Back to skill

Security audit

hyperliquid-btc-auto-trader

Security checks for vulnerabilities and agentic risk

Overview

This is a real-money autonomous trading skill that asks for a wallet private key and can place mainnet trades, but its safety controls and stop mechanisms are under-scoped or not implemented.

Do not install this for live funds without an independent code and trading-safety audit. Use testnet or paper trading first, use only a dedicated low-balance wallet key, never expose a primary private key to the agent environment, require an explicit live-trading enable switch, implement a working kill switch and exchange-state risk reconciliation, and pin dependencies before any real deployment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
safety/limits.py:7
Finding

Daily-loss and consecutive-loss safety controls are nonfunctional

Content
View full analysis
= Config.MAX_TRADES_PER_DAY: return False if self.daily_loss >= Config.MAX_DAILY_LOSS_USD: return False balance = self.get_usdc_balance() if balance < Config.MIN_USDC_BALANCE: return False if time.time() - self.last_trade_time < 300: # 5 min cooldown return False return True ``` ```python self.daily_trades += 1 self.last_trade_time = time.time() ``` ### Technical Analysis `daily_loss` and `consecutive_losses` are initialized but are never updated from fills, closed positions, or realized account P&L. Therefore, the configured daily-loss limit and the advertised pause after three consecutive losses cannot trigger. The code also does not associate `daily_trades` with a calendar date or reset it at the start of a new UTC trading day. As a result, the five-trade control is a lifetime counter for the current process rather than a daily limit. Restarting the process resets all counters, allowing the nominal limits to be bypassed unintentionally or deliberately. The documentation describes these controls as hard safety limits that cannot be bypassed, but the implementation only checks volatile in-memory values that are not reconciled against exchange state. ### Attack Path 1. An operator launches the bot against a funded Hyperliquid mainnet wallet. 2. The bot submits one or more losing market orders. 3. The exchange realizes losses when positi ...[truncated 925 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
safety/limits.py:32
Finding

Aggregate exposure, leverage, stop-loss, and take-profit protections are not enforced

Content
View full analysis
= 80 else 1.2 if signal["score"] >= 60 else 1.0) size_usd = min(size_usd, Config.MAX_POSITION_USD) sz = round(size_usd / signal["price"], 4) # BTC quantity # Place market order order = self.exchange.market_open(Config.ASSET, is_buy, sz, slippage=0.01) print(f"✅ TRADE EXECUTED | Score: {signal['score']} | {signal['direction']} {sz} BTC") self.daily_trades += 1 self.last_trade_time = time.time() ``` Relevant configuration: ```python MAX_LEVERAGE = 40 BASE_POSITION_USD = 2000 MAX_POSITION_USD = 10000 ``` ### Technical Analysis The implementation limits only the nominal value of an individual order. It does not retrieve the existing BTC position, account leverage, pending orders, or post-trade exposure before submitting the market order. Consequently, multiple same-direction orders can accumulate an aggregate position greater than the documented $10,000 maximum. `MAX_LEVERAGE` is declared but never applied or verified. The execution path also does not submit the advertised reduce-only take-profit and stop-market stop-loss orders. The return value assigned to `order` is not inspected. The code increments the trade counter and prints a success message without verifying whether the order was accepted, rejected, or partially filled. This can cause local safety state to diverge from exchange state. ### Attack Path 1. The wallet already holds a BTC position, or the bot previously opened one. 2. A new qualifying signal is produced. ...[truncated 998 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:11
Finding

Circuit breaker and documented manual kill switch are not connected to execution

Content
View full analysis
50 points in under 1 minute""" now = datetime.now() if (now - self.last_signal_time).total_seconds() < 60: if abs(new_signal - self.last_signal) > 50: self.paused_until = now + timedelta(minutes=30) print("⚠️ CIRCUIT BREAKER TRIGGERED — Pausing trading for 30 minutes") self.last_signal = new_signal self.last_signal_time = now ``` ### Technical Analysis Although a `CircuitBreaker` class exists, `trader.py` does not import, instantiate, or inv ...[truncated 1608 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
strategies/anchored_vwap.py:45
Finding

