Back to skill

Security audit

Vegas T Trading

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed trading-analysis skill that fetches market data and prints recommendations, with financial-risk and supply-chain cautions but no hidden persistence, credential access, or trade execution.

Install only in an isolated Python environment, consider pinning akshare and pandas versions, and do not treat the output as financial advice or an automated trading signal. Be aware that crypto data is effectively Binance-only and the tool is Chinese-first.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
SKILL.md:150
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:150-154
Vulnerability Type: Unpinned package installation and supply-chain exposure
Risk Level: Low

Vulnerable Code

bash
**Installation**:
```bash
# Python 3.8+
pip3 install akshare
text

The implementation also recommends unpinned upgrades when dependencies are unavailable:

```python
print("❌ pandas is not installed. Run: pip3 install pandas -U")
python
print("  Please run: pip3 install akshare pandas -U")

Technical Analysis

The documented installation command retrieves the latest available akshare release and its transitive dependencies without a version constraint, lock file, or integrity hash. The implementation similarly recommends installing or upgrading akshare and pandas without pinning versions.

As a result, the code that users receive can differ from the dependency versions reviewed with this project. A compromised upstream release, compromised maintainer account, malicious transitive dependency, or future incompatible release could introduce arbitrary behavior during package installation or when akshare is imported at scripts/vegas_analyzer.py:725.

The project does not automatically execute pip; exploitation requires an operator or agent to follow the installation instructions. No evidence of dependency confusion, typosquatting, a custom package index, or an intentionally malicious package was found.

Attack Path

  1. An attacker compromises a future release of akshare, pandas, or one of their transitive dependencies.
  2. A user or agent follows the documented pip3 install akshare command or the runtime recommendation to execute pip3 install akshare pandas -U.
  3. The package resolver downloads the currently available compromised release because no reviewed version or hash is enforced.
  4. Malicious package installation logic may run during installation, or malicious module code may r ...[truncated 772 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin direct dependencies to reviewed versions, for example through a version-controlled requirements.txt or pyproject.toml.
  2. Generate a fully resolved lock file that also pins transitive dependencies.
  3. Require package hashes by using a hash-locked requirements file and installing with pip install --require-hashes -r requirements.txt.
  4. Replace all pip install ... -U recommendations with installation from the reviewed lock file.
  5. Use an isolated virtual environment rather than modifying a global Python environment.
  6. Add automated dependency vulnerability and provenance scanning to the release process.
  7. Review and deliberately update dependency pins instead of automatically accepting the newest upstream release.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents the skill as a trading-analysis aid, but the body also relies on external network/data-source access that is not disclosed in the metadata. This mismatch is dangerous because reviewers and users may approve the skill for analytical behavior while missing its ability to contact outside services, expanding the trust boundary and attack surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README presents explicit trading actions such as position sizing and strong buy recommendations without prominent risk disclosures or caution about financial loss. In a trading-oriented skill, users may reasonably treat this as actionable financial guidance, increasing the chance of harmful reliance and monetary loss.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents network-dependent behavior but does not declare any tool scope or permission boundaries. In an agent environment, undeclared network capability reduces reviewability and can enable unintended external access, data exfiltration, or execution paths that operators did not explicitly approve.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough to match common financial conversation, which can cause the skill to activate unexpectedly outside a clearly intended context. In an agent system, overbroad activation increases the chance that trading guidance or external-data behavior is invoked when the user did not intend to call this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and all user-facing guidance are written exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy, a fixed language/locale without opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description is written to force a specific language/locale without indicating user choice or fallback behavior. This can cause the agent to respond in an unwanted language, leading to misunderstanding of trading recommendations and risk-related details, which is more dangerous in a financial skill where precision matters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and user-facing behavior indicate the skill is designed exclusively in Chinese, including a hard requirement note and later Chinese-only CLI/output strings. For a general-purpose analysis tool, this is a natural-language locale policy issue because users are not given any opt-in or language selection mechanism.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function signature and CLI expose an exchange parameter, implying the skill can fetch crypto data from a specified exchange. However, the implementation hardcodes https://api.binance.com/... and never uses the exchange argument, so the documented/user-facing intent contradicts actual behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/vegas_analyzer.py (reported line 770)May include surrounding context.

python
symbol_clean = symbol.replace('/', '').replace('USDT', 'USDT')
    
    url = f"https://api.binance.com/api/v3/klines?symbol={symbol_clean}&interval={interval}&limit=1000"
    
    try:
        req = urllib.request.Request(url, headers={'User-Agent': 'Mozilla/5.0'})

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Most visible outputs, prompts, and error messages are emitted only in Chinese, and the code does not expose any mechanism for users to choose another language. This violates the locale-choice criterion unless the restriction is explicitly justified as region-specific, which is not documented here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes the skill as a Vegas tunnel v3.0 system based on EMA sets plus Fibonacci retracement and multi-period scoring. In the non---multi path, the code analyzes signals via analyze_t_signal(...) only, without calling analyze_with_fibonacci(...) or computing score data, so the advertised Fibonacci-driven behavior is not actually applied for normal single-period use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The document presents all instructions and output examples in a single language and does not mention that the user can choose another language or locale. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document explicitly states 'AKShare(唯一数据源)' at L134, which implies a single-source implementation. However, the troubleshooting section later says A-share data can fail from '东方财富 + 新浪财经均失败' at L325, indicating multiple underlying sources are actually involved.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description is broad and does not clearly constrain when the skill should activate, which can cause the agent to invoke it for loosely related finance queries. In a trading-advice skill, overbroad activation increases the chance of unsolicited or contextually inappropriate financial guidance, though this is more of a safety/quality issue than a direct exploit primitive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's human-facing comments and error messages are written in Chinese, including the visible user output at lines 9 and 16. This imposes a specific language on users without any opt-in, fallback, or documentation that the skill is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.