Back to skill

Security audit

Trading Universe

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent trading-analysis dashboard, but it needs Review because optional reasoning credentials and trading context can be sent externally with insufficient endpoint and saved-key safeguards.

Install only if you are comfortable with a local trading dashboard that writes runtime data under ~/.trading-universe, polls market/news sources, and can send selected tickets or fundamentals packs to configured reasoning providers or local subscription CLIs. Avoid using Save key for API credentials unless you have verified local file permissions, and do not launch it from an untrusted wrapper or environment that could set REASONING_BASE_URL.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/dashboard.mjs:572
Finding

Saved reasoning-provider API keys may be stored with overly broad filesystem permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/dashboard.mjs:648
Finding

Unrestricted reasoning endpoint override can redirect API credentials and reasoning payloads

Content
View full analysis
ctl.abort(), opts.timeoutMs ?? 90000); try { const r = await fetch(base + "/chat/completions", { method: "POST", headers, body, signal: ctl.signal }); ``` The override is described earlier in the same file: ```js // REASONING_BASE_URL env overrides the base URL (testing). ``` ### Technical Analysis For API-based reasoning providers, the dashboard normally selects a fixed provider endpoint from its internal provider configuration. However, `REASONING_BASE_URL` completely replaces that endpoint without validating its scheme, hostname, port, or relationship to the selected provider. The application still attaches the selected provider’s bearer API key to the request after replacing the destination. It also sends the complete reasoning request body, which can contain a selected trade ticket, market evidence, OHLC data, headlines, economic-calendar information, prior fundamentals results, and trade-derived lessons. Consequently, a process environment controlled by an unsafe launcher, wrapper, service configuration, or another actor able to influence startup variables can redirect both the credential and reasoning data to an arbitrary server. The override is described as a testing facility in source comm ...[truncated 2174 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
Findings (37)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
· invalidation · "scan" · "any valid entries?" · "structure X" · "deep read" | `scripts/ict-levels.mjs` **only** — never web search |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
· invalidation · "scan" · "any valid entries?" · "structure X" · "deep read" | `scripts/ict-levels.mjs` **only** — never web search |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
| **DASHBOARD** | "dashboard" · "open the dashboard" | `scripts/dashboard.mjs` |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/dashboard.md (reported line 83)May include surrounding context.

md
- **Tickets:** All / Valid / Stand-down, instrument search, live stats, best ticket and a separate feed-error box.
- **Structure:** four-timeframe heatmap with continuation scores and board read.
- **Trade log:** Pending/Open/Closed/Unfilled/Auto plus Long/Short/Wins/Losses filters, semantic search, collapsible green Active and amber History sections, asset/RR/pips/date sorting where relevant, R analytics, lessons and CSV export.
- **Alerts:** arbitrary price plus liquidity/FVG/OB edge, CE/mid and zone triggers; current price/latest 1-minute OHLC helpers; re-arm/delete/clear history; chime, toast, desktop notification and flashing title.
- **Automation controls:** Auto scan refreshes the open tab; Auto-track runs headlessly while the dashboard process is alive. Both use the selected 5/10/15/20/30/60-minute cadence. On restart, candle replay catches up fills, TP and SL events.

### Ticket and detail views

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file comments claim the dashboard 'has no AI' and only writes request files for an external agent, but the implementation later directly invokes remote LLM providers and local CLIs to fulfill reviews and fundamentals. This hidden capability changes the trust boundary: sensitive market context, user-entered API keys, and locally stored trading data can be transmitted or processed in ways an operator would not expect from the documented behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The comments and API contract say the dashboard cannot compute fundamentals and only queues a request for an external agent, but the POST handler conditionally self-fulfills by calling fulfillFundamentalsAPI. This is dangerous because users or higher-level agents may rely on the documented separation when deciding what data can be exposed, while the server actually performs networked LLM-driven processing itself.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The verification request flow is documented as an external-agent handoff, yet the server directly fulfills reviews and writes verify-result.json when a provider is configured. That hidden execution path can send ticket details and fresh market evidence to third-party APIs or local CLIs without matching the advertised trust model, undermining reviewability and user consent.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/watcher.mjs (reported line 369)May include surrounding context.

