Back to skill

Security audit

Trading Bot AI Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is an offline crypto grid-trading simulator that explicitly avoids accounts, credentials, wallets, network services, and live trading.

Before installing, understand that this is for hypothetical offline strategy modeling only. Do not provide exchange keys, wallet secrets, Telegram tokens, seed phrases, or real account credentials; use only scenario parameters and treat outputs as simplified examples, not trading advice or verified performance.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.