Back to skill

Security audit

Universal Trading

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is functional but asks for wallet authority and runs high-impact setup and trading actions with risky defaults.

Review this skill carefully before installing. Use only a fresh low-value wallet, avoid importing an existing funded private key, disable auto invite binding unless you explicitly want it, skip or sandbox the smoke test, and treat dynamic retry buys as capable of spending more than one attempt if a transaction outcome is ambiguous.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/bootstrap-example.sh:8
Finding

Automatic Retrieval and Execution of Unpinned Remote Code

Content
View full analysis
/dev/null 2>&1; then echo "Cloning $REPO_URL into $TARGET_DIR (git)" git clone "$REPO_URL" "$TARGET_DIR" return fi if [ "$FETCH_MODE" != "auto" ] && [ "$FETCH_MODE" != "tarball" ]; then echo "Invalid UNIVERSAL_ACCOUNT_EXAMPLE_FETCH: $FETCH_MODE" echo "Use one of: auto, git, tarball" exit 1 fi require_command curl require_command tar echo "Downloading source archive (fetch mode: $FETCH_MODE)." echo "Downloading $TARBALL_URL" tmp_dir="$(mktemp -d)" archive_path="$tmp_dir/universal-account-example.tar.gz" extract_dir="$tmp_dir/extract" curl -fsSL "$TARBALL_URL" -o "$archive_path" mkdir -p "$extract_dir" tar -xzf "$archive_path" -C "$extract_dir" source_dir="$(find "$extract_dir" -mindepth 1 -maxdepth 1 -type d | head -n 1)" if [ -z "${source_dir:-}" ] || [ ! -d "$source_dir" ]; then echo "Failed to locate extracted source directory." exit 1 fi mv "$source_dir" "$TARGET_DIR" rm -rf "$tmp_dir" } ``` ```bash echo "Installing npm dependencies in $TARGET_DIR" ( cd "$TARGET_DIR" ...[truncated 2565 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/init.sh:18
Finding

Wallet Private Key Exposed Through Command-Line Arguments

Content
View full analysis
] [--skip-smoke]" echo " ./init.sh import [--target ] [--skip-smoke]" } ``` ```bash while [ "$#" -gt 0 ]; do case "$1" in new) ACTION="new" shift ;; import) ACTION="import" shift if [ "$#" -eq 0 ]; then echo "Missing private key for import." print_usage exit 1 fi PRIVATE_KEY="$1" shift ;; ``` The key is then forwarded to another process as an argument: ```bash ( cd "$TARGET_DIR" if [ "$ACTION" = "new" ]; then bash "$SCRIPT_DIR/setup-wizard.sh" new else bash "$SCRIPT_DIR/setup-wizard.sh" import "$PRIVATE_KEY" fi ) ``` The setup wizard reads it from its argument vector: ```bash elif [ "$ACTION" = "import" ]; then PRIVATE_KEY="${2:-}" if [ -z "$PRIVATE_KEY" ]; then print_usage exit 1 fi if [[ ! "$PRIVATE_KEY" =~ ^0x[a-fA-F0-9]{64}$ ]]; then echo "Invalid private key format. Expected: 0x + 64 hex chars." exit 1 fi ``` ### Technical Analysis Command-line arguments are not an appropriate channel for cryptographic private keys. The documented import command causes the complete wallet key to be stored in shell history unless history is disabled. During execution, the key is also included in the argument vectors of both `init.sh` and `setup-wizard.sh`. Depending on the operating system and process isolation settings, command-line arguments may be visible through process inspection utilities, process accounting, terminal-session rec ...[truncated 1261 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
scripts/setup-wizard.sh:179
Finding

Hardcoded Referral Is Bound Automatically Without Explicit User Consent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/buy-with-slippage.sh:342
Finding

