Back to skill

Security audit

Build Protocol Decision

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed decision-making workflow; its market-data lookups are purpose-aligned, but its audit script should be treated as advisory rather than a complete verifier.

Install only if you want an agent to use live web data and public market APIs while helping with decisions. Treat the included audit script as a checklist aid, not a guarantee that prices are current or that a decision document is safe to act on; verify current prices, dates, and financial assumptions independently before committing money or signing contracts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/audit-script-decision.sh:117
Finding

Fake-Precision Warnings Do Not Affect the Final Audit Result

Content
View full analysis
2 ? LINENUM-2 : 1)),$((LINENUM+2))p" "$TARGET_FILE") if echo "$CONTEXT" | grep -qi '(est\|含估算\|estimated\|approx'; then pass "Line $LINENUM: precise % found but labeled as estimate — OK" else warn "Line $LINENUM: precise % figure without '(est.)' label: $CONTENT" fi done ``` ### Technical Analysis In Bash, a loop on the right-hand side of a pipeline normally executes in a subshell. The `pass` and `warn` functions increment the global `PASS` and `WARN` counters, but calls made inside this piped `while` loop modify only the subshell's copies of those variables. When the loop terminates, the modified counters are discarded. As a result, the script may print a warning for an unlabeled high-precision percentage while leaving the parent process's `WARN` counter unchanged. The final summary and exit status are calculated from the unchanged parent counter. This creates a validation bypass in a script intended to act as a decision-document quality gate. ### Attack Path 1. Prepare a decision document that satisfies all other blocking and warning checks. 2. Include an unlabeled high-precision percentage such as `+12.85%`. 3. The script detects the value and invokes `warn` inside the piped loop. 4. The warning is printed, but the increment to `WARN` occurs only in the subshell. 5. After the pipeline finishes, the parent shell still has `WARN=0`. 6. The audit can return exit code `0` and report that all checks passed. ### Impact Assessment The flaw does not provide operating-system privileges, code ...[truncated 405 chars]
Remediation
View remediation
2 ? LINENUM-2 : 1)),$((LINENUM+2))p" "$TARGET_FILE") if printf '%s\n' "$CONTEXT" | grep -qiE '\(est|含估算|estimated|approx'; then pass "Line $LINENUM: precise % found but labeled as estimate — OK" else warn "Line $LINENUM: precise % figure without '(est.)' label: $CONTENT" fi done < <(printf '%s\n' "$PRECISION_LINES") ``` Security and reliability hardening should also include: 1. Add a regression test containing an unlabeled value such as `+12.85%`. 2. Assert that the test produces at least one warning and exit code `2`. 3. Add a corresponding test for a properly labeled estimate and verify that it does not generate a warning. 4. Run the script under both supported Bash versions and operating systems to verify consistent pipeline behavior. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
references/audit-script-decision.sh:181
Finding

