Back to skill

Security audit

0608-tosr2-01

Security checks for vulnerabilities and agentic risk

Overview

The skill is finance-related and mostly purpose-aligned, but its optional social scanners handle live X/Twitter session credentials in an overbroad and risky way.

Review carefully before installing. The core finance analysis is coherent, but avoid the Twitter/X setup unless you can isolate it: do not place browser session cookies in a shared or repository-local .env, prefer running scans with --no-social, and only use a pinned, trusted bird installation with a minimal environment.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hot_scanner.py:22
Finding

Hot Scanner Exposes the Full Process Environment to an External CLI

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/rumor_scanner.py:30
Finding

Rumor Scanner Exposes the Full Process Environment to the Bird CLI

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/hot_scanner.py:364
Finding

PATH-Based Bird Executable Hijacking in the Hot Scanner

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:152
Finding

Unpinned Global Installation of a Credential-Bearing Third-Party CLI

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (49)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is framed as Yahoo Finance analysis, but the documentation reveals use of additional sources such as Google News, CoinGecko, and Twitter/X via an external CLI. Hidden expansion of network and subprocess behavior changes the trust boundary and can expose users to unanticipated data exfiltration, third-party dependency risk, or auth-token misuse, especially where optional social integrations require credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is framed as Yahoo Finance analysis, but the documentation reveals use of additional sources such as Google News, CoinGecko, and Twitter/X via an external CLI. Hidden expansion of network and subprocess behavior changes the trust boundary and can expose users to unanticipated data exfiltration, third-party dependency risk, or auth-token misuse, especially where optional social integrations require credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is framed as Yahoo Finance analysis, but the documentation reveals use of additional sources such as Google News, CoinGecko, and Twitter/X via an external CLI. Hidden expansion of network and subprocess behavior changes the trust boundary and can expose users to unanticipated data exfiltration, third-party dependency risk, or auth-token misuse, especially where optional social integrations require credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is framed as Yahoo Finance analysis, but the documentation reveals use of additional sources such as Google News, CoinGecko, and Twitter/X via an external CLI. Hidden expansion of network and subprocess behavior changes the trust boundary and can expose users to unanticipated data exfiltration, third-party dependency risk, or auth-token misuse, especially where optional social integrations require credentials.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The example directs users to place active authentication secrets in a project .env file inside the skill directory. In practice, local .env files are frequently mishandled, copied, logged, or committed, which can expose credentials that provide direct access to a user's X/Twitter session.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Referencing and loading a repository-local .env file is a credential-access pattern because such files commonly contain secrets unrelated to the current feature. In this skill, the danger is heightened by subsequent inheritance into an external subprocess, making the secrets accessible outside the Python process.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The existence check and subsequent processing of .env facilitate opportunistic collection of local credentials whenever the script runs in a repository containing secrets. Given the skill context, this is more dangerous than normal configuration loading because those secrets are later exposed to a spawned external tool.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Executing the external bird CLI introduces local command execution capability that goes beyond ordinary stock analysis and creates dependency on a separate binary outside normal package review. In this skill, that risk is amplified because the subprocess receives the process environment and can make its own outbound requests using any loaded credentials.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
99% confidence
Finding

os.environ.copy() forwards the entire process environment to the external bird subprocess, which can include API keys, cloud credentials, session tokens, and any secrets loaded from .env. This is dangerous because the child process is an external binary with network capability, so broad secret exposure can lead to credential exfiltration or misuse.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Reading the .env file and importing all key-value pairs into process environment variables broadens secret exposure and facilitates later leakage to subprocesses. In this skill, that behavior directly feeds into full-environment inheritance by an external CLI, making credential access materially risky rather than merely configurational.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
96% confidence
Finding

Copying the full environment and passing it to a subprocess unnecessarily propagates all loaded secrets, tokens, and local configuration to the Bird CLI. If that external tool is malicious, compromised, or verbose in logs/crash reports, it can harvest credentials unrelated to its function.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
96% confidence
Finding

This second subprocess path repeats the same credential-exposure pattern by forwarding the entire parent environment to an external binary. Because the skill relies on a nonstandard third-party CLI and explicitly loads a .env file earlier, the context makes this more dangerous than a typical subprocess call.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file describes product analytics and error monitoring via Mixpanel/Amplitude, Sentry, and CloudWatch, which implies collection and transmission of user or device telemetry. The document includes general security and privacy references elsewhere, but it does not explicitly warn users here that behavior/usage data may be collected for analytics and monitoring.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to extract Twitter/X session cookies (AUTH_TOKEN and CT0) from browser DevTools and store them in a local .env file, but provides no warning about treating these as sensitive credentials. Session tokens can grant account access equivalent to a logged-in browser session, so disclosure through logs, shell history, backups, repos, or multi-user systems could enable account takeover or abuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises commands that invoke Python and shell tooling, use environment-backed auth for Twitter/X, perform network access, and persist portfolio/watchlist data, but it declares no explicit tool scope or permissions. This creates a capability-transparency gap: users and orchestrators cannot accurately constrain what the skill may access, increasing the chance of overbroad execution or unintended data handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description is broad enough to match many generic finance requests, which can cause the agent to invoke this skill in contexts the user did not clearly intend. Because the skill has network, shell, and local persistence characteristics, overbroad routing increases the chance of unnecessary external lookups, data storage, or use of optional integrations on sensitive financial queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents persistent storage of portfolios and watchlists under the user's home directory but does not clearly warn that potentially sensitive financial tracking data will be written to disk. This can surprise users, create privacy exposure on shared systems, and leave durable data artifacts that may be accessed by other local processes or users depending on filesystem permissions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation expands the skill from passive market analysis into authenticated access to a third-party social platform via an external CLI and browser-derived session material. That is security-sensitive behavior because it encourages users to expose live account credentials and install tooling that can act on their behalf, even if the stated goal is sentiment gathering.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide instructs users to manually extract auth_token and ct0 values from browser cookies and reuse them locally, which is direct handling of session credentials. Session tokens can grant account access equivalent to being logged in, so storing or copying them outside the browser creates a significant credential-compromise risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.