Back to skill

Security audit

Scrub Trading Signals Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill is a crypto market-data signal helper with purpose-aligned external API use, though users should note the missing referenced script and unpinned dependencies.

Install only in an environment where making outbound market-data API calls is acceptable. Use a limited CoinGecko key, avoid exposing unrelated secrets to the skill runtime, and be aware that the referenced trade_signals.py file is absent, so the packaged skill may not run as described without additional implementation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-21
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

yaml
install:
  - kind: uv
    package: requests
    bins: []
  - kind: uv
    package: ccxt
    bins: []

Technical Analysis

The Skill instructs the environment to install requests and ccxt without exact version constraints, integrity hashes, or a committed lockfile. Consequently, installation can resolve mutable package versions whose contents may differ from those reviewed during the audit.

These dependencies are relevant to the declared market-data functionality, and there is no evidence that either named package is currently malicious. The vulnerability is the absence of controls that ensure users receive a known, reviewed dependency artifact. Exposure may arise from a compromised upstream release, package-index compromise, dependency confusion in a misconfigured package registry, or an unexpectedly vulnerable future release.

The project contains only SKILL.md; the referenced trade_signals.py implementation is absent. Therefore, runtime API-key handling, endpoint restrictions, TLS behavior, and dependency usage could not be independently verified.

Attack Path

  1. An attacker compromises a future release or distribution channel for an unpinned dependency, or causes a malicious artifact to be preferred through a misconfigured package index.
  2. A user installs or loads the Skill after the malicious version becomes resolvable.
  3. The package installer selects that version because the Skill does not constrain versions or verify artifact hashes.
  4. Malicious package installation or runtime code executes with the privileges granted to the Skill environment.
  5. The code may inspect process-accessible information, including COINGECKO_API_KEY, and transmit it or perform other actions permitted by the environment.

This path depends on upstream o ...[truncated 810 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin each direct dependency to an exact, reviewed version, such as requests==X.Y.Z and ccxt==X.Y.Z.
  2. Commit a reproducible lockfile containing resolved transitive dependency versions.
  3. Require cryptographic hashes for all downloaded artifacts and reject hash mismatches.
  4. Configure installation to use an explicit trusted package index and disable unintended fallback indexes.
  5. Run dependency vulnerability and provenance checks in CI, including review of new versions before updating pins.
  6. Install and execute dependencies in an isolated, non-privileged environment with narrowly scoped filesystem and network access.
  7. Expose COINGECKO_API_KEY only to the process that needs it and prevent dependencies from reaching unrelated network destinations where the runtime supports egress controls.
  8. Add the referenced trade_signals.py implementation to the package so its endpoint construction, credential handling, input validation, and actual network behavior can be audited.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill declares use of COINGECKO_API_KEY and describes outbound API usage, but it does not clearly warn users that an environment secret may be accessed and transmitted to an external service. In this context the key is likely intended for legitimate API authentication, but the lack of explicit disclosure and consent around credential use creates avoidable secret-handling risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

python
# SaucerSwap public API (no auth)
SAUCER_POOLS_URL = "https://api.saucerswap.finance/pools"

def saucer_lp_signal(pools: list) -> dict:
    """Returns best LP opportunities with impermanent loss risk rating."""

Static analysis

No suspicious patterns detected.