Back to skill

Security audit

testskill-zip1

Security checks for vulnerabilities and agentic risk

Overview

The skill’s finance features are coherent, but its optional Twitter/X scanning uses risky browser-session credential handling and passes broad environment secrets to an external CLI.

Use the core stock, dividend, portfolio, and watchlist features with caution around stored financial data. Avoid enabling Twitter/X scanning unless you are comfortable handling X session cookies; do not grant Terminal Full Disk Access, do not keep unrelated secrets in the skill .env file, and consider running scans with --no-social. If you do use bird, verify the package source/version and revoke X session tokens if they may have been exposed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hot_scanner.py:22
Finding

Hot Scanner exposes the complete inherited environment to a network-capable third-party subprocess

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/rumor_scanner.py:33
Finding

Rumor Scanner exposes all parent and project environment secrets to Bird

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
docs/HOT_SCANNER.md:122
Finding

Authentication-capable Bird dependency is installed globally without version or integrity pinning

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
docs/HOT_SCANNER.md:132
Finding

Documentation recommends granting Terminal Full Disk Access for optional social scanning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (57)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 114)May include surrounding context.

md
GET  /portfolios
   POST /portfolios
   PUT  /portfolios/{id}
   DELETE /portfolios/{id}

   GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 119)May include surrounding context.

md
GET  /portfolios/{id}/assets
   POST /portfolios/{id}/assets
   PUT  /portfolios/{id}/assets/{ticker}
   DELETE /portfolios/{id}/assets/{ticker}

   GET  /portfolios/{id}/performance?period=weekly
   GET  /portfolios/{id}/summary

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · App-Plan.md (reported line 126)May include surrounding context.

md
GET  /alerts
   POST /alerts
   DELETE /alerts/{id}

   GET  /user/subscription
   POST /user/subscription/upgrade

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding is valid insofar as the documentation indicates persistent local state and broader capabilities without corresponding declared permissions. Hidden or underdeclared persistence is security-relevant because it can surprise users, retain sensitive portfolio/watchlist data, and evade policy enforcement even if the mismatch itself is not exploit code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding is valid insofar as the documentation indicates persistent local state and broader capabilities without corresponding declared permissions. Hidden or underdeclared persistence is security-relevant because it can surprise users, retain sensitive portfolio/watchlist data, and evade policy enforcement even if the mismatch itself is not exploit code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding is valid insofar as the documentation indicates persistent local state and broader capabilities without corresponding declared permissions. Hidden or underdeclared persistence is security-relevant because it can surprise users, retain sensitive portfolio/watchlist data, and evade policy enforcement even if the mismatch itself is not exploit code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding is valid insofar as the documentation indicates persistent local state and broader capabilities without corresponding declared permissions. Hidden or underdeclared persistence is security-relevant because it can surprise users, retain sensitive portfolio/watchlist data, and evade policy enforcement even if the mismatch itself is not exploit code.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 88)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TODO.md (reported line 193)May include surrounding context.

md
- [ ] Add timeout per indicator (10s max)
- [ ] Test with multiple stocks in sequence
- [ ] Measure actual runtime improvement
- [ ] Update SKILL.md with new runtime (target: 3-4s)

**Expected Impact**:
- Reduce runtime from 6-10s to 3-4s per stock

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to obtain live Twitter/X auth material via browser cookies or tokens and provide them to the tool. That creates a credential-handling and account-compromise risk, especially because browser-cookie extraction and local token storage can expose reusable session secrets beyond the narrow needs of a stock-analysis skill.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation explicitly instructs users to extract live Twitter/X authentication cookies from their browser and store them for tool use. This is dangerous because session-cookie harvesting bypasses normal app authorization boundaries and can expose full account sessions if the tokens are leaked, logged, or reused.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The example directs users to place live Twitter/X session credentials in a project-local .env file. Storing reusable auth secrets in local plaintext files creates a practical risk of accidental disclosure through backups, logs, shell history, screenshots, or source-control mistakes, and the danger is amplified because these are session tokens rather than limited API keys.

Content

Scanner excerpt · docs/HOT_SCANNER.md (reported line 149)May include surrounding context.

