T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/hot_scanner.py:22- Finding
Hot Scanner exposes the complete process environment to a network-capable third-party CLI
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent stock and crypto analysis tool, but its optional X/Twitter integration handles live session cookies in an unsafe, overbroad way.
Review before installing. The finance-analysis features are generally purpose-aligned, but avoid enabling the X/Twitter integration unless you understand the risk of copying browser session cookies. Do not place unrelated secrets in this skill's .env file, avoid granting Terminal Full Disk Access if possible, and prefer running social scanning in a restricted environment with a pinned, trusted bird version.
scripts/hot_scanner.py:22Hot Scanner exposes the complete process environment to a network-capable third-party CLI
scripts/rumor_scanner.py:30Rumor Scanner exposes the complete process environment to the Bird CLI
README.md:143Documentation directs users to install an unpinned global network-capable dependency
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /portfolios
POST /portfolios
PUT /portfolios/{id}
DELETE /portfolios/{id}
GET /portfolios/{id}/assets
POST /portfolios/{id}/assets
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /portfolios/{id}/assets
POST /portfolios/{id}/assets
PUT /portfolios/{id}/assets/{ticker}
DELETE /portfolios/{id}/assets/{ticker}
GET /portfolios/{id}/performance?period=weekly
GET /portfolios/{id}/summary
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /alerts
POST /alerts
DELETE /alerts/{id}
GET /user/subscription
POST /user/subscription/upgrade
The skill claims a Yahoo Finance-focused analysis workflow, yet the documentation expands into CoinGecko, Google News, Twitter/X via bird, and local file/env handling without clearly surfacing these as part of the declared behavior. Hidden or under-declared external integrations and persistence are risky because they broaden data exposure, credential usage, and execution pathways beyond user expectations.
The skill claims a Yahoo Finance-focused analysis workflow, yet the documentation expands into CoinGecko, Google News, Twitter/X via bird, and local file/env handling without clearly surfacing these as part of the declared behavior. Hidden or under-declared external integrations and persistence are risky because they broaden data exposure, credential usage, and execution pathways beyond user expectations.
The skill claims a Yahoo Finance-focused analysis workflow, yet the documentation expands into CoinGecko, Google News, Twitter/X via bird, and local file/env handling without clearly surfacing these as part of the declared behavior. Hidden or under-declared external integrations and persistence are risky because they broaden data exposure, credential usage, and execution pathways beyond user expectations.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)
**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)
**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock
The guide instructs users to extract live auth_token and ct0 browser cookies and reuse them for automation, which is effectively credential harvesting and replay. Those cookies can grant direct access to a user's X account, bypass safer auth flows, and may violate platform security expectations; if exposed, they can enable unauthorized access, impersonation, or account abuse.
The documentation explicitly tells users to place live session secrets in a local .env file inside the skill directory. Secrets stored this way are commonly leaked through source control, backups, debug output, shared workspaces, or downstream tooling, and here they would expose reusable X/Twitter session credentials rather than limited-scope API keys.
Create .env file in the skill directory:
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
The code conditionally opens and reads a local .env, which commonly contains secrets, and imports all values into the live process environment. In the context of this skill, that becomes more dangerous because a later subprocess inherits those secrets, creating an unnecessary credential exposure path.
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
for line in f:
os.environ.copy() forwards the entire host environment to the bird subprocess, which may include API keys, tokens, proxy credentials, cloud metadata settings, and secrets loaded earlier from .env. If the external CLI is malicious, compromised, or simply logs diagnostic data, those credentials can be exposed or exfiltrated.
for category, query in searches:
try:
env = os.environ.copy()
result = subprocess.run(
[bird_bin, "search", query, "-n", "15", "--json"],
capture_output=True, text=True, timeout=30, env=env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"
def load_env():
"""Load environment variables from .env file."""
The load_env function reads arbitrary key-value pairs from a local .env file and imports them into the process without validation or scoping. In this skill, that behavior is security-relevant because those secrets are then passed to an external CLI, increasing the chance of inadvertent credential disclosure.
BIRD_ENV = Path(__file__).parent.parent / ".env"
def load_env():
"""Load environment variables from .env file."""
if BIRD_ENV.exists():
for line in BIRD_ENV.read_text().splitlines():
if '=' in line and not line.startswith('#'):
Using os.environ.copy() after loading a .env file forwards the entire environment to the Bird CLI, not just the credentials it needs. If the child process, its plugins, or logs are compromised, unrelated secrets such as API keys, cloud tokens, or database credentials may be exposed.
for query in queries[:4]: # Limit to avoid rate limits
try:
cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
env = os.environ.copy()
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)
This second os.environ.copy() repeats the same overbroad secret propagation issue in another execution path. The skill context makes this more concerning because it is a market-scanning utility that contacts external services, so unnecessary credential exposure to external-facing tooling is not justified by core functionality.
for query in queries[:3]:
try:
cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
env = os.environ.copy()
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)
The plan explicitly includes Mixpanel/Amplitude and Sentry telemetry but does not mention user-facing notice, consent, or controls over analytics/error-reporting data collection. In a consumer finance app, telemetry can capture sensitive behavioral and portfolio-related metadata, creating privacy, compliance, and trust risks if users are not clearly informed.
The README instructs users to extract Twitter/X session tokens from browser cookies and store them in a local .env file, which normalizes handling highly sensitive bearer-style credentials outside an official OAuth flow. If these tokens are exposed through shell history, backups, logs, repo commits, or weak file permissions, an attacker could hijack the user's X session and access or act through that account.
The skill advertises executable commands, network access, local file storage, environment-variable usage, and shell execution, but it does not declare an explicit tool scope such as permissions or allowed-tools. This increases the attack surface because a host or user may not realize the full capabilities being granted, especially given the skill's use of external data sources, local persistence, and credential-dependent integrations.
The documentation instructs users to create a .env file containing authentication tokens for Twitter/X tooling but provides no warning about secret handling, storage location, permissions, or exclusion from source control. This can lead to accidental credential disclosure through logs, shell history, backups, repository commits, or overly permissive filesystem settings.
The manifest says the skill analyzes stocks and cryptocurrencies using Yahoo Finance data, but the architecture explicitly lists additional external sources: CNN Fear & Greed, SEC EDGAR, and Google News. Those sources materially expand the skill beyond a Yahoo-Finance-based analyzer into broader sentiment, filing, and news intelligence collection.
The documented check_breaking_news behavior scans Google News RSS for crisis keywords, which is a distinct news-monitoring capability rather than Yahoo Finance data analysis. Given the manifest frames the skill around Yahoo Finance data, this documented behavior is a meaningful scope expansion in how signals are generated.
The concept document states the solution 'Produces a clear BUY / HOLD / SELL signal,' which is an explicit trading-style recommendation. Later in the same document, it says the skill is 'NOT' a source of 'Trading signals,' creating a direct contradiction in the documented intent.
The documentation tells users to grant Terminal Full Disk Access and handle live X/Twitter authentication material without prominently warning that these permissions and cookies are highly sensitive. Full Disk Access materially increases the blast radius of any compromised tool or shell session, and auth cookies can enable account takeover or unauthorized API actions if copied, logged, or leaked.
No suspicious patterns detected.