T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:49- Finding
Remote installer is downloaded and executed without integrity verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mainly for LEAN trading backtests, but it needs review because it handles potentially sensitive trading configuration less safely than its documentation claims.
Review this skill before installing. Use it in an isolated project or VM, avoid running setup with elevated privileges, do not point it at a live broker config containing Interactive Brokers credentials, and prefer pinned dependencies plus a minimal backtest-only config. Back up LEAN config files before using the helper script.
SKILL.md:49Remote installer is downloaded and executed without integrity verification
SKILL.md:65Third-party Python dependencies are installed without version or hash pinning
scripts/run_backtest.sh:19Unvalidated algorithm arguments allow path traversal and unsafe configuration injection
scripts/run_backtest.sh:69Potentially credential-bearing configuration is predictably duplicated and overwritten
The skill explicitly instructs use of environment variables, reads and edits configuration files, and references helper scripts that create or swap config files, yet it declares no tool scope or allowed-tools restrictions. Without explicit capability boundaries, an agent may invoke broader file and environment access than intended, increasing the chance of unauthorized reads/writes or unsafe execution paths when handling trading configs and local repositories.
The description contains broad triggers such as 'manage US equity algorithm development', 'analyze backtest results', 'config editing', and 'deploy to Interactive Brokers TWS', which can match many common user requests beyond safe backtesting. Over-broad invocation criteria can cause the skill to activate in contexts involving sensitive config changes, live trading setup, or credential-adjacent workflows when a more specialized or safer skill should have been selected.
The header comments state that the original config.json is never touched, but the script later copies a generated backtest config over the live source config and restores it afterward. This discrepancy is dangerous because users may rely on the safety claim while the script mutates a potentially credential-bearing configuration file, creating risk of accidental corruption, race conditions, or exposure if the process crashes or multiple runs occur concurrently.
The code unconditionally rewrites the algorithm-language field to Python. This is a natural-language locale/policy-style constraint embedded in code behavior, and the file does not offer an opt-in, alternative language selection, or explanation that the skill is intentionally Python-only.
No suspicious patterns detected.