Back to skill

Security audit

Ptrade

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Ptrade trading skill, but it includes copyable live-trading and unsafe persistence examples without enough safeguards for a broker-backed financial environment.

Review carefully before installing. Treat all order examples as potentially live trading code, use paper trading or backtests first, add explicit account-mode checks and position limits, and replace pickle persistence examples with safer validated formats such as JSON. Install demo dependencies only in an isolated environment with pinned versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:577
Finding

Unsafe Pickle Deserialization in Strategy Persistence Examples

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:577-584 and SKILL.md:1053-1054
Vulnerability Type: Unsafe deserialization
Risk Level: High

Vulnerable Code

python
import pickle
NOTEBOOK_PATH = get_research_path()

def initialize(context):
    # Try to restore persisted data from file
    try:
        with open(NOTEBOOK_PATH + 'hold_days.pkl', 'rb') as f:
            g.hold_days = pickle.load(f)
    except:
        g.hold_days = {}  # Initialize as empty dict on first run

A second strategy example repeats the same unsafe pattern:

python
try:
    with open(NOTEBOOK_PATH + 'trade_log.pkl', 'rb') as f:
        trade_log = pickle.load(f)
except:
    trade_log = []

Technical Analysis

Python pickle data is executable serialization rather than a data-only format. During pickle.load(), specially constructed objects can invoke attacker-selected callables through methods such as __reduce__. The examples load files from the Ptrade research directory without validating their origin, integrity, ownership, or content.

The broad except clauses do not mitigate this issue. Malicious code may execute before deserialization raises an exception, and the broad handlers can conceal corruption or exploitation attempts.

Exploitation requires an attacker or compromised process to obtain write access to the relevant research directory or otherwise replace one of the persisted .pkl files.

Attack Path

  1. A user adopts one of the persistence examples in a live or backtest strategy.
  2. The strategy creates or expects hold_days.pkl or trade_log.pkl in the path returned by get_research_path().
  3. An attacker, compromised strategy, malicious file import, or another process with write access replaces the expected file with a crafted pickle payload.
  4. The strategy starts or reaches the affected loading operation.
  5. pickle.load() reconstructs the malicious object a ...[truncated 972 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace pickle persistence with a non-executable data format such as JSON for dictionaries, lists, strings, numbers, and booleans.
  2. Validate the parsed data against an explicit schema, including expected keys, types, ranges, and maximum sizes.
  3. If pickle is unavoidable, only deserialize files produced within a trusted boundary and verify a cryptographic signature or keyed MAC before loading.
  4. Restrict research-directory and persistence-file permissions so unrelated users or processes cannot modify them.
  5. Write updates atomically by creating a protected temporary file and replacing the destination only after successful serialization.
  6. Replace bare except clauses with specific exceptions and log integrity or parsing failures.
  7. Do not treat restricted unpickling implementations as a complete defense unless the accepted object types and callable resolution are rigorously constrained.
  8. Update both persistence examples so users are not encouraged to reproduce the unsafe pattern.

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Mutable and Unverified Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2; installation directed by demo_project/README.md:7-9
Vulnerability Type: Unpinned and unhashed dependencies
Risk Level: Medium

Vulnerable Code

requirements.txt:

text
pandas>=1.5.0
numpy>=1.20.0

demo_project/README.md:

bash
pip install -r ../requirements.txt

Technical Analysis

The requirements use open-ended lower bounds rather than exact, reviewed versions. No lockfile, package hashes, or trusted-index restriction is supplied. Consequently, the effective code installed by the documented command can change over time without any modification to this project.

Although pandas and numpy are legitimate package names and no malicious dependency is identified in the audited files, the installation process lacks reproducibility and package-artifact verification. A future compromised release, dependency-chain compromise, incompatible update, or untrusted package-index configuration could introduce unexpected code during installation or runtime.

Attack Path

  1. A user follows demo_project/README.md and runs the documented pip command.
  2. Pip contacts the configured package index and resolves any release satisfying the open-ended version constraints.
  3. The selected artifacts are not checked against project-maintained cryptographic hashes.
  4. If the configured index, selected release, transitive dependency, or distribution artifact has been compromised, pip installs attacker-controlled content.
  5. Malicious installation hooks or imported package code execute with the privileges of the user or environment running pip or the demo.

This path depends on an external package or package source becoming compromised; the audit found no evidence that the currently named packages are themselves malicious.

