Back to skill

Security audit

LEAN Engine — Algorithmic Trading

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly for LEAN trading backtests, but it needs review because it handles potentially sensitive trading configuration less safely than its documentation claims.

Review this skill before installing. Use it in an isolated project or VM, avoid running setup with elevated privileges, do not point it at a live broker config containing Interactive Brokers credentials, and prefer pinned dependencies plus a minimal backtest-only config. Back up LEAN config files before using the helper script.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:49
Finding

Remote installer is downloaded and executed without integrity verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:65
Finding

Third-party Python dependencies are installed without version or hash pinning

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run_backtest.sh:19
Finding

Unvalidated algorithm arguments allow path traversal and unsafe configuration injection

Content
View full analysis
}" ALGO_FILE="${2:?Usage: $0 }" ``` ```bash # Verify algorithm file exists if [ ! -f "$ALGO_DIR/$ALGO_FILE" ]; then echo "❌ Algorithm not found: $ALGO_DIR/$ALGO_FILE" echo " Place your .py file there first." exit 1 fi # Verify LEAN is built if [ ! -f "$LAUNCHER/QuantConnect.Lean.Launcher.dll" ]; then echo "❌ LEAN not built. Run: cd $LEAN_ROOT && dotnet build QuantConnect.Lean.sln -c Debug" exit 1 fi # Create backtest config from source (source is NOT modified) python3 "$SCRIPT_DIR/configure_algo.py" "$SOURCE_CONFIG" "$BACKTEST_CONFIG" "$ALGO_CLASS" "$ALGO_FILE" ``` ```python # Replace algorithm-type-name content = re.sub( r'"algorithm-type-name"\s*:\s*"[^"]*"', f'"algorithm-type-name": "{algo_class}"', content, ) # Replace algorithm-language content = re.sub( r'"algorithm-language"\s*:\s*"[^"]*"', '"algorithm-language": "Python"', content, ) # Replace algorithm-location content = re.sub( r'"algorithm-location"\s*:\s*"[^"]*"', f'"algorithm-location": "../../../Algorithm.Python/{algo_file}"', content, ) # Ensure backtesting environment content = re.sub( r'"environment"\s*:\s*"[^"]*"', '"environment": "backtesting"', content, ) ``` ### Technical Analysis `ALGO_FILE` is accepted without requiring it to be a basename, without canonicalizing it, and without checking that its resolved path remains under `$LEAN_ROOT/Algorithm.Python`. Quoting prevents shell metacharacter injection, but it does not prevent filesystem traversal. A value containing `../` components can escape the intended algorithm directory while still passing the `-f` check. The r ...[truncated 2378 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run_backtest.sh:69
Finding

Potentially credential-bearing configuration is predictably duplicated and overwritten

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs use of environment variables, reads and edits configuration files, and references helper scripts that create or swap config files, yet it declares no tool scope or allowed-tools restrictions. Without explicit capability boundaries, an agent may invoke broader file and environment access than intended, increasing the chance of unauthorized reads/writes or unsafe execution paths when handling trading configs and local repositories.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description contains broad triggers such as 'manage US equity algorithm development', 'analyze backtest results', 'config editing', and 'deploy to Interactive Brokers TWS', which can match many common user requests beyond safe backtesting. Over-broad invocation criteria can cause the skill to activate in contexts involving sensitive config changes, live trading setup, or credential-adjacent workflows when a more specialized or safer skill should have been selected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The header comments state that the original config.json is never touched, but the script later copies a generated backtest config over the live source config and restores it afterward. This discrepancy is dangerous because users may rely on the safety claim while the script mutates a potentially credential-bearing configuration file, creating risk of accidental corruption, race conditions, or exposure if the process crashes or multiple runs occur concurrently.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code unconditionally rewrites the algorithm-language field to Python. This is a natural-language locale/policy-style constraint embedded in code behavior, and the file does not offer an opt-in, alternative language selection, or explanation that the skill is intentionally Python-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.