Back to skill

Security audit

KTrendz Lightstick Trading

Security checks for vulnerabilities and agentic risk

Overview

The skill clearly aims to trade K-Trendz tokens, but it can execute real buy/sell transactions without script-level confirmation and has unsafe response parsing that could run code if the API response is compromised.

Review this skill carefully before installing. It is not clearly malicious, but it handles a trading API key, stores that key locally in plaintext, and can place real buy or sell orders. Only use it if you trust K-Trendz and are comfortable enforcing your own confirmation process; safer versions should add mandatory confirmations, dry-run/quote-only defaults, strict input validation, and safe JSON parsing via stdin rather than interpolating API responses into Python code.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/buy.sh:61
Finding

Remote API Responses Are Embedded into Executable Python Source

Content
View full analysis
/dev/null || echo "$RESPONSE" ``` From `scripts/sell.sh:61-71`: ```bash python3 << EOF import json data = json.loads('''$RESPONSE''')['data'] print(f"Token: {data['artist_name']}") print(f"Amount: {data['amount']} token") print(f"Refund: \${data['net_refund_usdc']:.2f} USDC") print(f"Fee: \${data.get('fee_usdc', 0):.2f} USDC") print(f"Tx Hash: {data.get('tx_hash', 'pending')}") EOF ``` From `scripts/sell.sh:77`: ```bash python3 -c "import json; d=json.loads('''$RESPONSE'''); print(d.get('error', d))" 2>/dev/null || echo "$RESPONSE" ``` ### Technical Analysis The scripts interpolate an HTTP response directly into Python source code inside a triple-quoted string. Although `json.loads()` is intended to parse the response as data, interpolation happens before Python parses the resulting program. A response containing a sequence that closes the triple-quoted string can introduce additional Python statements. Therefore, a maliciou ...[truncated 1840 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/buy.sh:17
Finding

Unvalidated Trade Parameters and Missing Script-Level Transaction Confirmation

Content
View full analysis
" echo "" echo "Available tokens:" echo " RIIZE, IVE, BTS, Cortis, 'K-Trendz Supporters', 'All Day Project'" exit 1 fi SLIPPAGE="${2:-5}" ``` From `scripts/buy.sh:34-37`: ```bash PRICE_RESPONSE=$(curl -s -X POST "$BASE_URL/token-price" \ -H "Content-Type: application/json" \ -H "x-bot-api-key: $API_KEY" \ -d "{\"artist_name\": \"$ARTIST\"}") ``` From `scripts/buy.sh:49-57`: ```bash # Execute buy echo "" echo "Executing purchase..." RESPONSE=$(curl -s -X POST "$BASE_URL/buy" \ -H "Content-Type: application/json" \ -H "x-bot-api-key: $API_KEY" \ -d "{\"artist_name\": \"$ARTIST\", \"max_slippage_percent\": $SLIPPAGE}") ``` From `scripts/sell.sh:17-27`: ```bash # Get artist name from argument ARTIST="${1:-}" if [ -z "$ARTIST" ]; then echo "Usage: ./scripts/sell.sh " echo "" echo "Available tokens:" echo " RIIZE, IVE, BTS, Cortis, 'K-Trendz Supporters', 'All Day Project'" exit 1 fi SLIPPAGE="${2:-5}" ``` From `scripts/sell.sh:34-37`: ```bash PRICE_RESPONSE=$(curl -s -X POST "$BASE_URL/token-price" \ -H "Content-Type: application/json" \ -H "x-bot-api-key: $API_KEY" \ -d "{\"artist_name\": \"$ARTIST\"}") ``` From `scripts/sell.sh:49-57`: ```bash # Execute sell echo "" echo "Executing sale..." RESPONSE=$(curl -s -X POST "$BASE_URL/sell" \ -H "Content-Type: application/json" \ -H "x-bot-api-key: $API_KEY" \ -d "{\"artist_name\ ...[truncated 2883 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
- `SKILL.md` - This file

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs authenticated remote purchase operations against a live API and can spend funds based solely on command-line input, with no higher-level trust boundary, dry-run mode, or transaction gating. In an agent-skill setting, this is dangerous because executing the skill can trigger real financial actions on behalf of the user, making misuse, prompt-triggered execution, or accidental invocation materially harmful.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/buy.sh (reported line 7)May include surrounding context.

sh
CONFIG_FILE="$HOME/.config/ktrendz/config.json"
BASE_URL="https://k-trendz.com/api/bot"

# Get API key from config or environment
if [ -n "$KTRENDZ_API_KEY" ]; then
    API_KEY="$KTRENDZ_API_KEY"
elif [ -f "$CONFIG_FILE" ]; then

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/price.sh (reported line 7)May include surrounding context.

sh
CONFIG_FILE="$HOME/.config/ktrendz/config.json"
BASE_URL="https://k-trendz.com/api/bot"

# Get API key from config or environment
if [ -n "$KTRENDZ_API_KEY" ]; then
    API_KEY="$KTRENDZ_API_KEY"
elif [ -f "$CONFIG_FILE" ]; then

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/sell.sh (reported line 7)May include surrounding context.

sh
CONFIG_FILE="$HOME/.config/ktrendz/config.json"
BASE_URL="https://k-trendz.com/api/bot"

# Get API key from config or environment
if [ -n "$KTRENDZ_API_KEY" ]; then
    API_KEY="$KTRENDZ_API_KEY"
elif [ -f "$CONFIG_FILE" ]; then

