Back to skill

Security audit

Technical Analysis Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed technical-analysis guidance skill with financial-risk caveats, but it does not execute trades, access accounts, persist data, or run hidden code.

Treat this as educational technical-analysis support, not financial advice or an automated trading system. Because the trigger scope is broad and the tone is confident, review outputs critically, require your own risk controls, and do not let it make trading decisions for you.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text is very broad and includes many generic trading-related terms, which can cause the skill to activate in contexts where the user did not specifically ask for technical-analysis guidance. In a financial domain, unintended invocation is risky because it may steer users toward trading-oriented advice without clear intent, increasing the chance of inappropriate or overconfident recommendations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill presents itself as an expert trading authority and discusses market edge identification, but it does not include a clear warning that outputs are informational and may influence risky financial decisions. In this context, authoritative framing without a cautionary notice can increase user reliance and contribute to harmful real-world trading behavior or financial loss.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown validation file defines activation patterns such as "pattern|setup|signal" with only broad context terms like "backtest|win_rate|expectancy." These terms are generic in trading or technical discussion and the file does not provide negative examples or tighter scope constraints, which can cause unintended matches.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The pattern "entry|signal|position" and context "stop|stop_loss|risk" are common terms that can appear in many unrelated code or documentation contexts. Without clearer activation rules or exclusions, this validation may fire too broadly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Terms like "signal|entry" and "timeframe|higher_tf|htf" are widely used and do not clearly distinguish intended from unintended matches. The file does not specify constraints or non-trigger examples to limit activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger "breakout|reversal|break" includes especially broad wording like "break," which can appear in many contexts, while "volume|vol" is also generic. Without more precise boundaries, this rule is vulnerable to unintended activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Keywords such as "MA," "EMA," and "lag|delay|late" are short and generic enough to match many contexts, especially in code. The markdown provides no negative examples or additional constraints to reduce accidental matches.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Terms like "target|take_profit|tp" and "risk|reward|ratio|rr" are broad and include abbreviations that may collide with unrelated text. The rule lacks explicit scope limitations or examples of when it should not trigger.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Patterns like "win_rate|success.*rate|probability" and context such as "sample|count|trades" can match many general analytical discussions. Because no trigger boundaries or negative examples are provided, the activation condition is ambiguous.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The pattern "backtest|backtesting" plus context "out.*sample|oos|walk.*forward|train.*test" is domain-relevant but still broad, and the file does not define when the rule should not apply. This can lead to over-triggering in general educational or reference material.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Keywords like "profit" and "cost" are highly common and can appear outside the intended backtest-validation scenario. The rule lacks negative examples or more precise scope definitions to prevent unintended matches.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger set "setup|pattern|entry" and context "invalid|cancel|abort|expire" consists of generic terms that can appear in many unrelated discussions or code comments. No exclusions or narrow applicability notes are provided, making activation ambiguous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest uses Chinese-only natural-language fields for the display name and description, which indicates the skill is presented in a specific language without any visible opt-in or explanation that it is intended only for a Chinese-speaking region. Under the policy rules, language constraints should either offer user choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.