Back to skill

Security audit

Hyperliquid Trading & Analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is clearly a Hyperliquid trading tool, but it gives an agent direct live trading and cancel-order authority with weak enforced safeguards and an undeclared local state write.

Install only if you are comfortable giving this skill access to a dedicated, limited Hyperliquid trading wallet. Prefer testnet first, keep minimal funds in the wallet, require manual confirmation before every trade or cancel action, do not rely on the CoinGecko signals as financial advice, and review or sandbox npm dependencies before exposing any private key.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
scripts/package-lock.json:419
Finding

Third-Party Wallet SDK Executes an Installation Lifecycle Script

Content
View full analysis
=16.0.0" } } ``` The installation instruction is: ```bash cd skills/hyperliquid/scripts && npm install ``` The installed SDK is subsequently given the trading private key: ```js const privateKey = process.env.HYPERLIQUID_PRIVATE_KEY; const sdk = new Hyperliquid({ privateKey: privateKey || undefined, testnet: isTestnet, enableWs: false, }); ``` ### Technical Analysis The `hyperliquid` dependency declares `hasInstallScript: true`. Therefore, following the documented `npm install` procedure executes third-party lifecycle code with the privileges of the user installing the Skill. The package is resolved from the official npm registry and protected by a lockfile integrity hash, which reduces accidental substitution and network tampering. However, these controls do not eliminate the trust boundary: a malicious or compromised dependency release can intentionally contain harmful lifecycle or runtime behavior. This is especially sensitive because the package is later instantiated with `HYPERLIQUID_PRIVATE_KEY`, granting its runtime code access to wallet signing authority. No malicious lifecycle implementation or credential exfiltration was demonstrated in the audited project. The finding concerns the unsafe ins ...[truncated 1396 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hyperliquid.mjs:125
Finding

Insufficient Trade Validation and Non-Reducing Close Orders Can Create Unintended Leveraged Exposure

Content
View full analysis
`); } const isBuy = command === 'market-buy'; // Get current price for slippage calculation const prices = await sdk.info.getAllMids(); const currentPrice = parseFloat(prices[coin]); if (!currentPrice) throw new Error(`Unknown coin: ${coin}`); // 5% slippage protection const slippagePrice = isBuy ? currentPrice * 1.05 : currentPrice * 0.95; const result = await sdk.exchange.placeOrder({ coin, is_buy: isBuy, sz: parseFloat(size), limit_px: slippagePrice, order_type: { limit: { tif: 'Ioc' } }, // Immediate or cancel reduce_only: false, }); console.log(JSON.stringify(result, null, 2)); break; } case 'limit-buy': case 'limit-sell': { if (!privateKey) throw new Error('Private key required for trading'); const coin = normalizeCoin(args[1]); const size = args[2]; const price = args[3]; if (!coin || !size || !price) { throw new Error(`Usage: hyperliquid ${command} `); } const isBuy = command === 'limit-buy'; const result = await sdk.exchange.placeOrder({ coin, is_buy: isBuy, sz: parseFloat(size), limit_px: parseFloat(price), order_type: { limit: { tif: 'Gtc' } }, // Good til cancelled reduce_only: false, }); console.log(JSON.stringify(result, null, 2)); break; } ``` The documented close-position workflow relies on these ordinary orders: ```text "Close my ETH position" 1. Run `positions` to get current ETH position size ...[truncated 2467 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check-positions.mjs:6
Finding

Position Monitor Performs an Undeclared Write to a Hard-Coded External Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (27)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 63)May include surrounding context.

Or use .env file (recommended for security):

bash
cd hyperliquid
cp .env.example .env
# Edit .env with your credentials
nano .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 64)May include surrounding context.

bash
cd hyperliquid
cp .env.example .env
# Edit .env with your credentials
nano .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

bash
cd hyperliquid
cp .env.example .env
# Edit .env with your credentials
nano .env

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script is materially misaligned with the declared Hyperliquid skill purpose: instead of monitoring or trading via Hyperliquid, it pulls third-party CoinGecko market data and derives standalone trade recommendations. In a trading skill, hidden or undocumented strategy logic is dangerous because it can influence user decisions or downstream automation using unaudited external signals that users did not explicitly request.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill exposes live trading operations (market-buy, market-sell, limit-buy, limit-sell, cancel-all) that execute immediately whenever the command is invoked, with no explicit confirmation, dry-run mode, or secondary safety check. In the context of an agent skill for leveraged perpetual futures trading, this is especially dangerous because accidental, coerced, or prompt-injected invocations can directly place trades or cancel protections, leading to rapid financial loss.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.4 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
88% confidence
Finding

The lockfile pins axios 1.13.4, which the supplied advisory set flags for multiple issues including SSRF/proxy bypass and prototype-pollution-related attack paths. In a trading skill that makes outbound API calls and may operate with secrets, these classes of flaws can enable request redirection, credential leakage, or response tampering if exploitable code paths are reached.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
84% confidence
Finding

The nested ethers dependency includes ws 8.17.1, which is flagged for memory disclosure and memory-exhaustion denial-of-service issues. Because this skill is intended to monitor and trade via live network connectivity, a vulnerable WebSocket client/server library can increase exposure to malformed-frame attacks that crash the process or leak memory contents.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
80% confidence
Finding

form-data 4.0.5 is flagged for CRLF injection via unescaped multipart field names and filenames. If any part of this skill constructs multipart requests using user-controlled names or filenames, an attacker may be able to smuggle or corrupt headers and alter downstream request interpretation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
85% confidence
Finding