js
function pruneOldAlertState(state) {
  const cutoffMs = Date.now() - ALERT_STATE_MAX_AGE_MS;
  const cutoffSec = Math.floor(cutoffMs / 1000); // lastEqAlert stores Yahoo (seconds) timestamps
  for (const k of Object.keys(state.alerts)) if (state.alerts[k] < cutoffMs) delete state.alerts[k];
  for (const k of Object.keys(state.lastEqAlert)) if (state.lastEqAlert[k] < cutoffSec) delete state.lastEqAlert[k];
}

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/watcher.mjs (reported line 370)May include surrounding context.

js
function pruneOldAlertState(state) {
  const cutoffMs = Date.now() - ALERT_STATE_MAX_AGE_MS;
  const cutoffSec = Math.floor(cutoffMs / 1000); // lastEqAlert stores Yahoo (seconds) timestamps
  for (const k of Object.keys(state.alerts)) if (state.alerts[k] < cutoffMs) delete state.alerts[k];
  for (const k of Object.keys(state.lastEqAlert)) if (state.lastEqAlert[k] < cutoffSec) delete state.lastEqAlert[k];
}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to use shell execution, network search/fetch, and local file/state interactions, but the manifest does not declare an explicit tool scope such as allowed-tools or permissions. That creates an over-privileged integration surface where a host may grant broader capabilities than the skill actually needs, increasing the blast radius if the skill is misrouted, prompt-injected, or modified later.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

md
2. Per watchlist asset: at most ONE asset-specific search, then score with the shared picture + that search.
3. Sort by `Net` descending. One line per asset: `🟢🟢🟢🟢⚪ Gold — Bullish 4/5 · rate-cut bets + safe-haven`.
4. Header `Market leaderboard — <date>`; footer = the mandatory as-of line.
5. **Save the board** so the dashboard can show it: write `{ asOf, context, items:[{ asset, direction, score, reason, factors:[…], flip }] }` to `<TRADE_DATA_DIR or ~/.trading-universe>/fundamentals.json`.

### Dashboard refresh requests (the "Refresh fundamentals" button)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

md
2. Per watchlist asset: at most ONE asset-specific search, then score with the shared picture + that search.
3. Sort by `Net` descending. One line per asset: `🟢🟢🟢🟢⚪ Gold — Bullish 4/5 · rate-cut bets + safe-haven`.
4. Header `Market leaderboard — <date>`; footer = the mandatory as-of line.
5. **Save the board** so the dashboard can show it: write `{ asOf, context, items:[{ asset, direction, score, reason, factors:[...], flip }] }` to `<TRADE_DATA_DIR or ~/.trading-universe>/fundamentals.json`.

### Dashboard refresh requests (the "Refresh fundamentals" button)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The fallback refresh flow tells the agent to inspect fundamentals-request.json and overwrite request state with {"status":"done"}, which mutates local application state. Without a clear warning to the user that the agent will read and modify local files, this can cause unexpected state changes and weakens user awareness around persistence and automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The ticket review fallback reads pending review requests and writes verify-result.json, creating persistent artifacts that affect dashboard behavior. If users are not clearly warned, they may unknowingly trigger file inspection and state mutation beyond a simple chat-based review, which is risky in a tool-enabled environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill authorizes direct use of external reasoning-provider APIs, expanding the trust boundary beyond the local deterministic engine described in the skill metadata. This can cause unintended data exfiltration of trading context or locally derived artifacts to third parties, and may trigger network actions the user did not expect from this skill.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

This is a session-persistence pattern: the skill directs the agent to use ~/.trading-universe/verify-request.json and verify-result.json to carry state across turns. Cross-session persistence increases risk because untrusted local state can survive boundaries between conversations and be reused as if it were trusted workflow input.

Content

Scanner excerpt · references/playbook.md (reported line 105)May include surrounding context.

Dashboard "🔍 Review (reasoning)" button — with a reasoning provider configured in the dashboard (⚙ More → 🧠 Reasoning: NVIDIA NIM / OpenAI / OpenRouter, reasoning-capable models only), the dashboard fulfils the review itself by direct API call: a fresh single-asset engine run, then either the single-call checklist review above, or — in Collaborative Decision Review mode — a 2-round review where three specialists work the same evidence toward the best-supported decision, not against each other (Analyst: build the case to execute · Risk Analyst: surface concerns and refinements · Financial Advisor: check for a higher-expectancy alternative — round 2 re-tests it against the Analyst/Risk Analyst pair's REFINED position and requires a quantified edge, so a replacement is never just "a different ticket" · Judge: rule TAKE / MODIFY / WAIT / REPLACE / PASS with confidence, winner and per-role evidence scores; MODIFY = thesis right but levels change, REPLACE = the Advisor demonstrated a real efficiency gain over the refined original). The card's revised-ticket diff renders as labeled old→new chips, not a flat line of bare values.

