Back to skill

Security audit

Dfw Trading Signals

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is being sent to Review because it markets advanced financial analytics that the bundled code does not actually implement.

Before installing, treat this as a basic crypto market-data helper, not professional or statistically validated trading advice. Be aware it can send selected assets and a CoinGecko API key to external services, and its unused unpinned dependencies should be removed or pinned before use in a sensitive environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned and Unused Third-Party Dependencies Increase Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill advertises sophisticated probabilistic analytics, backtesting, regime-adjusted thresholds, and whale/on-chain correlation, but the static finding indicates the implemented behavior does not actually provide those controls or computations. This is dangerous because users may place financial trust in outputs that appear quantitatively rigorous when they are in fact based on much simpler heuristics, creating a deception and unsafe-decision risk amplified by the financial trading context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description advertises institutional-grade probabilistic analytics, confidence intervals, historical win rates, market-regime thresholds, and whale-flow correlation, but the implementation only performs basic heuristic RSI/VWAP/price-change checks and DeFi pool listing. In a trading context, this discrepancy can materially mislead users into relying on outputs as sophisticated decision support, increasing the risk of financial loss through false trust and unsafe automation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to an environment variable and external Python/network dependencies but does not define any explicit tool scope such as permissions or allowed-tools. That creates unnecessary ambiguity about what runtime capabilities the skill may exercise, which increases the risk of overbroad network use or accidental secret exposure in systems that rely on manifest scoping for enforcement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill provides concrete trading actions, invalidation levels, and position-sizing guidance without a clear warning that the content is not financial advice and can result in losses. In a trading skill, this context makes the omission more dangerous because users may interpret the guidance as reliable professional advice and take real-money actions without understanding risk, uncertainty, or model limitations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
74% confidence
Finding

This hardcoded CoinGecko endpoint confirms outbound network communication to a third-party service. In this skill, the request includes asset identifiers and may include an API key header, so the main risk is undisclosed external data transmission rather than code execution or direct compromise.

Content

Scanner excerpt · trade_signals.py (reported line 20)May include surrounding context.

python
from datetime import datetime, timezone

# ── Constants ─────────────────────────────────────────────────────────────────
COINGECKO_BASE = "https://api.coingecko.com/api/v3"
DEFILLAMA_POOLS = "https://yields.llama.fi/pools"
SAUCER_POOLS = "https://api.saucerswap.finance/pools"
BINANCE_OHLCV = "https://api.binance.com/api/v3/klines"

External Transmission

Medium
Category
Data Exfiltration
Confidence
72% confidence
Finding

This hardcoded SaucerSwap API endpoint also represents outbound third-party communication without any explicit runtime notice to the user. The danger is limited to privacy/transparency concerns and dependency on an external service, but in a finance-related skill that still matters because users may not expect portfolio-interest queries to be transmitted.

Content

Scanner excerpt · trade_signals.py (reported line 22)May include surrounding context.

python
# ── Constants ─────────────────────────────────────────────────────────────────
COINGECKO_BASE = "https://api.coingecko.com/api/v3"
DEFILLAMA_POOLS = "https://yields.llama.fi/pools"
SAUCER_POOLS = "https://api.saucerswap.finance/pools"
BINANCE_OHLCV = "https://api.binance.com/api/v3/klines"

SYMBOL_MAP = {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · trade_signals.py (reported line 23)May include surrounding context.

python
COINGECKO_BASE = "https://api.coingecko.com/api/v3"
DEFILLAMA_POOLS = "https://yields.llama.fi/pools"
SAUCER_POOLS = "https://api.saucerswap.finance/pools"
BINANCE_OHLCV = "https://api.binance.com/api/v3/klines"

SYMBOL_MAP = {
    "btc": "bitcoin", "eth": "ethereum", "xrp": "ripple",

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code sends user-selected asset queries and optional API-authenticated requests to third-party services without any user-facing notice or consent flow. While the transmitted data is limited, silent outbound requests can expose usage patterns and API key use to external providers, which is a privacy and transparency issue in agent skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.