Back to skill

Security audit

0605-tosr2-csig-04

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stock-analysis purpose, but its optional X/Twitter scanners handle browser session tokens and pass the full local environment to a third-party CLI, which needs careful review before installation.

Review before installing, especially if you plan to use /stock_hot or /stock_rumors with X/Twitter. Do not place unrelated secrets in the skill .env, avoid running it in environments with cloud or CI credentials, prefer --no-social unless you specifically need X/Twitter data, and understand that portfolio/watchlist data is stored locally in plaintext. No artifact-backed deception, exfiltration, or destructive payload was found, but the credential and subprocess handling is too broad to treat as low risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
README.md:141
Finding

Unpinned Global Installation of a Privileged Third-Party CLI

Content
View full analysis
Remediation
View remediation
``` 2. Record and verify the expected package integrity digest. 3. Prefer a project-local dependency with a committed lockfile over a global installation. 4. Document the reviewed upstream repository and package identity. 5. Resolve the executable to an explicitly configured, verified path before execution. 6. Run the CLI in a restricted environment with only the credentials and filesystem access it requires. 7. Consider replacing browser-session-cookie authentication with an official, narrowly scoped API integration. 8. Establish a dependency update process that includes source review and integrity validation before changing the pinned version. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hot_scanner.py:22
Finding

Third-Party CLI Receives the Complete Project and Host Environment

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/watchlist.py:55
Finding

Portfolio and Watchlist Data Are Stored Without Explicit Owner-Only Permissions

Content
View full analysis
list[WatchlistItem]: """Load watchlist from file.""" if WATCHLIST_FILE.exists(): data = json.loads(WATCHLIST_FILE.read_text()) return [WatchlistItem(**item) for item in data] return [] def save_watchlist(items: list[WatchlistItem]): """Save watchlist to file.""" ensure_dirs() data = [asdict(item) for item in items] WATCHLIST_FILE.write_text(json.dumps(data, indent=2)) ``` The portfolio store similarly relies on the current process umask: ```python def get_default_portfolio_path() -> Path: """Get the default portfolio storage path.""" state_dir = os.environ.get("CLAWDBOT_STATE_DIR", os.path.expanduser("~/.clawdbot")) portfolio_dir = Path(state_dir) / "skills" / "stock-analysis" portfolio_dir.mkdir(parents=True, exist_ok=True) ``` ```python def _save(self) -> None: """Save portfolio data to disk atomically.""" self.path.parent.mkdir(parents=True, exist_ok=True) # Atomic write: write to temp file, then rename tmp_path = self.path.with_suffix(".tmp") try: with open(tmp_path, "w", encoding="utf-8") as f: json.dump(self._data, f, indent=2) tmp_path.replace(self.path) except Exception: if tmp_path.exists(): tmp_path.unlink() raise ``` ### Technical Analysis The files contain investment-related state, including ticker selections, notes, quantities, acquisition costs, targets, stop prices, and strategy signals. They are pers ...[truncated 1768 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (61)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description centers on Yahoo Finance analysis, but the markdown also documents additional external sources such as CoinGecko, Google News, and Twitter/X, plus use of a local CLI tool for social access. This expands the attack and data-exposure surface beyond what a user may reasonably expect, especially when third-party auth tokens and subprocess execution are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description centers on Yahoo Finance analysis, but the markdown also documents additional external sources such as CoinGecko, Google News, and Twitter/X, plus use of a local CLI tool for social access. This expands the attack and data-exposure surface beyond what a user may reasonably expect, especially when third-party auth tokens and subprocess execution are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill description centers on Yahoo Finance analysis, but the markdown also documents additional external sources such as CoinGecko, Google News, and Twitter/X, plus use of a local CLI tool for social access. This expands the attack and data-exposure surface beyond what a user may reasonably expect, especially when third-party auth tokens and subprocess execution are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description centers on Yahoo Finance analysis, but the markdown also documents additional external sources such as CoinGecko, Google News, and Twitter/X, plus use of a local CLI tool for social access. This expands the attack and data-exposure surface beyond what a user may reasonably expect, especially when third-party auth tokens and subprocess execution are involved.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The documentation directs users to store live Twitter/X authentication material in a .env file inside the project directory. In practice, project-local secret files are commonly exposed through version control mistakes, backups, support bundles, or overly broad file access by other tools, making this a credential-handling weakness.