Back to skill

Security audit

Trading Co-Agent Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about being an autonomous live-trading assistant, but it grants broad authority to execute and retry real trades without clear user approval limits.

Only install this if you intentionally want an agent to help operate a live trading workflow. Before use, require paper-trading by default, explicit confirmation for every live order, approved accounts and markets, maximum trade and daily loss limits, and a manual kill switch.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description explicitly authorizes real, non-simulated trading and ongoing autonomous optimization without a prominent warning about financial loss, irreversible orders, or the need for explicit user approval boundaries. In this context, an agent could act on live funds and compound mistakes through repeated monitoring and self-directed execution, making accidental loss materially more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

These instructions tell the agent to proactively execute trades and retry failed ones based on its own judgment, but provide no prominent warning that such actions are irreversible market operations that can lose user funds. The retry/correction framing is especially dangerous because it encourages the agent to turn transient failures or misclassifications into repeated live trading attempts.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The 'active trading authority' section grants the agent broad permission to trade whenever it deems conditions worthwhile, yet it does not define user fund protections, approval boundaries, or explicit risk disclosures. In a live trading skill, this context makes the issue more dangerous because the agent is empowered not only to initiate trades but also to perform emergency corrective trades that may amplify losses or create unintended positions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The monitoring loop can automatically execute trades whenever analyze_signal returns a recommended action of "TRADE", with no human approval, explicit confirmation step, dry-run mode, or emergency kill switch. In a trading/bot context this is dangerous because any bad signal, compromised signal source, logic bug, or manipulated market condition could directly trigger real financial transactions and losses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The checklist gives prescriptive trading recovery actions such as re-executing trades, selling after losses, or evaluating whether to chase missed opportunities, but it does so without explicit warnings that on-chain trades can be irreversible and may cause financial loss. In the context of a trading skill, this increases the chance that users treat the content as operational advice and take risky actions without understanding consequences, especially during time-sensitive failures.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s natural-language description is presented in Chinese only, including the operational description of the script. This imposes a language choice without offering the user an explicit language or locale option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file is primarily written in Traditional Chinese, with only limited English terms in examples, and does not state that users may choose another language. Under the policy rule for language/locale constraints, documentation that effectively forces one language without opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is written entirely in Traditional Chinese aside from brief English glosses, and it does not indicate that the user may choose another language or that the locale constraint is intentional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.