Back to skill

Security audit

0605-tosr2-csig

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent stock and crypto analysis tool, but its optional X/Twitter integration handles live session cookies in an unsafe, overbroad way.

Review before installing. The finance-analysis features are generally purpose-aligned, but avoid enabling the X/Twitter integration unless you understand the risk of copying browser session cookies. Do not place unrelated secrets in this skill's .env file, avoid granting Terminal Full Disk Access if possible, and prefer running social scanning in a restricted environment with a pinned, trusted bird version.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/hot_scanner.py:22
Finding

Hot Scanner exposes the complete process environment to a network-capable third-party CLI

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/rumor_scanner.py:30
Finding

Rumor Scanner exposes the complete process environment to the Bird CLI

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:143
Finding

Documentation directs users to install an unpinned global network-capable dependency

Content
View full analysis
Remediation
View remediation
``` - Install it locally to the project rather than globally. - Commit and enforce a lockfile containing integrity hashes. - Use `npm ci` for reproducible installation. - Review the selected package version and its transitive dependencies before distribution. - Disable lifecycle scripts during installation when they are unnecessary: ```bash npm ci --ignore-scripts ``` - Verify the package's publisher, source repository, release provenance, and integrity. - Document the exact reviewed version in both `README.md` and `SKILL.md`. - Combine dependency pinning with a minimal subprocess environment so that compromise of the executable does not expose unrelated secrets. - Consider replacing the external CLI with a narrowly scoped, reviewed integration or running it in a sandbox. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (55)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill claims a Yahoo Finance-focused analysis workflow, yet the documentation expands into CoinGecko, Google News, Twitter/X via bird, and local file/env handling without clearly surfacing these as part of the declared behavior. Hidden or under-declared external integrations and persistence are risky because they broaden data exposure, credential usage, and execution pathways beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims a Yahoo Finance-focused analysis workflow, yet the documentation expands into CoinGecko, Google News, Twitter/X via bird, and local file/env handling without clearly surfacing these as part of the declared behavior. Hidden or under-declared external integrations and persistence are risky because they broaden data exposure, credential usage, and execution pathways beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims a Yahoo Finance-focused analysis workflow, yet the documentation expands into CoinGecko, Google News, Twitter/X via bird, and local file/env handling without clearly surfacing these as part of the declared behavior. Hidden or under-declared external integrations and persistence are risky because they broaden data exposure, credential usage, and execution pathways beyond user expectations.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide instructs users to extract live auth_token and ct0 browser cookies and reuse them for automation, which is effectively credential harvesting and replay. Those cookies can grant direct access to a user's X account, bypass safer auth flows, and may violate platform security expectations; if exposed, they can enable unauthorized access, impersonation, or account abuse.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The documentation explicitly tells users to place live session secrets in a local .env file inside the skill directory. Secrets stored this way are commonly leaked through source control, backups, debug output, shared workspaces, or downstream tooling, and here they would expose reusable X/Twitter session credentials rather than limited-scope API keys.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The code conditionally opens and reads a local .env, which commonly contains secrets, and imports all values into the live process environment. In the context of this skill, that becomes more dangerous because a later subprocess inherits those secrets, creating an unnecessary credential exposure path.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

os.environ.copy() forwards the entire host environment to the bird subprocess, which may include API keys, tokens, proxy credentials, cloud metadata settings, and secrets loaded earlier from .env. If the external CLI is malicious, compromised, or simply logs diagnostic data, those credentials can be exposed or exfiltrated.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The load_env function reads arbitrary key-value pairs from a local .env file and imports them into the process without validation or scoping. In this skill, that behavior is security-relevant because those secrets are then passed to an external CLI, increasing the chance of inadvertent credential disclosure.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

Using os.environ.copy() after loading a .env file forwards the entire environment to the Bird CLI, not just the credentials it needs. If the child process, its plugins, or logs are compromised, unrelated secrets such as API keys, cloud tokens, or database credentials may be exposed.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

This second os.environ.copy() repeats the same overbroad secret propagation issue in another execution path. The skill context makes this more concerning because it is a market-scanning utility that contacts external services, so unnecessary credential exposure to external-facing tooling is not justified by core functionality.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The plan explicitly includes Mixpanel/Amplitude and Sentry telemetry but does not mention user-facing notice, consent, or controls over analytics/error-reporting data collection. In a consumer finance app, telemetry can capture sensitive behavioral and portfolio-related metadata, creating privacy, compliance, and trust risks if users are not clearly informed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to extract Twitter/X session tokens from browser cookies and store them in a local .env file, which normalizes handling highly sensitive bearer-style credentials outside an official OAuth flow. If these tokens are exposed through shell history, backups, logs, repo commits, or weak file permissions, an attacker could hijack the user's X session and access or act through that account.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises executable commands, network access, local file storage, environment-variable usage, and shell execution, but it does not declare an explicit tool scope such as permissions or allowed-tools. This increases the attack surface because a host or user may not realize the full capabilities being granted, especially given the skill's use of external data sources, local persistence, and credential-dependent integrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs users to create a .env file containing authentication tokens for Twitter/X tooling but provides no warning about secret handling, storage location, permissions, or exclusion from source control. This can lead to accidental credential disclosure through logs, shell history, backups, repository commits, or overly permissive filesystem settings.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill analyzes stocks and cryptocurrencies using Yahoo Finance data, but the architecture explicitly lists additional external sources: CNN Fear & Greed, SEC EDGAR, and Google News. Those sources materially expand the skill beyond a Yahoo-Finance-based analyzer into broader sentiment, filing, and news intelligence collection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented check_breaking_news behavior scans Google News RSS for crisis keywords, which is a distinct news-monitoring capability rather than Yahoo Finance data analysis. Given the manifest frames the skill around Yahoo Finance data, this documented behavior is a meaningful scope expansion in how signals are generated.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The concept document states the solution 'Produces a clear BUY / HOLD / SELL signal,' which is an explicit trading-style recommendation. Later in the same document, it says the skill is 'NOT' a source of 'Trading signals,' creating a direct contradiction in the documented intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation tells users to grant Terminal Full Disk Access and handle live X/Twitter authentication material without prominently warning that these permissions and cookies are highly sensitive. Full Disk Access materially increases the blast radius of any compromised tool or shell session, and auth cookies can enable account takeover or unauthorized API actions if copied, logged, or leaked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.