Future or Unrelated Dates Can Bypass Document Freshness Validation

Content
View full analysis
/dev/null || date -j -f "%Y-%m-%d" "$DATE_LINE" +%s 2>/dev/null || echo "0") NOW_EPOCH=$(date +%s) AGE_DAYS=$(( (NOW_EPOCH - DOC_EPOCH) / 86400 )) if [[ $AGE_DAYS -le 1 ]]; then pass "Document dated $DATE_LINE — fresh (${AGE_DAYS}d old)" ``` ### Technical Analysis The script subtracts the extracted document timestamp from the current timestamp and treats every result less than or equal to one day as fresh. If the document date is in the future, `AGE_DAYS` is negative. Every negative value satisfies the condition `AGE_DAYS -le 1`, so even an arbitrarily distant future date is marked as fresh. The extraction logic also selects the first string matching `YYYY-MM-DD` anywhere in the file. It does not require that the value belong to a designated decision date or live-data fetch timestamp. A date in an example, historical section, future review schedule, or unrelated metadata can therefore control the freshness result. Although invalid dates fall back to epoch zero and generally fail as stale, the script does not explicitly distinguish parsing failure from a genuinely old document. ### Attack Path 1. Start with a stale decision document containing outdated prices or assumptions. 2. Place a future date, such as `2099-01-01`, before every other date in the document. 3. The script extracts that value because it is the first matching date. 4. `DOC_EPOCH` is later than `NOW_EPOCH`, producing a negative `AGE_DAYS`. 5. The condition `AGE ...[truncated 845 chars]
Remediation
View remediation
/dev/null || date -j -f "%Y-%m-%d" "$DATE_LINE" +%s 2>/dev/null ); then fail "Invalid document date: $DATE_LINE" else NOW_EPOCH=$(date +%s) AGE_SECONDS=$((NOW_EPOCH - DOC_EPOCH)) if (( AGE_SECONDS < 0 )); then fail "Document date is in the future: $DATE_LINE" else AGE_DAYS=$((AGE_SECONDS / 86400)) if (( AGE_DAYS <= 1 )); then pass "Document dated $DATE_LINE — fresh (${AGE_DAYS}d old)" elif (( AGE_DAYS <= 7 )); then pass "Document dated $DATE_LINE — ${AGE_DAYS}d old (acceptable)" elif (( AGE_DAYS <= 30 )); then warn "Document dated $DATE_LINE — ${AGE_DAYS}d old" else fail "Document dated $DATE_LINE — ${AGE_DAYS}d old" fi fi fi fi ``` Additional hardening should include: 1. Define an unambiguous metadata field for the decision date and a separate field for each live-data fetch timestamp. 2. For liquid assets, validate the data-fetch timestamp rather than only the document date. 3. Reject future timestamps outside a small, documented clock-skew tolerance. 4. Add regression tests for future dates, invalid calendar dates, multiple unrelated dates, and stale data paired with a recent review date. 5. Ensure that parsing failures generate an explicit failure rather than silently substituting epoch zero. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly instructs use of shell commands such as curl to fetch live market data, but the manifest declares no allowed tool scope or permissions. This creates an authorization ambiguity where an agent may invoke shell/network-capable tooling without an explicit least-privilege declaration, increasing the chance of unintended command execution or policy bypass in environments that rely on manifest scoping.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list includes broad natural-language phrases like 'which option', 'compare options', and multilingual variants that can match many ordinary conversations beyond high-stakes decisions. Over-broad auto-invocation can cause the skill to activate in inappropriate contexts and push users into unnecessary shell/network-backed workflows, increasing exposure to external data access and risky financial-style guidance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The header says the script 'Verifies: live data freshness' and the usage/help text lists 'Live data fetch' as a performed check, suggesting automated validation. In reality, the live-data section only extracts possible tickers and prints curl commands, explicitly warning that live price fetch is 'not automated,' so the implemented behavior falls short of the claimed verification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file comment and the 'Checks performed' text describe live data verification as something the script does. However, lines later in the script state 'Live price fetch not automated' and only print example curl commands, directly contradicting the earlier documentation claim of verification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
# ── Config ────────────────────────────────────────────────────
TARGET_FILE="${1:-}"
STOOQ_BASE="https://stooq.com/q/l/?s=SYMBOL.us&f=sd2t2ohlcv&h&e=csv"
COINGECKO_BASE="https://api.coingecko.com/api/v3/simple/price"

PASS=0
WARN=0

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/audit-script-decision.sh (reported line 25)May include surrounding context.

sh
# ── Config ────────────────────────────────────────────────────
TARGET_FILE="${1:-}"
STOOQ_BASE="https://stooq.com/q/l/?s=SYMBOL.us&f=sd2t2ohlcv&h&e=csv"
COINGECKO_BASE="https://api.coingecko.com/api/v3/simple/price"

PASS=0
WARN=0

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/decision-workflow.md (reported line 102)May include surrounding context.

md
# ── Config ────────────────────────────────────────────────────
TARGET_FILE="${1:-}"
STOOQ_BASE="https://stooq.com/q/l/?s=SYMBOL.us&f=sd2t2ohlcv&h&e=csv"
COINGECKO_BASE="https://api.coingecko.com/api/v3/simple/price"

PASS=0
WARN=0

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language checks and remediation text explicitly require either Chinese or English terminology such as '止损' and later '含估算', which reflects a built-in locale expectation rather than user choice. The file does not state that the skill is region-specific or provide an opt-in/out for language handling, so this can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.