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs authenticated remote trading operations, including an actual sell request, based solely on command-line input and immediately executes the sale once pricing succeeds. In an agent-skill context, this is dangerous because it enables irreversible financial actions against a live external service without meaningful user verification or execution safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script executes a sell transaction without any confirmation prompt, preview gate, or explicit acknowledgment immediately before the irreversible action. In a skill or automation environment, this substantially increases the risk of accidental or coerced asset sales, especially if invoked by another tool, script, or misled user.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

With no manifest available, the skill's intended purpose is unknown, so accessing secrets from KTRENDZ_API_KEY or a user config file is an unjustified capability relative to stated intent. This is a semantic capability expansion beyond a narrowly documented local utility unless explicitly declared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script sends the irreversible buy request immediately after fetching a quote, without requiring the user to confirm the artist, displayed cost, or slippage. In a security-sensitive or agent-executed environment, the lack of confirmation materially increases the chance of accidental or unauthorized purchases.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This external transmission submits an authenticated purchase request to a remote endpoint, which can directly trigger a financial transaction. In the context of an agent skill, the danger comes from enabling real-world spending over the network without additional approval or policy checks, not from network use alone.

Content

Scanner excerpt · scripts/buy.sh (reported line 54)May include surrounding context.

sh
echo ""
echo "Executing purchase..."

RESPONSE=$(curl -s -X POST "$BASE_URL/buy" \
    -H "Content-Type: application/json" \
    -H "x-bot-api-key: $API_KEY" \
    -d "{\"artist_name\": \"$ARTIST\", \"max_slippage_percent\": $SLIPPAGE}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell script accesses a credential from either the KTRENDZ_API_KEY environment variable or a local config file, then sends it in the x-bot-api-key header via curl. Although the file has brief internal comments, there is no user-facing warning, prompt, or disclosure that credentials will be read and transmitted to a remote service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/buy.sh (reported line 36)May include surrounding context.

sh
fi

# Call API
RESPONSE=$(curl -s -X POST "$BASE_URL/token-price" \
    -H "Content-Type: application/json" \
    -H "x-bot-api-key: $API_KEY" \
    -d "{\"artist_name\": \"$ARTIST\"}")

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/price.sh (reported line 28)May include surrounding context.

sh
fi

# Call API
RESPONSE=$(curl -s -X POST "$BASE_URL/token-price" \
    -H "Content-Type: application/json" \
    -H "x-bot-api-key: $API_KEY" \
    -d "{\"artist_name\": \"$ARTIST\"}")

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sell.sh (reported line 36)May include surrounding context.

sh
fi

# Call API
RESPONSE=$(curl -s -X POST "$BASE_URL/token-price" \
    -H "Content-Type: application/json" \
    -H "x-bot-api-key: $API_KEY" \
    -d "{\"artist_name\": \"$ARTIST\"}")

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

With no manifest available, the skill's purpose is unknown, so accessing an API key from environment variables or a user config file is an unjustified capability under the stated context. This goes beyond a purely local shell utility and introduces credential-handling behavior that is not supported by any declared intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script reads an API key from the environment or a local config file and sends it in the x-bot-api-key header during network requests. While the script logs that it is fetching price and executing a sale, it does not disclose to the user that credentials will be transmitted to a remote service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This external transmission is not just informational; it submits an authenticated sell order to a remote API, creating a direct financial effect outside the local environment. In the context of an agent skill, remote execution of a live trade is materially dangerous because it can cause unauthorized or accidental asset liquidation.

Content

Scanner excerpt · scripts/sell.sh (reported line 54)May include surrounding context.

sh
echo ""
echo "Executing sale..."

RESPONSE=$(curl -s -X POST "$BASE_URL/sell" \
    -H "Content-Type: application/json" \
    -H "x-bot-api-key: $API_KEY" \
    -d "{\"artist_name\": \"$ARTIST\", \"min_slippage_percent\": $SLIPPAGE}")

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script accepts an API key from the environment or interactive input and persists it in plaintext to a local JSON config file. Even though it sets mode 600, long-term storage of a secret for an otherwise unspecified third-party service increases credential exposure risk through local compromise, backups, dotfile syncing, or accidental disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends a user-supplied API key to an external domain to validate it, creating explicit outbound transmission of a credential. In a skill of unknown trustworthiness, this network behavior is security-relevant because it could exfiltrate secrets to a third party or an unexpected endpoint under the guise of validation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This curl command transmits the API key in an HTTP header to an external service. Even over HTTPS, sending a secret to a third-party endpoint during setup is dangerous in an untrusted skill context because it exposes the credential beyond the local machine and could facilitate unauthorized use if the endpoint or operator is not trustworthy.

Content

Scanner excerpt · scripts/setup.sh (reported line 42)May include surrounding context.

sh
echo ""
echo "Validating API key..."

RESPONSE=$(curl -s -X POST "https://k-trendz.com/api/bot/token-price" \
    -H "Content-Type: application/json" \
    -H "x-bot-api-key: $API_KEY" \
    -d '{"artist_name": "RIIZE"}')

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/setup.sh (reported line 65)May include surrounding context.

sh
}
EOF

chmod 600 "$CONFIG_FILE"

echo ""
echo "✓ Configuration saved to $CONFIG_FILE"

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The header comment frames the script as a price-and-signals retrieval utility, but lines L07-L11 perform credential discovery by reading either KTRENDZ_API_KEY or a local config file. That documentation is materially incomplete about sensitive behavior, creating a mild intent/code divergence around secret handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.