Back to skill

Security audit

Market News Brief

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent market-news helper that fetches Yahoo Finance market data through a local script, with ordinary dependency and network-use cautions.

Before installing, consider running this in a normal constrained skill environment and pinning or locking yfinance if reproducibility matters. Expect outbound Yahoo Finance requests and a small /tmp lock file; I did not find credential access, destructive actions, persistence, or hidden exfiltration in the inspected artifact.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
src/main.py:4
Finding

Unpinned Runtime Dependency Allows Unreviewed Package Code to Execute

Content
View full analysis

Vulnerability Details

File Location: src/main.py:4-8
Vulnerability Type: Unpinned third-party runtime dependency
Risk Level: Medium

Vulnerable Code

python
# /// script
# requires-python = ">=3.12"
# dependencies = [
#   "yfinance",
# ]
# ///

Technical Analysis

The inline dependency metadata declares yfinance without an exact version, lockfile, or integrity hash. The documented execution workflow uses uv run, causing the dependency to be resolved and installed at runtime. Consequently, the code reviewed during this audit does not fully determine which dependency code will execute in future invocations.

If the package distribution is compromised, a malicious release is published, or a future release introduces unsafe behavior, runtime resolution may select that unreviewed version. Python package code can execute during import and normal library initialization, before the Skill completes its market-news operation.

This is a supply-chain weakness rather than evidence that the current yfinance package is malicious.

Attack Path

  1. An attacker compromises the upstream package publishing account, package distribution channel, or an eligible future package release.
  2. The attacker publishes a malicious or compromised yfinance version that still satisfies the unconstrained dependency declaration.
  3. A user or Agent invokes the documented uv run .../src/main.py command in an environment without a previously locked resolution.
  4. uv resolves and installs the attacker-controlled or otherwise unreviewed release.
  5. src/main.py imports service, which imports yfinance; dependency-controlled Python code then executes with the privileges and environment of the Skill process.
  6. That code could access files, environment variables, credentials, and network resources available to the invoking process or manipulate the generated market report.

Impact Assessment

Successful exploitation would provide code execution un ...[truncated 601 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin yfinance to an audited exact version rather than permitting unconstrained resolution:
python
# dependencies = [
#   "yfinance==<reviewed-version>",
# ]
  1. Generate and commit a uv.lock file so direct and transitive dependency versions remain reproducible.
  2. Require package integrity verification using hashes where supported by the deployment workflow.
  3. Install dependencies from an explicitly trusted package index and disable unintended fallback indexes to reduce dependency-confusion exposure.
  4. Update dependencies through a controlled process that includes source review, vulnerability scanning, and functional testing before changing the lockfile.
  5. Run the Skill with least privilege in an isolated environment that exposes no unnecessary credentials, writable directories, or network destinations.
  6. Cache or preinstall the reviewed dependency set during deployment instead of resolving new package versions whenever the Skill is invoked.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to run a local Python script via uv run, but the manifest does not declare any explicit tool scope or permissions despite static analysis detecting environment access capability. This weakens least-privilege controls because the runtime may expose environment variables or broader execution context than users or orchestrators expect, increasing the risk of secret disclosure or unintended system interaction if the script is modified or compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.