Back to skill

Security audit

CAI: trade-xyz-with-cai

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward live-trading guide, but it asks users to enable broad trading authority without clearly requiring confirmation or warning about financial loss.

Review this carefully before installing. Only use it with a CAI key whose permissions and balances you are comfortable risking, prefer the narrowest available scope, and require explicit confirmation for every live order including asset, side, size, price, and venue before execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides direct instructions for placing and canceling live trades, including concrete order parameters and setup steps, but does not include an explicit warning that these actions can execute real financial transactions with loss potential. In an agent setting, this increases the chance that a user or downstream system treats the skill as routine operational guidance and submits unintended or insufficiently understood live orders.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.