Back to skill

Security audit

simontest-1

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent stock-analysis tool, but its optional X/Twitter feature handles live session credentials in an under-scoped way.

Install only if you are comfortable storing portfolio/watchlist data locally and sending tickers or holdings-derived requests to finance/news services. Avoid the optional X/Twitter setup unless you isolate the environment, do not grant broad Full Disk Access, do not keep live browser session cookies in a project .env, and verify or pin the bird CLI before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hot_scanner.py:22
Finding

Entire Process Environment Exposed to the External Bird CLI

Content
View full analysis
Remediation
View remediation
dict[str, str]: allowed = {"AUTH_TOKEN", "CT0"} credentials = {} if path.exists(): for raw_line in path.read_text().splitlines(): line = raw_line.strip() if not line or line.startswith("#") or "=" not in line: continue key, value = line.split("=", 1) key = key.strip() if key in allowed: credentials[key] = value.strip().strip('"').strip("'") return credentials ``` 3. Construct a minimal subprocess environment instead of copying the parent environment: ```python credentials = load_bird_credentials(ENV_FILE) env = { "PATH": os.environ.get("PATH", ""), "LANG": os.environ.get("LANG", "C.UTF-8"), **credentials, } ``` 4. Refuse to invoke Bird when either required credential is absent instead of inheriting arbitrary fallback values. 5. Resolve Bird to a trusted, fixed path and verify that it is a regular file with expected ownership and permissions. 6. Run the social scanner in an isolated process or container without unrelated Agent credentials. 7. Apply the same remediation to both Twitter search functions in `rumor_scanner.py` and to `HotScanner.scan_twitter()`. 8. Keep the `.env` file outside the project source tree where practical, restrict it to owner-only permissions, and document that it must not be committed to version control. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:152
Finding

Unpinned Global CLI Receives Reusable Browser Session Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (57)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The file documents persistent storage in ~/.clawdbot for portfolios and watchlists without declaring storage permissions or retention details, and several prominent capabilities may be only partially implemented. Undeclared persistence and overstated features are risky because users may unknowingly store sensitive financial holdings locally and trust functionality that has not been fully validated.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file documents persistent storage in ~/.clawdbot for portfolios and watchlists without declaring storage permissions or retention details, and several prominent capabilities may be only partially implemented. Undeclared persistence and overstated features are risky because users may unknowingly store sensitive financial holdings locally and trust functionality that has not been fully validated.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The file documents persistent storage in ~/.clawdbot for portfolios and watchlists without declaring storage permissions or retention details, and several prominent capabilities may be only partially implemented. Undeclared persistence and overstated features are risky because users may unknowingly store sensitive financial holdings locally and trust functionality that has not been fully validated.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file documents persistent storage in ~/.clawdbot for portfolios and watchlists without declaring storage permissions or retention details, and several prominent capabilities may be only partially implemented. Undeclared persistence and overstated features are risky because users may unknowingly store sensitive financial holdings locally and trust functionality that has not been fully validated.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document instructs users to extract auth_token and ct0 cookies from their browser and place them into a .env file or environment variables without emphasizing that these are highly sensitive session credentials. If leaked through logs, shell history, source control, backups, or other local compromise, an attacker could reuse them to access the user's Twitter/X account session.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Storing live authentication tokens in a local .env file creates a credential exposure point, especially in a skill directory that may be synced, backed up, or accidentally committed. In this context the tokens are not low-risk API keys but reusable session artifacts, so compromise could directly enable account takeover or unauthorized access.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
97% confidence
Finding

Copying the full process environment is effectively harvesting all available secrets for use by a subprocess. In this skill, the risk is amplified because .env values are loaded into os.environ earlier, so any token present becomes accessible to the external bird executable.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

Referencing a local .env file is not inherently malicious, but in this script it is part of a credential-loading flow that feeds an external CLI. That creates a real risk of secret exposure if the file contains tokens for Twitter/X or other services and the child process receives more than it strictly needs.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The load_env function reads arbitrary key-value pairs from .env and injects them into os.environ without scoping. In combination with later subprocess inheritance, this can leak or misuse credentials beyond their intended purpose.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
94% confidence
Finding

Copying the full parent environment and passing it to an external CLI can disclose unrelated secrets such as API keys, tokens, cloud credentials, or CI secrets to that subprocess. In this skill context, the script intentionally loads a .env file first, which makes the environment especially likely to contain sensitive credentials and increases the blast radius if the external binary is compromised, logs env values, or invokes other components.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
94% confidence
Finding

This is the same broad environment exposure pattern in a second code path. Because the skill depends on external social-media tooling and network access, giving that tool the entire environment unnecessarily increases the chance of credential leakage or misuse.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The plan explicitly includes product analytics and error tracking but does not pair that collection with any concrete in-app notice, consent flow, or disclosure mechanism beyond a general privacy-policy mention elsewhere. For a consumer finance app that processes portfolio, watchlist, and behavioral data, undisclosed telemetry can create privacy and compliance exposure, especially if third-party analytics vendors receive sensitive usage patterns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to extract live X/Twitter browser authentication tokens and store them in a local .env file, but it does not warn that these are highly sensitive session credentials equivalent to account access. If mishandled, logged, committed, shared, or read by other local processes, an attacker could reuse them to access the user's social media account or abuse the integration.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises commands that invoke Python and shell-based tooling, use network sources, and persist data locally, but it does not declare any explicit tool scope or permissions. This creates an authorization and transparency gap: operators and users cannot easily understand the true capability surface before installation or execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Twitter/X setup instructs users to place AUTH_TOKEN and CT0 in a local .env file without warning about the sensitivity of those values or safe handling practices. These are high-value session credentials; if stored insecurely, committed to source control, or exposed through logs, they can allow account misuse or session hijacking.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The document states that the system pulls data from Yahoo Finance, CNN Fear & Greed, SEC EDGAR, Google News, and other sources, including async fetches and RSS scanning. Under SQP-2 for markdown files, behavior that may affect privacy or system integrity should be disclosed; this file documents the network behavior but does not warn users that running the skill will contact third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file explains that the skill stores portfolio holdings, cost basis, target prices, and watchlist state in portfolios.json and watchlist.json. For markdown files, SQP-2 applies when the description omits warnings about behaviors affecting user data or privacy; here the persistence of personal financial data is documented structurally but not accompanied by any warning or disclosure about local storage.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation is internally inconsistent: it says the system produces clear BUY/HOLD/SELL signals and recommendations, while elsewhere disclaiming that it is not providing trading signals. In an investment context, this can mislead users and integrators about the skill’s purpose, compliance posture, and level of automation, increasing the risk that users treat advisory output as actionable financial direction without appropriate safeguards.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.