The top-level ws 8.19.0 dependency is also flagged for memory disclosure and memory exhaustion issues. Given the skill's real-time trading and monitoring use case, sustained WebSocket exposure to exchange or intermediary infrastructure makes reliability and memory-safety issues more operationally significant than in a non-networked utility.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

The package explicitly references ws 8.19.0, which the finding reports as affected by memory disclosure and memory exhaustion denial-of-service advisories. In a trading skill that may maintain persistent WebSocket connections for market data and account events, exploitation could expose process memory or disrupt trading visibility and execution reliability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README includes broad natural-language examples such as 'Enter a BTC long position' and 'Close my ETH position' without stating any approval gate, confirmation requirement, or limitation on when the agent may execute trades. In an AI skill that can place real orders, this increases the risk of unsafe automatic action, prompt-based overreach, or ambiguous user intent being interpreted as authorization to trade.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes scripts that require environment variables and network access, including a private key for live trading, but it does not declare any explicit tool scope or permissions boundaries. In an agent setting, missing scope metadata increases the chance the skill can be invoked with broader-than-expected capabilities, exposing secrets or enabling unintended outbound trading actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation text is broad enough to match generic portfolio, crypto position, or trading requests, which can cause the skill to trigger outside clearly Hyperliquid-specific intent. Because this skill supports real trading operations, overbroad routing raises the risk of users being pushed into the wrong exchange context or having sensitive trading actions initiated based on ambiguous requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation exposes destructive actions such as cancel-all and position-closing-related operations without a prominent warning that these actions can immediately alter or remove live orders and materially affect financial exposure. In a trading skill, lack of explicit irreversible-action warnings increases the chance of accidental account disruption or loss, especially when an agent follows the documented workflows mechanically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'Close my ETH position' workflow instructs the agent to determine direction and execute a market trade immediately, but it omits an explicit final confirmation before placing the order. Since closing a derivatives position is a live financial action that can realize gains/losses and incur slippage, this creates a direct risk of unintended or mistaken trade execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs trading actions to be signed with an Ethereum private key but provides no warning about secret-handling, key isolation, or the danger of exposing signing material to an agent runtime. In an agent skill focused on executing trades, this omission materially increases the chance that developers or operators will pass raw private keys into the skill or logs, enabling account takeover and unauthorized trading if mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file documents live order placement and cancellation, including cancel-all semantics, without clearly warning that these actions can immediately affect real funds and open positions on mainnet. In the context of a trading skill that may be invoked by user intent, lack of explicit risk/confirmation guidance makes accidental or induced destructive actions more likely, potentially causing financial loss or strategy disruption.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/analyze-coingecko.mjs (reported line 9)May include surrounding context.

js
async function getChartData(coinId, days = 1) {
  // Don't specify interval - let CoinGecko auto-select (free tier limitation)
  const url = `https://api.coingecko.com/api/v3/coins/${coinId}/market_chart?vs_currency=usd&days=${days}`;
  
  const response = await fetch(url);
  if (!response.ok) {

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code generates bullish/bearish trade signals and final long/short recommendations from CoinGecko data without clear justification in the skill's stated scope. In the context of a trading-enabled skill, this creates a risky hidden decision engine that may cause users or connected agents to place real leveraged trades based on simplistic, potentially unreliable external heuristics.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script presents concrete trading actions such as 'Enter BTC LONG' and 'Consider SHORT entry' without any warning that the output is speculative, incomplete, and not financial advice. In a Hyperliquid-related skill where real perpetual futures trades may follow, omission of such warnings increases the likelihood of overtrust and unsafe financial actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script is described as a position-check utility, but it also performs a local state mutation by overwriting a fixed trading-state file. This side effect can mislead operators or downstream automation into trusting that a 'read-only' check is safe, and if the file is consumed by other trading components, stale or unexpected writes could influence later trading behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The orders command is documented and expected to show open orders, but it instead prints state.assetPositions. In a trading skill, misleading portfolio/order state can cause users or higher-level agents to make unsafe decisions, such as believing there are no resting orders or confusing exposure with outstanding orders.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
76% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. In a trading integration that may send API keys, bearer tokens, or signed headers to remote services, redirect-related header leakage could expose credentials to attacker-controlled domains if redirects are followed from compromised or malicious endpoints.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency uses a caret range, which allows newer minor/patch releases to be installed without explicit review. In a trading skill that can place orders and handle balances, unexpected dependency updates increase supply-chain risk and can introduce breaking or malicious changes into a sensitive execution path.

Content

Scanner excerpt · scripts/package.json (reported line 6)May include surrounding context.

json
"version": "1.0.0",
  "type": "module",
  "dependencies": {
    "ethers": "^6.9.0",
    "hyperliquid": "^1.7.7",
    "node-fetch": "^3.3.2",
    "ws": "^8.19.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The hyperliquid package is specified with a caret range, so dependency resolution may pull in unreviewed future releases. Because this skill directly interfaces with a trading platform, dependency drift is more dangerous than in a read-only utility and can affect order placement or credential handling.

Content

Scanner excerpt · scripts/package.json (reported line 7)May include surrounding context.

json
"type": "module",
  "dependencies": {
    "ethers": "^6.9.0",
    "hyperliquid": "^1.7.7",
    "node-fetch": "^3.3.2",
    "ws": "^8.19.0"
  }

Static analysis

No suspicious patterns detected.