Back to skill

Security audit

Unbeatable Condor Strategy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a trading-signal tool that openly downloads market data, but it gives direct options-trading instructions with inadequate safety context.

Review carefully before installing. Run it only in an isolated Python environment, treat results as informational rather than financial advice, and do not let an agent place trades or allocate capital based only on this output.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–22
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

markdown
Before running the script, ensure the following Python libraries are installed:
```bash
pip install pandas numpy lightgbm yfinance
text

### Technical Analysis

The documented installation command retrieves mutable latest versions of four third-party packages and their transitive dependencies. No version constraints, cryptographic hashes, lockfile, or trusted package-index configuration are provided.

Consequently, the reviewed source does not uniquely determine the code that users will install and execute. A malicious or compromised package release, transitive dependency, or configured Python package index could supply attacker-controlled code. Python packages may execute code during installation through build backends, and their modules execute code when imported by `condor_signals.py`.

This finding does not establish that the named packages are currently malicious. It identifies an avoidable supply-chain exposure caused by installing unverified, unpinned artifacts.

### Attack Path

1. An attacker compromises a named package, one of its transitive dependencies, or a package index used by the victim.
2. The attacker publishes or serves an artifact containing malicious installation or import-time code.
3. A user follows the instructions and runs:
   ```bash
   pip install pandas numpy lightgbm yfinance
  1. Because versions and hashes are not constrained, pip resolves and downloads the attacker-controlled artifact.
  2. Malicious code executes during package build or installation, or when condor_signals.py imports the installed module.
  3. The payload operates with the permissions and environment access of the user running the installation or script.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the affected user ...[truncated 538 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define reviewed, exact dependency versions in a requirements or lock file rather than installing unconstrained latest releases.
  2. Generate and verify cryptographic hashes for every direct and transitive artifact. For example, use a fully resolved requirements file with:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Commit the lock file to source control and update dependencies through a controlled review process.
  4. Document and enforce an approved HTTPS package index; disable untrusted extra indexes to reduce dependency-confusion exposure.
  5. Install dependencies in a dedicated virtual environment or isolated container under a non-privileged account. Do not run pip as root or with administrative privileges.
  6. Scan locked dependencies for known vulnerabilities and review dependency updates before adoption.
  7. Consider using an internal artifact repository that stores vetted packages and preserves approved versions.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill’s declared purpose is a simple threshold check, but the instructions direct the agent to install packages, fetch live external market data, train an ML model on the fly, and produce concrete trading actions and strike recommendations. This hidden expansion of capability increases attack surface, bypasses user expectations about what the skill will do, and can trigger unreviewed network access and high-risk financial advice under a misleading description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The stated purpose is a daily check on user-provided stocks for a 4% volatility-threshold condor signal. Instead of only evaluating the given symbols, the code expands scope by downloading 8 years of data for a built-in training set and retraining predictive models on every invocation, which is a materially broader behavior than the manifest describes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill emits direct trading instructions like 'SELL OTM PUT' and 'SELL OTM CALL' without any warning about financial risk, model uncertainty, suitability, or that the output is not financial advice. In the context of an agent skill that may be used operationally, this increases the chance of harmful real-world actions based on unqualified automated recommendations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The inline comment says these are 'Reference Stocks that the AI was optimized on,' implying a previously optimized or fixed model basis. The implementation actually constructs a fresh training dataset from those symbols and retrains models during execution, so the comment misstates how the code behaves.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.