Back to plugin

Security audit

openInvest

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent investment-assistant plugin with disclosed local portfolio writes, credential storage, and backups, but no evidence of hidden exfiltration or real trading.

Install only if you are comfortable letting the plugin manage local investment records and store API or remote-hub credentials under ~/openInvest. Protect backup zip files because they include .env secrets, consider pinning OPENINVEST_SPEC for reproducible backend execution, and confirm any ledger-changing buy/sell/deposit/withdraw actions before they run.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (44)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skills/invest/README.md (reported line 45)May include surrounding context.

bash
cd $INVEST_HOME
# 1. Edit SKILL.md / scripts/run.sh / references/*.md
vim skills/invest/SKILL.md
# 2. Test (the symlink is already live; no reinstall needed)
~/.claude/skills/invest/scripts/run.sh status
# 3. commit + push

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skills/invest/README.md (reported line 35)May include surrounding context.

bash skills/install.sh # installs both invest + invest-setup

text

`install.sh` installs into `~/.claude/skills/invest/` and `~/.claude/skills/invest-setup/`,
whose contents are symlinks pointing back at the source directory — updates to `SKILL.md` /
`scripts/` take effect immediately, no reinstall needed. The backend itself is distributed via
PyPI; update it with `run.sh update`.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skills/invest/README.md (reported line 72)May include surrounding context.

CLAUDE_SKILLS_DIR=/some/other/path bash skills/install.sh

text

Usually unnecessary — Claude Code reads skills from `~/.claude/skills/<name>/` by default.

## Uninstall

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skills/invest/references/troubleshooting.md (reported line 76)May include surrounding context.

bash
curl -H "Authorization: Bearer $DEEPSEEK_API_KEY" \
  https://api.deepseek.com/v1/models

200 = key valid, 401 = key invalid. Have the user reissue one at

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to execute shell commands (run.sh, curl) but does not declare any tool scope such as permissions or allowed-tools. That makes invocation boundaries implicit, increasing the chance an agent or host grants broader shell access than intended and enabling unintended command execution paths.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/invest-backup/scripts/run.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash
# invest-backup — 备份/恢复 memory/ + db/ + .env + user_profile.json*
#
# 这些数据全部 .gitignore(含真实持仓/交易/委员会记录/凭据),git 里完全没有
# 历史版本。2026-07-08 migrate_profile.py 被直接跑了一次,无任何 safety guard

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/invest/scripts/run.sh (reported line 7)May include surrounding context.

sh
# 2026-07 起后端从 PyPI 分发(pypi.org/project/openinvest),本脚本不再
# git clone / uv sync / 自愈更新——那 180 行 bash 全部退役:
#   - 后端代码:uvx 按需拉 openinvest 包(缓存于 uv cache,首跑需网络)
#   - 数据目录:$INVEST_HOME(默认 ~/openInvest),只放 memory/ db/ .env static/
#   - 更新:`run.sh update`(= uvx --refresh,显式更新,不再启动时静默 git pull)
#   - GUI dist 拉取 / 远端模式提示等业务逻辑收进 openinvest-web(Python)
#

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/invest/SKILL.md (reported line 201)May include surrounding context.

md
# 2026-07 起后端从 PyPI 分发(pypi.org/project/openinvest),本脚本不再
# git clone / uv sync / 自愈更新——那 180 行 bash 全部退役:
#   - 后端代码:uvx 按需拉 openinvest 包(缓存于 uv cache,首跑需网络)
#   - 数据目录:$INVEST_HOME(默认 ~/openInvest),只放 memory/ db/ .env static/
#   - 更新:`run.sh update`(= uvx --refresh,显式更新,不再启动时静默 git pull)
#   - GUI dist 拉取 / 远端模式提示等业务逻辑收进 openinvest-web(Python)
#

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Including .env in backup archives causes API keys, SMTP credentials, and other secrets to be copied into a zip file under $ROOT/.backups. That materially expands the attack surface: anyone who can read the backup directory, move the archive off-host, or ingest it into logs/artifacts gains access to credentials that may enable broader compromise.

Content

Scanner excerpt · skills/invest-backup/scripts/run.sh (reported line 39)May include surrounding context.

sh
BACKUP_DIR="$ROOT/.backups"
# 备份对象:git 完全不追踪、又不可再生的数据。db/*.sqlite-journal 等 WAL 临时
# 文件不带——那是运行时产物,恢复时会自动重建,带了反而可能是半提交状态。
INCLUDE_PATHS=(memory db .env user_profile.json user_profile.json.bak)
EXCLUDE_GLOBS=("*.pyc" "*.sqlite-journal" "*.db-shm" "*.db-wal" "*.lock")

usage() {

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill explicitly includes .env in backups, which commonly contains SMTP/API credentials and other secrets. Even though the purpose is legitimate disaster recovery, packaging credentials into portable zip archives increases the risk of credential exposure through weak storage permissions, accidental sharing, or restore artifacts being copied to less trusted systems.

