudWatch for tracking usage, errors, and business metrics. Because markdown files should warn about behaviors affecting user data or privacy, the absence of any disclosure here is a notable omission even though the document discusses security and privacy elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to extract AUTH_TOKEN and CT0 values from browser cookies and place them into a local .env file, which encourages handling live session credentials outside the browser's protections. Those tokens can grant account access if leaked via shell history, dotfile sync, backups, logs, screenshots, or accidental commits, and the README does not include strong warnings, scope limitations, or safer alternatives.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises executable commands, persistent storage paths, external data sources, and optional credentialed integrations, but it does not declare a restrictive tool scope such as allowed tools or permissions. In an agent environment, missing scope boundaries increases the chance the skill can access shell, network, filesystem, or environment capabilities more broadly than users expect, which raises the risk of unintended data access or command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs users to create a local .env containing authentication tokens for Twitter/X integration without warning about secure storage, accidental commit, permissions, or token leakage. These credentials could be exposed through shell history, repository check-ins, backups, logs, or broad file access by the agent/runtime, leading to account compromise or misuse of authenticated services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The concept document explicitly promises clear BUY / HOLD / SELL signals for investment decisions before presenting a sufficiently prominent risk warning about financial loss. Even though later sections include disclaimers, users may anchor on the recommendation framing and treat the tool as actionable financial guidance, increasing the chance of harmful trading decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest says the skill analyzes stocks and cryptocurrencies using Yahoo Finance data, but this file documents a Hot Scanner that aggregates CoinGecko, Google News, Twitter/X, and planned Reddit signals, not just Yahoo Finance. It also documents saving scan results to local cache files, which goes beyond a plain data-analysis description and indicates persistent automation behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation expands the skill into using an external Twitter/X scraping/search CLI and handling live authentication material, which goes beyond passive stock analysis and introduces credential exposure and account-misuse risk. Because users are told to supply reusable auth tokens and integrate a third-party tool, the feature materially increases the attack surface for a finance-analysis skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.