Impact Assessment

The potential scope is the Python environment and user account under which installation ...[truncated 518 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin dependencies to exact, reviewed versions, for example package==version.
  2. Generate and commit a lockfile that includes all transitive dependencies.
  3. Use hash-verified installation, such as a requirements file generated with hashes and installed using pip install --require-hashes.
  4. Configure pip to use an explicitly trusted package index or an internally controlled package mirror.
  5. Review and regularly update pinned versions through a controlled dependency-update process.
  6. Run installation inside an isolated virtual environment with minimal operating-system permissions.
  7. Remove pandas and NumPy from the demo requirements if the demonstration does not actually use them; the audited demo.py only prints text and sample strategy code.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The quick reference includes executable trading examples that place real orders and adjust positions, but it provides no warning that these actions may execute on a live broker-backed account. In the context of a low-latency production trading platform running on broker servers, a user could copy these snippets into a live strategy and trigger unintended, financially irreversible transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README includes executable-looking strategy examples that call live trading primitives such as order() in the context of a broker-hosted production trading platform, but it provides no warning that these examples may place real orders or cause financial loss if copied into a live account. In this skill context, the omission is more dangerous because the platform explicitly runs on broker servers with low-latency execution, so users may reasonably treat the snippet as ready-to-deploy rather than educational pseudocode.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This section documents direct order-placement APIs, including market and limit orders, in a way that could be copied into a live trading environment without prominent warnings that real funds may be used. In a financial-trading skill, omission of strong execution-risk warnings materially increases the chance of unintended real-world actions and financial loss.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The persistence example restores state from a pickle file using pickle.load, which is unsafe if the file can be modified by another party or process. Python pickle deserialization can execute arbitrary code during loading, so a tampered state file could lead to code execution inside the broker-hosted strategy environment.

Content

Scanner excerpt · SKILL.md (reported line 581)May include surrounding context.

md
NOTEBOOK_PATH = get_research_path()

def initialize(context):
    # Try to restore persisted data from file
    try:
        with open(NOTEBOOK_PATH + 'hold_days.pkl', 'rb') as f:
            g.hold_days = pickle.load(f)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example strategies automate buying, selling, IPO subscription, margin, futures, and other actions that could execute in live mode if reused as-is. Because the skill is specifically for broker-hosted execution on actual trading infrastructure, these examples create a meaningful risk of accidental or uncontrolled real trades and resulting financial harm.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest and earlier documentation describe Ptrade as a broker-hosted intranet trading platform and explicitly state that strategies cannot access the external internet. However, the AI-agent section advises combining the interface with 'other data sources or tools' for macro and cross-market analysis, which expands the described behavior beyond the platform's documented operating constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses Chinese for the primary operational instructions and does not indicate that the user can select another language or that the language restriction is intentional and justified. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

A natural-language policy issue exists because the skill content appears to force a specific language/locale for all users without opt-in or explanation. The file does not indicate that Chinese is optional, nor does it justify that the skill is region-specific or intended only for a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as oriented to the Chinese securities market without offering any language or locale choice. This can violate a language/locale policy when a skill implicitly forces one language for all users rather than documenting it as an opt-in or region-specific constraint.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a minimum version but not pinned to an exact release, which makes builds non-reproducible and can introduce unexpected or vulnerable package versions through future installs. In a trading platform context, dependency drift is more sensitive because behavior changes or compromised upstream releases could affect reliability or execution logic on broker-hosted infrastructure.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
pandas>=1.5.0
numpy>=1.20.0

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
82% confidence
Finding

Because pandas is unpinned, it is not possible to verify from this manifest whether deployment will install a version affected by known advisories. This creates avoidable uncertainty in the software supply chain, and in a broker-connected trading environment even low-confidence dependency exposure is more concerning due to the operational sensitivity of the system.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The numpy dependency is not pinned to an exact version, so installations may resolve to different releases over time, including versions with defects or known security issues. In a quantitative trading skill, reproducibility and supply-chain control matter more because unexpected library changes can affect calculations or operational stability.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
pandas>=1.5.0
numpy>=1.20.0

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest does not pin numpy, so the actual installed version cannot be validated against the listed advisories from the file alone. That uncertainty is a real supply-chain weakness: vulnerable versions could be pulled in depending on installation time and resolver behavior, which is undesirable for code used in financial trading workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.