Back to skill

Security audit

test-0612

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent stock-analysis tool, but its optional Twitter/X scanners handle live session cookies and pass broad environment secrets to an external CLI.

Review before installing. The core stock analysis and local portfolio/watchlist features are coherent, but avoid the Twitter/X integration unless you are comfortable giving an external Bird CLI access to X session cookies. Prefer running hot scans with --no-social, do not store unrelated secrets in the skill .env, do not install unpinned global binaries for credential-bearing workflows, and rotate/revoke X sessions if those tokens are exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hot_scanner.py:22
Finding

Excessive Disclosure of Process Environment to the Third-Party Bird CLI

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
README.md:143
Finding

Unpinned Global Bird CLI Installation Receives Live Session Credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/analyze_stock.py:2
Finding

Runtime Python Dependencies Are Not Reproducibly Locked

Content
View full analysis
=3.10" # dependencies = [ # "yfinance>=0.2.40", # "pandas>=2.0.0", # "fear-and-greed>=0.4", # "edgartools>=2.0.0", # "feedparser>=6.0.0", # ] # /// ``` From `scripts/dividends.py`: ```python # /// script # requires-python = ">=3.10" # dependencies = [ # "yfinance>=0.2.40", # "pandas>=2.0.0", # ] # /// ``` From `scripts/portfolio.py`: ```python # /// script # requires-python = ">=3.10" # dependencies = ["yfinance>=0.2.40"] # /// ``` From `scripts/watchlist.py`: ```python # /// script # requires-python = ">=3.10" # dependencies = [ # "yfinance>=0.2.40", # ] # /// ``` ### Technical Analysis The inline dependency metadata specifies only lower version bounds. Commands documented as `uv run` may therefore resolve a future package version that was not present when the Skill was audited. No dependency lockfile or package hashes were identified in the supplied project structure. As a result, identical commands can install materially different code at different times. Python packages execute code during installation, import, and normal runtime, so an upstream compromise or unsafe future release can affect routine stock-analysis operations. There is no evidence that the currently named packages are malicious. This finding concerns non-reproducible dependency resolution and the resulting supply-chain exposure. ### Attack Path 1. An upstream package or one of its transitive dependencies publishes a compromised future version that still satisfies the declared lower bound. 2. A user runs one of the documented `uv run` commands in an environment without a previously fixed depend ...[truncated 681 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (56)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The documentation suggests a Yahoo Finance analysis skill, but the flagged behavior includes use of additional external data sources, local cache writes, and invocation of an external CLI for Twitter/X access. Hidden expansion of data flows and subprocess usage matters in a finance-oriented skill because it can expose user data, pull untrusted content, or execute extra binaries outside the expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation suggests a Yahoo Finance analysis skill, but the flagged behavior includes use of additional external data sources, local cache writes, and invocation of an external CLI for Twitter/X access. Hidden expansion of data flows and subprocess usage matters in a finance-oriented skill because it can expose user data, pull untrusted content, or execute extra binaries outside the expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documentation suggests a Yahoo Finance analysis skill, but the flagged behavior includes use of additional external data sources, local cache writes, and invocation of an external CLI for Twitter/X access. Hidden expansion of data flows and subprocess usage matters in a finance-oriented skill because it can expose user data, pull untrusted content, or execute extra binaries outside the expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation suggests a Yahoo Finance analysis skill, but the flagged behavior includes use of additional external data sources, local cache writes, and invocation of an external CLI for Twitter/X access. Hidden expansion of data flows and subprocess usage matters in a finance-oriented skill because it can expose user data, pull untrusted content, or execute extra binaries outside the expected trust boundary.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

These instructions describe extracting browser cookies from x.com and reusing them as tool credentials, which is effectively manual session-token harvesting. If those cookies are exposed through shell history, .env files, logs, backups, or repository commits, an attacker may be able to hijack the user's Twitter/X session and act as that account.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The example directs users to create a .env file in the skill directory containing live authentication tokens. In practice, project-local .env files are frequently leaked via accidental commits, debugging output, backups, or overly broad file access by other tools, exposing credentials that can grant account access.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The script explicitly accesses a local .env file, which commonly contains API keys, tokens, and other secrets. For a hot-scanner feature, broad credential ingestion is unnecessary and materially increases the blast radius if any later code, dependency, or subprocess leaks environment data.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The existence check and subsequent use of the repository .env file is part of the same credential-access pattern: the skill is designed to read local secrets opportunistically. In the presence of external network calls and subprocess execution, that access is more dangerous because it broadens what sensitive data may be exposed indirectly.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Twitter/X feature invokes an external bird CLI, introducing a new execution and trust boundary unrelated to ordinary finance-data retrieval. In a skill expected to analyze market data, this context expansion is risky because the binary may use local auth state, network access, and inherited environment data in ways the user did not anticipate.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
99% confidence
Finding

os.environ.copy() captures the full process environment, including secrets loaded from .env or provided by the host, and passes them into the spawned bird process. That creates a clear secret-exposure path to an external binary whose behavior is outside this script's control.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Referencing a project-local .env for runtime credential loading indicates direct access to stored secrets. In this skill, the danger comes from coupling secret retrieval with later subprocess execution, which increases the chance that credentials are propagated beyond the trusted Python runtime.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Reading .env contents line-by-line to populate runtime secrets is a real credential-handling risk when done without scoping, validation, or disclosure. In the context of a networked rumor scanner that launches an external CLI, this increases the blast radius of any secret stored in the environment.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

Copying the full process environment and passing it to an external binary can expose unrelated secrets such as API keys, tokens, and internal configuration to that child process. In this script, that risk is heightened because .env contents are first loaded into os.environ, so the subprocess inherits more secrets than it needs.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

This second os.environ.copy() repeats the same high-risk pattern of exposing the entire parent environment to a third-party CLI. If the CLI logs, crashes, or is compromised, inherited secrets may be disclosed even though they are unrelated to the search operation.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a stock/crypto analysis skill with portfolio, watchlist, alerts, and signal detection features. This roadmap reframes it as a commercial mobile product with authentication, monetization, and cloud platform components, which goes materially beyond the stated analysis-focused skill behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Stripe integration, webhook handling, receipt validation, and subscription tier management are commercial billing features, not direct requirements of performing stock/crypto analysis or portfolio monitoring. While useful for a product business, they are contextually separate from the manifest's functional purpose as an analysis skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The roadmap explicitly plans analytics and error-tracking tooling but does not pair it with user-facing disclosure, consent, or data-minimization controls. In a finance-oriented app that may process portfolio, alert, and usage data, undisclosed telemetry can expose sensitive behavioral and financial information to third parties and create compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README instructs users to extract live Twitter/X session tokens from browser cookies and place them in a local .env file, but it does not warn that these are highly sensitive authentication credentials equivalent to account access. If handled insecurely, committed to source control, shared in logs, or exposed on a multi-user system, they could enable account takeover or abuse of the user's X account.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises commands that invoke Python and shell tooling, access environment data, read/write local files, and fetch network resources, but it declares no explicit tool scope or permission boundaries. In an agent ecosystem, missing permission declarations increases the chance that the skill is granted broader capabilities than users expect, enabling unintended filesystem, network, or shell access during execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions tell users to place authentication tokens in a .env file for Twitter/X integration but do not warn about secret handling, file permissions, accidental commits, or token rotation. That omission can lead to credential leakage through source control, logs, shared directories, or weak local protection, especially because the skill also uses external tooling and social-media access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.