Content

Scanner excerpt · skills/invest-backup/SKILL.md (reported line 4)May include surrounding context.

md
---
name: invest-backup
version: 0.2.1 # x-release-please-version
description: Back up / restore openInvest's local state — memory/ (holdings, strategy, user profile, committee records, dream logs) + db/ (trade ledger, job run history, market-data cache) + .env (SMTP/API credentials) + user_profile.json. All of this data is .gitignore'd with no historical versions in git, so a single accidental overwrite (e.g. slipping and running some one-off migration/init script) means real data loss — no git revert available. **Proactive trigger scenarios** — "backup invest data / 备份一下 openInvest 的数据", "my holdings/strategy look wiped / 我的持仓/策略好像被清空了", "invest data is lost / invest 数据丢了", "restore invest backup / 恢复一下 invest 的备份", before any reinstall/migration of the openInvest deployment on this machine, or right before running an unfamiliar migration/init script (back up first, then act).
platforms: [linux, macos]
metadata:
  hermes:

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

The README explicitly instructs users to edit the skill protocol and scripts, and notes that symlinked contents become live immediately with no reinstall. In an agent-skill context, encouraging direct self-modification of prompts and execution scripts raises the risk of persistence, unsafe customization, or accidental weakening of security boundaries, especially because changes affect future invocations immediately.

Content

Scanner excerpt · skills/invest/README.md (reported line 44)May include surrounding context.

bash
cd $INVEST_HOME
# 1. Edit SKILL.md / scripts/run.sh / references/*.md
vim skills/invest/SKILL.md
# 2. Test (the symlink is already live; no reinstall needed)
~/.claude/skills/invest/scripts/run.sh status

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skills/invest/SKILL.md (reported line 72)May include surrounding context.

md
runs on Coordinator just to save that much.

**No sub-task delegation capability and no key configured**: do not force your way through
Coordinator, do not fabricate a verdict, and do not write code to brute-force around it —
just call `run_committee` (you will get a clear error) and honestly tell the user
"LLM_API_KEY needs to be configured".

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

This is a real session/credential persistence concern because the skill directs durable storage of API endpoint and authentication material in $INVEST_HOME/.env. Persistent plaintext secrets increase the chance of later compromise from local attackers, misconfigured permissions, backups, or accidental exfiltration by other tools.

Content

Scanner excerpt · skills/invest-setup/SKILL.md (reported line 51)May include surrounding context.

  • Hub address? (e.g. https://invest.example.com or http://10.0.0.6:8765)
    • Does the hub have auth enabled? A token (INVEST_API_TOKEN) or a Cloudflare Access service token (CF_ACCESS_CLIENT_ID/SECRET)? Skip if not enabled.
  1. Write the answers into $INVEST_HOME/.env (only these two or three lines are needed; no DeepSeek key / Gmail / 5-question flow — those all live on the hub):
    env
    INVEST_API_BASE=https://invest.example.com
    

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

Referencing uvx openinvest without a pinned package version creates a supply-chain and integrity risk: future upstream releases could change behavior, introduce breaking changes, or ship malicious code. Because this skill is intended for daily use and can affect portfolio state, unpinned execution materially raises risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to invoke uvx openinvest without pinning a specific package version or artifact digest, which creates a supply-chain risk. A compromised or malicious future release on PyPI could be pulled automatically and executed in the user's environment, and this skill is explicitly intended for frequent/daily use, increasing exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This is the same unpinned uvx openinvest execution path repeated later in the README, again exposing users to unintended execution of whatever version is current on PyPI. Because the backend is fetched on demand, the trust boundary extends to the package registry and maintainer account security.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest and top-level guidance repeatedly constrain the skill to one-time onboarding and say it should step aside after setup. The FAQ nevertheless instructs the agent to run run.sh update, which is a software maintenance/upgrade capability outside the stated onboarding-only scope. Even if presented as troubleshooting advice, it expands the skill's practical role beyond initial setup.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description narrows the skill to first-time onboarding via the canonical 5-question init flow. However, the body of the skill defines a second operational mode, 'Path B', that skips init entirely and instead configures remote connectivity by persisting INVEST_API_BASE and optional authentication tokens into $INVEST_HOME/.env. That is a materially different behavior than 'wraps run.sh init --from-stdin'.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation exposes wealth-context and account-profile management capabilities that go beyond simple investment analysis and verdict generation. Expanding the agent's authority into sensitive profile fields increases the chance of unauthorized modification, privacy overreach, and harmful decision-making based on altered user context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The statement that the agent has access to ALL backend functionality materially broadens authority beyond the manifest's described workflows. In a tool-using agent, this creates a confused-deputy risk where the model may invoke powerful write or admin-like operations that the user did not intend when activating an analysis-oriented investment skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill collects remote authentication material and persists it locally in .env, which expands its access from simple onboarding to credential handling for a remote service. That broader capability increases the blast radius if the workstation, skill runtime, or config files are exposed, especially because the manifest does not clearly foreground this secret-management behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Claiming the command set is closed while later referencing additional native commands creates inconsistent tool boundaries. Ambiguity in what tools exist can cause agents to hallucinate, fall back to undocumented endpoints, or bypass intended safety constraints because the authoritative interface is unclear.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are very broad and include normal conversational language such as 'analyze X' or 'show portfolio', which can cause accidental invocation in unrelated contexts. In a skill that can read financial data, write ledger entries, and run shell-backed workflows, overbroad activation increases the chance of unintended sensitive actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The protocol explicitly treats broad natural-language phrases like 'should I buy/sell X' and 'analyze X' as triggers for a multi-step investment workflow that can invoke shell commands and spawn delegated subtasks. In a daily-use financial skill, overly broad trigger phrases increase the chance of accidental activation from ordinary conversation, causing unintended analysis runs, persistence of decision artifacts, and potentially nudging users toward financial actions they did not intend to initiate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This README is a markdown file, so vague trigger guidance applies. The listed activation examples include generic phrases like "show portfolio" and "analyze X," which are common requests and the README does not provide negative examples or constraints explaining when these phrases should or should not invoke this specific skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.