Ambiguous Transaction Failures Can Trigger Duplicate Purchases

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill's stated purpose does not adequately disclose that it may generate or import a wallet private key, store secrets in a local .env file, write credentials/configuration, derive wallet information, and invoke invite-binding flows. In a blockchain trading context, undisclosed secret-handling and wallet-affecting setup is especially risky because compromise or misuse directly threatens user funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill's stated purpose does not adequately disclose that it may generate or import a wallet private key, store secrets in a local .env file, write credentials/configuration, derive wallet information, and invoke invite-binding flows. In a blockchain trading context, undisclosed secret-handling and wallet-affecting setup is especially risky because compromise or misuse directly threatens user funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill's stated purpose does not adequately disclose that it may generate or import a wallet private key, store secrets in a local .env file, write credentials/configuration, derive wallet information, and invoke invite-binding flows. In a blockchain trading context, undisclosed secret-handling and wallet-affecting setup is especially risky because compromise or misuse directly threatens user funds.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs users to import a private key and store it locally in .env, and even says where the key will be stored. Handling blockchain private keys this way is highly dangerous because .env files can be read by other tools, accidentally committed, or exfiltrated, leading directly to wallet takeover and loss of assets.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Passing a private key on the command line exposes it to shell history, process listings, terminal logs, and telemetry, even before it is written to disk. In a crypto-wallet context this is a direct secret-exposure path that can lead to immediate theft of funds.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
- `scripts/buy-with-slippage.sh` (fixed slippage or dynamic retry)

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The environment template and surrounding instructions indicate credential material is expected in .env, and the file also states demo credentials are included for testing. In isolation this is normal development practice, but in the context of a trading skill handling wallet and API credentials, encouraging colocated env-file secrets raises the risk of credential leakage, misuse of shared/demo credentials, and unintended access by other tools or repository consumers.

Content

Scanner excerpt · references/env-setup.md (reported line 114)May include surrounding context.

Use this template as reference:

bash
cp {baseDir}/references/.env.example .env

Demo Credentials Limitations

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The script accesses a raw wallet private key from .env and then uses it to sign a login message for an external service. Handling long-lived signing secrets in plaintext environment files is high risk because compromise of the host, repository leakage, logs, backups, or operator error can expose the key and lead to wallet takeover or unauthorized transactions.

Content

Scanner excerpt · scripts/bind-invitation.sh (reported line 112)May include surrounding context.

sh
const projectAppUuid = process.env.PROJECT_APP_UUID || '';

  if (!/^0x[a-fA-F0-9]{64}$/.test(privateKey)) {
    throw new Error('PRIVATE_KEY is missing or invalid in .env');
  }
  if (!projectId || !projectClientKey || !projectAppUuid) {
    throw new Error('PROJECT_ID / PROJECT_CLIENT_KEY / PROJECT_APP_UUID missing in .env');

Credential Access

High
Category
Privilege Escalation
Confidence
79% confidence
Finding

The script also depends on project credentials from .env, broadening sensitive credential handling for an ancillary invitation-binding function. Exposure of these values may enable abuse of the associated project configuration or API access, and in combination with the private key, makes the skill more sensitive than its trading-focused description suggests.

Content

Scanner excerpt · scripts/bind-invitation.sh (reported line 115)May include surrounding context.

sh
throw new Error('PRIVATE_KEY is missing or invalid in .env');
  }
  if (!projectId || !projectClientKey || !projectAppUuid) {
    throw new Error('PROJECT_ID / PROJECT_CLIENT_KEY / PROJECT_APP_UUID missing in .env');
  }

  const wallet = new Wallet(privateKey);

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/buy-with-slippage.sh (reported line 122)May include surrounding context.

sh
exit 1
fi

if [ ! -f .env ]; then
    echo ".env not found. Initialize wallet first."
    exit 1
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/buy-with-slippage.sh (reported line 123)May include surrounding context.

sh
exit 1
fi

if [ ! -f .env ]; then
    echo ".env not found. Initialize wallet first."
    exit 1
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check-transaction.sh (reported line 64)May include surrounding context.

sh
exit 1
fi

if [ ! -f .env ]; then
    echo ".env not found. Initialize wallet first."
    exit 1
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check-transaction.sh (reported line 65)May include surrounding context.

sh
exit 1
fi

if [ ! -f .env ]; then
    echo ".env not found. Initialize wallet first."
    exit 1
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-wizard.sh (reported line 111)May include surrounding context.

sh
exit 1
fi

if [ ! -f .env ]; then
    echo ".env not found. Initialize wallet first."
    exit 1
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-wizard.sh (reported line 132)May include surrounding context.

