Back to skill

Security audit

Strategy Workflow

Security checks for vulnerabilities and agentic risk

Overview

The skill is for trading-strategy optimization, but it also directs broad autonomous worker control, persistent state, remote infrastructure setup, and hidden workflow notes that deserve manual review before installation.

Install only if you intend to run a high-autonomy trading backtest control plane in a bounded workspace or container. Review and limit Bash/Write/Edit use, require approval before killing or launching processes, avoid persistent watchdog auto-starts unless explicitly needed, and handle SSH/API/cloud backup steps with least-privilege credentials and clear data-transfer approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
backtest-optimize.md:5
Finding

Mandatory Autonomous Control Doctrine Overrides Task Boundaries and Persists Operational Instructions

Content
View full analysis
/workflow_events.log`. ``` ```markdown ### Instant Reactivity To Problem Signatures - On worker crash, stuck worker, stale progress, OOM, or failed GPU path: detect in the same control cycle, execute remediation immediately, and re-verify outcome. - If no active optimize workers exist and launcher is not active, relaunch immediately subject only to cooldown guardrails. - If GPU is below target while work queue exists, trigger GPU fill lanes. - If CPU is below target while work queue exists, trigger CPU fill lanes. - If an action is executabl ...[truncated 4023 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Hidden Instructions

High
Category
Prompt Injection
Confidence
79% confidence
Finding

The hidden comment block contains operational status, remediation guidance, and continuity instructions maintained by a swarm, which can act as concealed prompt material not obvious to end users. Hidden instructions are risky because they can steer agent behavior in ways users do not see or approve, particularly when they reinforce persistence, worker saturation, and infrastructure actions.

Content

Scanner excerpt · backtest-optimize.md (reported line 320)May include surrounding context.

└── phase0_top500.json # Phase 0 prescreening results

text

<!-- AUTO-WORKFLOW-NOTES:START -->
## Auto Workflow Notes (Maintained By Swarm)
- Updated UTC: `2026-02-12T09:42:52.947228+00:00`
- Run ID: `bt-20260211_233304Z`

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The declared skill is a strategy-development workflow, but the content actually instructs an always-on, goal-locked autonomous control plane with persistent state, self-healing, and non-stop operation. This mismatch is dangerous because it hides the real operational behavior from users and reviewers, increasing the chance that an agent is granted broader autonomy than intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill authorizes autonomous process control, including kill/relaunch behavior, session recovery, and continuous remediation loops that can affect the host system outside normal backtesting tasks. In a markdown workflow meant for strategy optimization, these instructions expand operational authority well beyond analysis and can cause unintended service disruption, runaway process spawning, or interference with unrelated workloads if an agent follows them blindly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs autonomous killing, relaunching, watchdog repair, and repeated file/state writes without clearly warning the user that it can modify the running system and operational state. That combination can lead to destructive or destabilizing behavior, especially when an agent interprets these steps as mandatory and ongoing rather than optional operator-driven maintenance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow mandates knowledge-plane health checks and database-backed query tooling that are not necessary for basic strategy optimization, increasing the capability surface and encouraging connectivity to auxiliary services. This broadens access to local infrastructure and creates opportunities for unauthorized data access, dependency abuse, or unexpected failures when an agent attempts to interact with databases or service endpoints.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
60% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · backtest-optimize.md (reported line 343)May include surrounding context.

md
- Generate a fresh HANDOFF_SWARM_RUN_<timestamp>.md with verification evidence.
- Session manager next step: maintain_polling_and_keep_workers_saturated
<!-- AUTO-WORKFLOW-NOTES:END -->

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly directs setup of remote desktop access, SSH/API access, and movement of backtesting data between local and cloud systems, but provides no guardrails around credential handling, host hardening, least-privilege access, or user confirmation before enabling remote access. In an agent skill context, operational instructions that expand system access and data movement without safety constraints materially increase the risk of unauthorized access, credential exposure, and unintended exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages installing broad and partly unspecified dependencies ('+ any extra I forgot here') and backing up outputs to local/cloud destinations without defining trusted sources, version pinning, license controls, or data classification requirements. This creates supply-chain and data-handling risk because an agent could pull unvetted packages or copy sensitive artifacts to unapproved storage locations during execution of the workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.