Back to skill

Security audit

The Titan Scalper IDX

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed IDX scalping analysis skill with financial-risk concerns, but it does not install code, access accounts, execute trades, or hide behavior.

Install only if you want Indonesian-language technical scalping analysis for IDX stocks. It may produce concrete entry, cut-loss, and target levels, so treat it as educational market analysis rather than personalized financial advice, verify all data independently, and do not connect it to brokerage execution without separate safeguards.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is overly broad for a high-risk financial-advice skill, so it could activate on general investing questions and steer users into unsolicited short-term trading recommendations. In a trading context, misrouting ordinary market queries into aggressive scalping guidance increases the chance of unsuitable, potentially harmful advice.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill forces a specific Indonesian-language trader persona without user opt-in, which can override user preferences and make the assistant sound more authoritative than warranted. In a financial setting, a rigid expert persona may unduly increase user trust and reduce clarity that the output is only conditional analysis, not personalized financial advice.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This document gives specific scalping entry, exit, breakout, and aggressive trading guidance without any warning about financial risk, suitability, or the possibility of rapid losses. In a skill context, users may treat this as actionable advice and act on it immediately, increasing the chance of harmful financial decisions without informed consent.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
All instructional content is written in Indonesian, and the file does not indicate that the skill is intentionally limited to Indonesian-speaking users or a region-specific compliance context. The policy allows locale constraints when they are explicitly justified or when users are offered a language choice, neither of which is present here.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This markdown file is entirely presented in Indonesian, including the title and all instructions, but it does not state that the skill is intended only for Indonesian-speaking users or provide any opt-in for language preference. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
The entire markdown skill is written in Indonesian and provides no indication that other languages are supported or that the user can choose their preferred language. Under the policy rule for natural-language violations, this is a locale/language constraint that is not presented as optional.

Static analysis

No suspicious patterns detected.