Create .env file in the skill directory:

bash
# /path/to/stock-analysis/.env
AUTH_TOKEN=your_auth_token_here
CT0=your_ct0_token_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 22)May include surrounding context.

python
from collections import defaultdict
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 23)May include surrounding context.

python
from concurrent.futures import ThreadPoolExecutor, as_completed

# Load .env file if exists
ENV_FILE = Path(__file__).parent.parent / ".env"
if ENV_FILE.exists():
    with open(ENV_FILE) as f:
        for line in f:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

os.environ.copy() copies all ambient environment variables, including secrets loaded from .env, and forwards them to the external bird process. If that binary is malicious, compromised, or simply over-privileged, it can access API keys, tokens, and other credentials unrelated to Twitter/X scanning.

Content

Scanner excerpt · scripts/hot_scanner.py (reported line 387)May include surrounding context.

python
for category, query in searches:
                try:
                    env = os.environ.copy()
                    result = subprocess.run(
                        [bird_bin, "search", query, "-n", "15", "--json"],
                        capture_output=True, text=True, timeout=30, env=env

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

Referencing a repository-adjacent .env file for credentials is a real security concern in a skill because it creates an implicit secret dependency and encourages local secret storage without access controls or transparency. In combination with the subprocess calls, these credentials are then made available to an external binary.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 30)May include surrounding context.

python
# Bird CLI path
BIRD_CLI = "/home/clawdbot/.nvm/versions/node/v24.12.0/bin/bird"
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The code reads raw lines from .env and imports them directly into environment variables, which constitutes credential access and propagation without validation or scoping. In an agent skill, this increases the blast radius of any stored secret and can unintentionally couple unrelated credentials to external network operations.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 33)May include surrounding context.

python
BIRD_ENV = Path(__file__).parent.parent / ".env"

def load_env():
    """Load environment variables from .env file."""
    if BIRD_ENV.exists():
        for line in BIRD_ENV.read_text().splitlines():
            if '=' in line and not line.startswith('#'):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
88% confidence
Finding

Copying the entire process environment and passing it to an external CLI unnecessarily exposes every loaded secret, not just the credentials required for Twitter search. In this script, load_env() imports a potentially broad .env file first, so the subprocess may receive unrelated API keys or tokens that could be read, logged, or mishandled by the external binary.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 79)May include surrounding context.

python
for query in queries[:4]:  # Limit to avoid rate limits
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
88% confidence
Finding

This is the same excessive-environment exposure pattern in the second subprocess path. Because the code forwards the full environment to a third-party CLI, any secrets present in the runtime can be unintentionally disclosed beyond the Python process boundary.

Content

Scanner excerpt · scripts/rumor_scanner.py (reported line 132)May include surrounding context.

python
for query in queries[:3]:
        try:
            cmd = [BIRD_CLI, 'search', query, '-n', '15', '--json']
            env = os.environ.copy()
            
            result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a stock/crypto analysis skill with portfolio, alerts, and related analytics features. This document states an intent to transform it into a commercial mobile app with backend services, authentication, subscriptions, monetization, and AWS infrastructure, which materially broadens the behavior and product scope beyond an analysis skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest focuses on market analysis, watchlists, alerts, scoring, and trend/rumor detection. The roadmap adds Stripe integration, webhook handling, receipt validation, and subscription lifecycle management, which are business-platform capabilities rather than stock-analysis functions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The plan includes Mixpanel/Amplitude and Sentry collection without any clear consent flow or prominent privacy notice tied to those analytics/error-tracking features. In a consumer finance context, telemetry may capture sensitive behavioral, portfolio, or diagnostic data, creating privacy, compliance, and data-minimization risk if deployed without explicit disclosure and controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README instructs users to retrieve AUTH_TOKEN and CT0 values from browser cookies and place them into a local .env file, but it does not clearly warn that these are sensitive session credentials equivalent to account access. If mishandled, logged, committed to source control, or exposed to other local processes, an attacker could reuse them to access the user's Twitter/X session.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope or permissions even though its documented behavior clearly involves shell execution, network access, file reads/writes, and environment-variable use. This is dangerous because operators and policy layers cannot accurately constrain the skill, increasing the chance of unintended command execution, data persistence, or network access beyond what users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation instructs users to place authentication tokens in a .env file without warning about sensitivity, storage risks, or scope of access. That can lead to accidental credential leakage through source control, logs, backups, or overbroad file access, especially because the skill also references shell/env capabilities and external integrations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.