Agent fallback (no provider configured): the click writes ~/.trading-universe/verify-request.json ({status:"pending", asset, ticket, nonce}) and you fulfil it. When it is pending (the user mentions the dashboard/a ticket, or at the start of a trading turn), run node ict-levels.mjs <asset>, run the checklist above over out.ohlc, and write ~/.trading-universe/verify-result.json:

text
{ "status":"done", "asset":"XAUUSD", "nonce":"<echo the request nonce>",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The playbook explicitly instructs the agent to read and write persistent files under ~/.trading-universe/ as part of normal operation, which exceeds a purely analytical skill and creates cross-session state. Persistent file writes can be abused to inject or retain untrusted review requests/results, influence later decisions, or clobber existing local data without clear user approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions tell the agent to overwrite local verification files and even emphasize 'Never delete either file — overwrite,' but provide no nearby warning or consent checkpoint. Silent overwrites can destroy prior state, mask tampering history, and let stale or maliciously planted request/result files steer later behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script sends queued messages to Telegram via an external CLI, which is an outbound communication capability not clearly aligned with a supposedly local analysis/tracking skill. Even if intended for user alerts, this creates a data exfiltration path for market data, prompts, or other queued content if the queue is influenced by other components or untrusted inputs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Invoking the external openclaw CLI to send Telegram messages introduces a non-local side effect and expands the trust boundary beyond this skill. If the external tool is misconfigured, compromised, or fed sensitive queue contents, the skill can transmit data off-host in a way users may not expect from the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This dashboard includes substantial LLM orchestration: provider selection, key handling, model fallback, CLI spawning, remote API calls, and prompt construction over trading data. That is broader than a local dashboard's stated purpose and increases attack surface, especially because prompts include fresh market data, fundamentals, and ticket context that may leave the machine or be exposed to external tools.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The code contains direct integration with external endpoints such as OpenAI, OpenRouter, NVIDIA, Yahoo Finance, RSS feeds, and ClawHub. External transmission is expected for these features, but it still represents a real data-exposure risk because prompts and telemetry can include trading tickets, fundamentals context, and user-entered secrets if mishandled.

Content

Scanner excerpt · scripts/dashboard.mjs (reported line 540)May include surrounding context.

js
],
  },
  openai: {
    label: "OpenAI", base: "https://api.openai.com/v1",
    models: ["gpt-5.5", "gpt-5.5-pro", "gpt-5.4", "gpt-5.4-mini", "gpt-5.2"],
  },
  openrouter: {

Unbounded Output

Medium
Category
Output Handling
Confidence
80% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · scripts/dashboard.mjs (reported line 3857)May include surrounding context.

js
// Awareness of auto-track additions. AUTO_SEEN persists which auto-tracked ticket
// ids have already been surfaced (so reloads don't repeat them). On the very first
// diff of a brand-new browser we seed silently, so the historical backlog doesn't
// flood the log/toasts. This path also catches HEADLESS adds (browser was closed)
// on the next reload. Verbosity follows ENGCFG.autoTrack.notify.
var AUTO_SEEN=(function(){try{return JSON.parse(localStorage.getItem('tuAutoSeen'))||{}}catch(e){return {}}})();
var AUTO_BOOTSTRAP=Object.keys(AUTO_SEEN).length===0;

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script reads a local live-trades JSON file from a path influenced by environment variables and mines its contents into 'lessons' and behavioral guidance. In an agent setting, this can expose sensitive historical trading data to downstream model outputs or other consumers without clear minimization or consent boundaries, increasing privacy and prompt-context leakage risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest emphasizes deterministic scans using the bundled engine, a local dashboard, and trade tracking, with fresh web research only for fundamentals. This file instead continuously fetches live market data from Yahoo Finance and generates outbound alert messages via an alert queue for later delivery, which is a materially different operational behavior from the stated local/dashboard-oriented scope.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/dashboard.mjs:102

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/dashboard.mjs:27