Invalid anchored-VWAP calculation can saturate signals and trigger real orders

Content
View full analysis
= df.index[0] # full history for simplicity sub = df[mask].copy() sub["typical"] = (sub["high"] + sub["low"] + sub["close"]) / 3 sub["age"] = range(len(sub)) decay = 0.95 ** sub["age"] weighted_pv = (sub["typical"] * sub["volume"] * decay).cumsum() weighted_vol = (sub["volume"] * decay).cumsum() vwap_price = (weighted_pv / weighted_vol).iloc[-1] confidence = self._vwap_confidence(anchor["significance"], len(sub)) vwaps.append({"price": vwap_price, "confidence": confidence, "type": anchor["type"]}) return vwaps ``` ```python def _calculate_weighted_deviation(self, vwaps, current_price): if not vwaps: return 0 total_w = sum(v["confidence"] for v in vwaps) return sum((cur ...[truncated 2434 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned dependencies make the wallet-signing environment non-reproducible

Content
View full analysis
=1.0.0 pandas pandas_ta python-dotenv schedule numpy ``` ### Technical Analysis The dependency file does not pin exact versions or package hashes. The security-sensitive Hyperliquid SDK accepts any version at or above `1.0.0`, while all other packages are entirely unconstrained. A future installation can therefore resolve code that was not part of this audit. Python packages can execute code during installation and are imported into a process that holds the wallet address and private key. The unused `schedule` dependency also unnecessarily expands the supply-chain attack surface. No evidence was found that the currently named packages are malicious, and no dependency-confusion package name was confirmed. The risk arises from unrestricted future resolution and the privileged context in which these dependencies run. ### Attack Path 1. An operator installs the project at a later date using `requirements.txt`. 2. The package index resolves newer or otherwise different dependency versions. 3. Installation hooks or imported package code execute in the bot's environment. 4. The bot process loads `HYPERLIQUID_PRIVATE_KEY` and initializes transaction-signing functionality. 5. A compromised dependency could access process secrets, alter market data handling, modify orders, or redirect signing behavior. ### Impact Assessment A compromised dependency would execute with the same operating-system privileges as the bot process. Within that scope, it could read environment variables and files accessible to the process, including the wallet private key, and could influence or initiate transactions through the exchange client. The ultimate financial scope could include the funds and trading authority associated with the configured wallet. This audit di ...[truncated 109 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill describes autonomous mainnet trading and references wallet address/private key setup without a prominent warning about real-funds risk, credential sensitivity, liquidation risk from leverage, and irreversibility of blockchain transactions. In this context, missing warnings materially increase the chance that users expose secrets or authorize dangerous live trading without informed consent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
#### 2. of `SKILL.md`

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file starts an autonomous trading loop on mainnet immediately when executed and initializes the exchange with a real wallet address and private key configuration, but provides no interactive confirmation, dry-run mode, or user-facing warning. In the context of a trading skill, this is dangerous because accidental execution can place real BTC-USDC trades repeatedly every minute, causing direct financial loss if the strategy, config, or safety checks are wrong or misconfigured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly promotes a fully autonomous trading bot operating on Hyperliquid mainnet with up to 40x leverage, but it does not clearly warn users that this will place real trades with real funds and can incur rapid, substantial losses. In the context of an agent skill, this omission is dangerous because users may treat the skill as a normal automation utility rather than a high-risk financial system capable of executing irreversible market actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README tells users to export a wallet address and private key directly into environment variables without any accompanying guidance on secret handling, storage hygiene, or exposure risks. In an agent or automation environment, this increases the chance that sensitive credentials are leaked through shell history, logs, process inspection, misconfigured deployment systems, or copied setup snippets, which could lead to wallet compromise and theft of funds.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation wording is broad and lacks clear trigger constraints for actions that purportedly start, pause, or stop live trading. In a high-risk financial context, ambiguous activation semantics increase the chance of unintended execution, operator confusion, or accidental initiation of sensitive workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown asserts that all 8 hard safety limits are implemented and non-bypassable, but no code in this file demonstrates or enforces those controls. In a live mainnet trading context, this creates a dangerous false sense of safety that could lead users to trust autonomous execution with real funds and private keys without actual protection.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Claiming the skill is 'ready to trade' and can run autonomously 24/7 suggests production readiness for real-money trading despite the absence of executable trading logic in the provided file. This can mislead users into enabling or installing a purported live trading system under unsafe assumptions, especially where financial loss is possible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code reads a private key from the environment at L08, which is a sensitive credential access operation covered by this rule for code files. There is no nearby comment, docstring, print/log statement, or confirmation explaining this behavior in the file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is framed as a safety/limits component, but it directly performs live market execution through exchange.market_open(). This is dangerous because callers may reasonably trust this class as a guardrail layer while it actually contains side-effecting trade logic, increasing the chance of unintended or unauthorized real-money trades when integrated into an agent workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code places an immediate market order automatically once a score threshold is met, with no user confirmation, secondary authorization, or explicit safety interlock before sending a live trade. In an agent skill context, this is especially dangerous because upstream signals, prompt injection, bad model outputs, or misconfiguration can directly trigger irreversible financial actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description states the skill is an autonomous mainnet trader but does not define when it may activate, what preconditions must be met, or what trading/risk boundaries apply. For a financial trading skill operating on mainnet, this ambiguity can enable unintended invocation or overly broad use, increasing the chance of unauthorized or unsafe trades with real funds.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Within _compute_all_vwaps, the code iterates over provided anchors but uses df.index >= df.index[0], which selects the entire dataset for every anchor. This actively conflicts with the function name and surrounding logic that imply VWAPs should be anchored to each supplied anchor point, making the documented intent of anchor-based computation diverge from actual behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions imply that natural-language commands will start and control a live trading loop, but no such command implementation is present here. In an autonomous trading skill, ambiguous or overstated activation behavior can cause unsafe operator assumptions about what actions the agent can take and when it may begin interacting with mainnet systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language instructions prescribe specific English phrases the user should say to operate the skill, with no indication that other languages or locales are supported. This can be a language-policy issue when a skill mandates a single language without opt-in or alternative language support.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency 'hyperliquid-python-sdk>=1.0.0' is only lower-bounded rather than pinned, so any future version meeting the constraint may be installed. That permits unreviewed dependency drift and creates supply-chain risk even if no immediate exploit is shown in this file.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
hyperliquid-python-sdk>=1.0.0
pandas
pandas_ta
python-dotenv

