Back to skill

Security audit

TA Radar

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a crypto technical-analysis skill, but it uses an unsafe fixed temporary execution path and sends asset lookups to public third-party services, so it should be reviewed before use.

Install only if you are comfortable sending tickers or contract addresses to the named market-data services and the allorigins.win proxy. Prefer running it in an isolated account or container because the current workflow uses a predictable /tmp script path, and verify the package is complete before relying on it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:76
Finding

Predictable Temporary File Allows Symlink-Based File Overwrite and Race-Condition Code Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 76–103
Vulnerability Type: Unsafe predictable temporary file
Risk Level: Medium

Vulnerable Code

bash
cat > /tmp/ta_radar_run.py << 'PYEOF'
&lt;PASTE COMPLETE PYTHON SCRIPT HERE&gt;
PYEOF
bash
TA_SYMBOL="&lt;SYMBOL&gt;" TA_INTERVAL="&lt;INTERVAL&gt;" python3 /tmp/ta_radar_run.py
bash
rm -f /tmp/ta_radar_run.py

Technical Analysis

The workflow writes and executes Python code at the fixed, globally predictable path /tmp/ta_radar_run.py. Ordinary shell redirection follows symbolic links and does not create the file exclusively. The instructions also do not verify file ownership, type, or permissions before writing and executing it.

On a shared system, another local user can prepare this path as a symbolic link. When the workflow performs the redirection, it may overwrite the symbolic link's target with the Agent's privileges. There is also a time-of-check/time-of-use race between writing and executing the file: an attacker able to manipulate the shared temporary directory could replace the path after the write but before Python opens it.

The cleanup command does not prevent either issue. It runs only after execution and removes the pathname rather than securely controlling the temporary file throughout its lifecycle.

Attack Path

Symlink overwrite scenario:

  1. A local attacker predicts that the Skill will use /tmp/ta_radar_run.py.
  2. Before invocation, the attacker creates that path as a symbolic link to a file writable by the Agent.
  3. The Agent follows the Skill instructions and writes the embedded script through shell redirection.
  4. The operating system follows the symbolic link, overwriting the target file with the Agent's privileges.
  5. The final rm -f removes the temporary pathname but cannot undo corruption of the target.

Race-condition execution scenario:

  1. The Agent writes ...[truncated 1085 chars]
Remediation
View remediation

Remediation Suggestions

Create a private, uniquely named temporary directory and place the script inside it. Apply restrictive permissions before writing and register cleanup immediately:

bash
tmpdir="$(mktemp -d)" || exit 1
trap 'rm -rf -- "$tmpdir"' EXIT
umask 077

script="$tmpdir/ta_radar_run.py"
cat > "$script" <<'PYEOF'
# Complete embedded Python script
PYEOF

TA_SYMBOL="$SYMBOL" TA_INTERVAL="$INTERVAL" python3 "$script"

Additional hardening should include:

  1. Do not reuse a fixed pathname in a shared directory.
  2. Ensure the temporary directory is owned by the current account and has mode 0700.
  3. Keep the script inaccessible to other users with umask 077.
  4. Avoid separating creation from execution through an attacker-manipulable path.
  5. Run the Skill as an unprivileged account with access limited to resources required for market analysis.
  6. Use an exit trap so cleanup occurs on success, failure, or interruption.
  7. Where supported, execute the embedded program directly from a securely opened file descriptor or avoid materializing it as a file.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

Step 4: Clean Up Temporary File

bash
rm -f /tmp/ta_radar_run.py

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends user-supplied symbols or contract addresses to Binance, Gate.io, DexScreener, and the allorigins proxy, but the description does not clearly warn users that their inputs will be transmitted to third parties. Contract addresses can reveal user research interests, portfolio focus, or operational intent, and transmission through a public proxy adds additional privacy risk.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

TA_SYMBOL="" TA_INTERVAL="" python3 /tmp/ta_radar_run.py

text

- **Success (exit code 0)**: Present the full standard output of the script to the user exactly as-is, no trimming or summarization.
- **Failure (exit code non-0)**: Present the standard error output to the user and prompt to check parameter format.

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This code transmits the resolved trading symbol to api.binance.info, an external third-party service. Even if the payload is small, it exposes user-supplied asset interests and request metadata to an external endpoint, which is a real privacy and data-handling concern in an agent skill.

Content

Scanner excerpt · SKILL.md (reported line 235)May include surrounding context.

md
sym += "USDT"

    url = (
        f"https://api.binance.info/api/v3/klines"
        f"?symbol={sym}&interval={interval}&limit={limit}"
    )
    data, err = safe_fetch(url)

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This fallback path sends the user-derived trading pair to Gate.io, another external service. Because it is automatic failover, users may not realize their inputs are being sent to a secondary provider, increasing the transparency and privacy risk.

Content

Scanner excerpt · SKILL.md (reported line 269)May include surrounding context.

md
gate_pair = sym[:-4] + "_USDT"

    url = (
        f"https://api.gateio.ws/api/v4/spot/candlesticks"
        f"?currency_pair={urllib.parse.quote(gate_pair)}"
        f"&interval={interval}&limit={limit}"
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill sends on-chain contract addresses to DexScreener search, which can reveal specific tokens the user is investigating. Contract-address queries are often more sensitive than generic ticker lookups because they can encode niche or newly discovered asset interest.

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
Returns (base_symbol: str | None, pair_label: str, error_msg: str | None).
    """
    dex_url = (
        f"https://api.dexscreener.com/latest/dex/search"
        f"?q={urllib.parse.quote(address)}"
    )
    proxy_url = (

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

The skill routes DexScreener queries through the public allorigins.win proxy, causing user-supplied contract addresses and destination URLs to be exposed to an additional intermediary outside the primary data source. Using a public proxy materially increases privacy, integrity, and availability risks because responses could be logged, altered, rate-limited, or unavailable.

Content

Scanner excerpt · SKILL.md (reported line 332)May include surrounding context.

md
f"?q={urllib.parse.quote(address)}"
    )
    proxy_url = (
        f"https://api.allorigins.win/raw"
        f"?url={urllib.parse.quote(dex_url)}"
    )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The deployment guide instructs operators to forward the user's raw query directly to a remote API endpoint, but provides no notice, minimization guidance, or privacy controls. If users include wallet addresses, trading intent, or other sensitive text, that data is transmitted to a third-party hosted service and may be logged or retained, creating an avoidable privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The workflow instructs the agent to create and delete a temporary file in /tmp without clearly warning the user that the skill modifies the local filesystem. While the file path is fixed and the action is limited, undisclosed write/delete behavior reduces transparency and can matter in constrained or audited execution environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

这里以自然语言要求输出风格被硬编码,并且全文以中文为唯一面向语言,没有体现用户可选择语言或 locale 的机制。根据该规则,强制单一语言而无用户选择或明确合规/地域性 justification,可能构成语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.