Back to skill

Security audit

CAI: gtrade-with-cai

Security checks for vulnerabilities and agentic risk

Overview

This skill is explicitly for CAI gTrade perpetual trading, but it can use live custodial funds without a prominent risk warning or required final confirmation step.

Review this carefully before installing. Use the narrowest CAI API scope available, confirm every order and close action yourself, understand that leveraged perps can lose real funds, and disable or revoke CAI platform automation when you no longer want agents to trade.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill enables real custodial perpetual trading and position closing, but the user-facing description does not prominently warn that actions can affect live funds and open leveraged positions. In a trading context, omission of a clear financial-risk warning increases the chance of accidental execution, user misunderstanding, and unsafe delegation to an agent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.