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency 'pandas' is unpinned, so installations may resolve to different versions over time, reducing build reproducibility and making it harder to ensure vulnerable releases are excluded. In a requirements manifest, this is a real supply-chain hygiene weakness even though it does not by itself prove exploitation.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
hyperliquid-python-sdk>=1.0.0
pandas
pandas_ta
python-dotenv
schedule

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Pandas has known advisories, but because the manifest does not pin a version, it is impossible to determine whether deployments will receive a safe or affected release. The danger is not confirmed active exploitation in this file, but the inability to verify exposure makes secure deployment assurance weak.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency 'pandas_ta' is unpinned, which permits non-deterministic installs and increases supply-chain risk if a future release introduces malicious or vulnerable code. This weakens reproducibility and patch assurance for the skill environment.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
hyperliquid-python-sdk>=1.0.0
pandas
pandas_ta
python-dotenv
schedule
numpy

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency 'python-dotenv' is unpinned, so the installed version may drift and could include vulnerable behavior or breaking changes without review. Because dotenv libraries often interact with local configuration files and secrets, uncontrolled version resolution increases risk.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
hyperliquid-python-sdk>=1.0.0
pandas
pandas_ta
python-dotenv
schedule
numpy

Unverifiable Dependency: python-dotenv has 2 known advisory(ies) (CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

python-dotenv has known advisories and the requirements file does not pin a version, so an affected release could be installed without visibility. Since dotenv tooling can read or modify environment configuration and, in some cases, interact with filesystem paths, version ambiguity can have more direct operational impact than a purely passive library.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency 'schedule' is unpinned, which allows future installs to pull arbitrary newer releases and undermines reproducibility. This is a supply-chain security weakness because dependency changes can introduce vulnerabilities or malicious behavior outside the author's review.

Content

Scanner excerpt · requirements.txt (reported line 5)May include surrounding context.

text
pandas
pandas_ta
python-dotenv
schedule
numpy

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency 'numpy' is unpinned, so different environments may install different releases, including versions with known defects or vulnerabilities. This creates avoidable supply-chain uncertainty and weakens the ability to verify that a safe version is consistently used.

Content

Scanner excerpt · requirements.txt (reported line 6)May include surrounding context.

text
pandas_ta
python-dotenv
schedule
numpy

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
94% confidence
Finding

NumPy has multiple historical advisories, and without version pinning there is no reliable way to verify that an installed release is unaffected. The primary issue here is unverifiable exposure due to dependency drift, not direct evidence that the current file triggers a NumPy vulnerability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.