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Accessing a local .env file is often legitimate, but in this skill it is broader than necessary and creates unnecessary exposure of credentials unrelated to stock analysis. Because the loaded secrets are later available to subprocesses and the entire runtime, this crosses from simple configuration handling into a meaningful credential-exposure risk.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The .env handling pattern indicates indiscriminate reading of local secrets/configuration. In the context of a skill that also executes an external binary, this increases the chance that credentials are exposed to code outside the Python process.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Invoking an undocumented external CLI for Twitter/X introduces unnecessary local execution capability into a data-analysis skill. In this context, the binary may run with the user's privileges and access inherited secrets or files, making the feature materially riskier than ordinary outbound HTTP requests.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

Copying the full process environment and handing it to a child process can expose API keys, tokens, and other secrets to that subprocess. In this file, the risk is amplified because the environment was previously populated from .env, so sensitive values are intentionally aggregated and then propagated to an external executable.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Referencing a repository-local .env file as an input source for credentials indicates the script is designed to access locally stored secrets. In combination with external subprocess execution, this creates a realistic credential-exposure path even if the script does not explicitly print or exfiltrate those values itself.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The load_env implementation parses and imports every non-comment entry from .env into the runtime environment. This indiscriminate secret loading is risky because it makes all local credentials available to subsequent code and child processes, far beyond the apparent need of a rumor-scanning utility.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

Using os.environ.copy() after loading .env forwards the entire environment to the Bird subprocess, not just the one or two variables it may need. That broad credential exposure is dangerous because any secret present in the parent environment becomes accessible to the child process and potentially to its logs, plugins, crashes, or downstream behavior.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

This second subprocess path repeats the same environment-harvesting pattern, again exposing the full parent environment to an external CLI. In an agent setting, that materially increases the risk of unintended secret access beyond the narrow purpose of performing searches.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes tracking product analytics with Mixpanel/Amplitude and error tracking with Sentry, which can affect user privacy by collecting behavioral and diagnostic data. The document includes a generic privacy-policy note elsewhere, but it does not explicitly warn users here that analytics and monitoring data will be collected or transmitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to extract and place live X/Twitter browser authentication cookies (AUTH_TOKEN and CT0) into a local .env file without a clear security warning, scoping guidance, or safer alternative. Session tokens taken from browser cookies can grant account access if leaked through shell history, logs, backups, repo commits, or other local compromise, making this a real credential-handling weakness.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises commands that read/write local state, access external services, and invoke shell commands, but it does not declare any explicit tool scope or permissions. That makes the trust boundary unclear for users and orchestrators, increasing the chance the skill is granted broader capabilities than expected or reviewed less rigorously.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is broad enough to match common investment-related requests, which can cause over-invocation of a capability-rich skill. In context, that matters because the skill can access network resources, shell commands, and local files, so accidental triggering increases exposure to unnecessary data access and external calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown instructs users to place Twitter/X authentication tokens in a local .env file without any clear warning about token sensitivity, storage risks, rotation, or least-privilege handling. This can lead to credential leakage through shell history, accidental commits, permissive file permissions, or reuse across unrelated tools.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document first claims the system 'Produces a clear BUY / HOLD / SELL signal' and explains the reasoning, which is effectively a trading recommendation. Later it says the skill is 'NOT' financial advice and 'NOT' trading signals, creating a direct contradiction in the documented intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to obtain Twitter/X authentication tokens from browser cookies and, on macOS, grant Terminal Full Disk Access to retrieve or validate them. This expands privileges beyond the core stock-analysis purpose and normalizes credential extraction practices that could expose unrelated browser data or account session secrets if the environment or tooling is compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.