sh
exit 1
fi

if [ ! -f .env ]; then
    echo ".env not found. Initialize wallet first."
    exit 1
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-wizard.sh (reported line 134)May include surrounding context.

sh
exit 1
fi

if [ ! -f .env ]; then
    echo ".env not found. Initialize wallet first."
    exit 1
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-wizard.sh (reported line 137)May include surrounding context.

sh
exit 1
fi

if [ ! -f .env ]; then
    echo ".env not found. Initialize wallet first."
    exit 1
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/buy-with-slippage.sh (reported line 314)May include surrounding context.

sh
const projectAppUuid = process.env.PROJECT_APP_UUID || '';

  if (!/^0x[a-fA-F0-9]{64}$/.test(privateKey)) {
    throw new Error('PRIVATE_KEY is missing or invalid in .env');
  }

  const wallet = new Wallet(privateKey);

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/buy-with-slippage.sh (reported line 317)May include surrounding context.

sh
const projectAppUuid = process.env.PROJECT_APP_UUID || '';

  if (!/^0x[a-fA-F0-9]{64}$/.test(privateKey)) {
    throw new Error('PRIVATE_KEY is missing or invalid in .env');
  }

  const wallet = new Wallet(privateKey);

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check-transaction.sh (reported line 109)May include surrounding context.

sh
const projectAppUuid = process.env.PROJECT_APP_UUID || '';

  if (!/^0x[a-fA-F0-9]{64}$/.test(privateKey)) {
    throw new Error('PRIVATE_KEY is missing or invalid in .env');
  }

  const wallet = new Wallet(privateKey);

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init.sh (reported line 74)May include surrounding context.

sh
echo "Step 2/4: Patch trade defaults"
bash "$SCRIPT_DIR/patch-trade-defaults.sh" "$TARGET_DIR"

echo "Step 3/4: Create .env"
(
    cd "$TARGET_DIR"
    if [ "$ACTION" = "new" ]; then

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup-wizard.sh (reported line 138)May include surrounding context.

sh
echo "Step 2/4: Patch trade defaults"
bash "$SCRIPT_DIR/patch-trade-defaults.sh" "$TARGET_DIR"

echo "Step 3/4: Create .env"
(
    cd "$TARGET_DIR"
    if [ "$ACTION" = "new" ]; then

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Copying an existing .env to a timestamped backup duplicates any stored secrets into another plaintext file, increasing the attack surface and the chance that credentials remain on disk longer than intended. In a wallet setup context, proliferating private-key-bearing files materially raises compromise risk.

Content

Scanner excerpt · scripts/setup-wizard.sh (reported line 113)May include surrounding context.

sh
if [ -f .env ]; then
    BACKUP_FILE=".env.bak.$(date +%Y%m%d-%H%M%S)"
    cp .env "$BACKUP_FILE"
    echo "Existing .env backed up to $BACKUP_FILE"
fi

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

Creating a new .env containing a wallet private key is security-sensitive because it places credentials in plaintext within the project directory, where they may be read by local malware, backup software, or accidentally committed. For a trading skill, exposure of this file can directly lead to asset theft.

Content

Scanner excerpt · scripts/setup-wizard.sh (reported line 114)May include surrounding context.

sh
if [ -f .env ]; then
    BACKUP_FILE=".env.bak.$(date +%Y%m%d-%H%M%S)"
    cp .env "$BACKUP_FILE"
    echo "Existing .env backed up to $BACKUP_FILE"
fi

cat > .env <<'__ENV__'

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This line writes PRIVATE_KEY into .env, which is direct plaintext storage of the wallet credential. Anyone or anything with access to the file can control the associated wallet and drain funds.

Content

Scanner excerpt · scripts/setup-wizard.sh (reported line 117)May include surrounding context.

sh
echo "Existing .env backed up to $BACKUP_FILE"
fi

cat > .env <<'__ENV__'
# EVM private key, which can be used by ethers.Wallet
PRIVATE_KEY=__PRIVATE_KEY__
# Particle Network credentials

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/bind-invitation.sh:103

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/bind-invitation.sh:82

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/setup-wizard.sh:14