T09 · Insecure Skill Coding Practices
- Location
scripts/hot_scanner.py:22- Finding
Hot Scanner Exposes the Full Process Environment to an External CLI
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is finance-related and mostly purpose-aligned, but its optional social scanners handle live X/Twitter session credentials in an overbroad and risky way.
Review carefully before installing. The core finance analysis is coherent, but avoid the Twitter/X setup unless you can isolate it: do not place browser session cookies in a shared or repository-local .env, prefer running scans with --no-social, and only use a pinned, trusted bird installation with a minimal environment.
scripts/hot_scanner.py:22Hot Scanner Exposes the Full Process Environment to an External CLI
scripts/rumor_scanner.py:30Rumor Scanner Exposes the Full Process Environment to the Bird CLI
scripts/hot_scanner.py:364PATH-Based Bird Executable Hijacking in the Hot Scanner
SKILL.md:152Unpinned Global Installation of a Credential-Bearing Third-Party CLI
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /portfolios
POST /portfolios
PUT /portfolios/{id}
DELETE /portfolios/{id}
GET /portfolios/{id}/assets
POST /portfolios/{id}/assets
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /portfolios/{id}/assets
POST /portfolios/{id}/assets
PUT /portfolios/{id}/assets/{ticker}
DELETE /portfolios/{id}/assets/{ticker}
GET /portfolios/{id}/performance?period=weekly
GET /portfolios/{id}/summary
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /alerts
POST /alerts
DELETE /alerts/{id}
GET /user/subscription
POST /user/subscription/upgrade
The skill is framed as Yahoo Finance analysis, but the documentation reveals use of additional sources such as Google News, CoinGecko, and Twitter/X via an external CLI. Hidden expansion of network and subprocess behavior changes the trust boundary and can expose users to unanticipated data exfiltration, third-party dependency risk, or auth-token misuse, especially where optional social integrations require credentials.
The skill is framed as Yahoo Finance analysis, but the documentation reveals use of additional sources such as Google News, CoinGecko, and Twitter/X via an external CLI. Hidden expansion of network and subprocess behavior changes the trust boundary and can expose users to unanticipated data exfiltration, third-party dependency risk, or auth-token misuse, especially where optional social integrations require credentials.
The skill is framed as Yahoo Finance analysis, but the documentation reveals use of additional sources such as Google News, CoinGecko, and Twitter/X via an external CLI. Hidden expansion of network and subprocess behavior changes the trust boundary and can expose users to unanticipated data exfiltration, third-party dependency risk, or auth-token misuse, especially where optional social integrations require credentials.
The skill is framed as Yahoo Finance analysis, but the documentation reveals use of additional sources such as Google News, CoinGecko, and Twitter/X via an external CLI. Hidden expansion of network and subprocess behavior changes the trust boundary and can expose users to unanticipated data exfiltration, third-party dependency risk, or auth-token misuse, especially where optional social integrations require credentials.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)
**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)
**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock
The example directs users to place active authentication secrets in a project .env file inside the skill directory. In practice, local .env files are frequently mishandled, copied, logged, or committed, which can expose credentials that provide direct access to a user's X/Twitter session.
Create .env file in the skill directory:
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here
Referencing and loading a repository-local .env file is a credential-access pattern because such files commonly contain secrets unrelated to the current feature. In this skill, the danger is heightened by subsequent inheritance into an external subprocess, making the secrets accessible outside the Python process.
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
The existence check and subsequent processing of .env facilitate opportunistic collection of local credentials whenever the script runs in a repository containing secrets. Given the skill context, this is more dangerous than normal configuration loading because those secrets are later exposed to a spawned external tool.
from concurrent.futures import ThreadPoolExecutor, as_completed
# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
with open(ENV_FILE) as f:
for line in f:
Executing the external bird CLI introduces local command execution capability that goes beyond ordinary stock analysis and creates dependency on a separate binary outside normal package review. In this skill, that risk is amplified because the subprocess receives the process environment and can make its own outbound requests using any loaded credentials.
os.environ.copy() forwards the entire process environment to the external bird subprocess, which can include API keys, cloud credentials, session tokens, and any secrets loaded from .env. This is dangerous because the child process is an external binary with network capability, so broad secret exposure can lead to credential exfiltration or misuse.
for category, query in searches:
try:
env = os.environ.copy()
result = subprocess.run(
[bird_bin, "search", query, "-n", "15", "--json"],
capture_output=True, text=True, timeout=30, env=env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"
def load_env():
"""Load environment variables from .env file."""
Reading the .env file and importing all key-value pairs into process environment variables broadens secret exposure and facilitates later leakage to subprocesses. In this skill, that behavior directly feeds into full-environment inheritance by an external CLI, making credential access materially risky rather than merely configurational.
BIRD_ENV = Path(__file__).parent.parent / ".env"
def load_env():
"""Load environment variables from .env file."""
if BIRD_ENV.exists():
for line in BIRD_ENV.read_text().splitlines():
if '=' in line and not line.startswith('#'):
Copying the full environment and passing it to a subprocess unnecessarily propagates all loaded secrets, tokens, and local configuration to the Bird CLI. If that external tool is malicious, compromised, or verbose in logs/crash reports, it can harvest credentials unrelated to its function.
for query in queries[:4]: # Limit to avoid rate limits
try:
cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
env = os.environ.copy()
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)
This second subprocess path repeats the same credential-exposure pattern by forwarding the entire parent environment to an external binary. Because the skill relies on a nonstandard third-party CLI and explicitly loads a .env file earlier, the context makes this more dangerous than a typical subprocess call.
for query in queries[:3]:
try:
cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
env = os.environ.copy()
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)
This markdown file describes product analytics and error monitoring via Mixpanel/Amplitude, Sentry, and CloudWatch, which implies collection and transmission of user or device telemetry. The document includes general security and privacy references elsewhere, but it does not explicitly warn users here that behavior/usage data may be collected for analytics and monitoring.
The README explicitly instructs users to extract Twitter/X session cookies (AUTH_TOKEN and CT0) from browser DevTools and store them in a local .env file, but provides no warning about treating these as sensitive credentials. Session tokens can grant account access equivalent to a logged-in browser session, so disclosure through logs, shell history, backups, repos, or multi-user systems could enable account takeover or abuse.
The skill advertises commands that invoke Python and shell tooling, use environment-backed auth for Twitter/X, perform network access, and persist portfolio/watchlist data, but it declares no explicit tool scope or permissions. This creates a capability-transparency gap: users and orchestrators cannot accurately constrain what the skill may access, increasing the chance of overbroad execution or unintended data handling.
The description is broad enough to match many generic finance requests, which can cause the agent to invoke this skill in contexts the user did not clearly intend. Because the skill has network, shell, and local persistence characteristics, overbroad routing increases the chance of unnecessary external lookups, data storage, or use of optional integrations on sensitive financial queries.
The skill documents persistent storage of portfolios and watchlists under the user's home directory but does not clearly warn that potentially sensitive financial tracking data will be written to disk. This can surprise users, create privacy exposure on shared systems, and leave durable data artifacts that may be accessed by other local processes or users depending on filesystem permissions.
The documentation expands the skill from passive market analysis into authenticated access to a third-party social platform via an external CLI and browser-derived session material. That is security-sensitive behavior because it encourages users to expose live account credentials and install tooling that can act on their behalf, even if the stated goal is sentiment gathering.
The guide instructs users to manually extract auth_token and ct0 values from browser cookies and reuse them locally, which is direct handling of session credentials. Session tokens can grant account access equivalent to being logged in, so storing or copying them outside the browser creates a significant credential-compromise risk.
No suspicious patterns detected.