Back to skill

Security audit

cortex-backtest

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Cortex backtesting helper, but it asks agents to persist new lessons into future instruction files, modify shared workspace registration, and includes privileged setup commands without clear approval gates.

Review before installing. Prefer workspace or tenant-local setup, require explicit approval before any file changes, do not let the agent run sudo automatically, and treat any new experience entries as untrusted until reviewed. Confirm the tool is running only backtests or simulations before using order APIs or strategy examples.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:20
Finding

Unvalidated Observations Can Be Persisted as Instructions for Future Agent Sessions

Content
View full analysis
= 100: Usage-collected experience discovered during actual use and appended after use. Post-use append rule: When a new problem is discovered, append it to the end of the experience document, incrementing from number 100. Deduplication rule: If new system-predefined experience is added, inspect user-collected experience for identical or similar entries. If one exists, delete it directly; its number may be reused. ``` `SKILL.md:258-280` additionally requires persistent modification of shared workspace state: ```markdown ### Step 5: Update the TOOLS.md Registration After configuration is complete, it must be registered in TOOLS.md: ## Cortex Backtesting Engine ### Scenario Mode Current selection: Scenario X ### Installation Location | Item | Path | | CLI tool | /opt/cirt/bin/cortex_cli.py | | Python library | /opt/cirt/lib/cortex/ | ### Configuration Information Fill in the concrete path according to the scenario. ### Usage Fill in the command according to the scenario. ``` The persistence policy is repeated in `references/cortex-experience.md:7-12`: ```markdown Update and maintenance rules: 1. After every use, append newly discovered experience to the end of this document, numbering entries from 100. 2. When new predefined experience is added, inspect user-collected experience for identical or similar entries and remove matching entries. 3. When removing user experience, delete the record directly; its number may later be reused. ``` The document also provides an append template and reiterates that future operational findings should be written into the same ...[truncated 3664 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L003 lists activation phrases such as “策略回测”, “量化策略开发”, “策略验证”, and “Cortex 配置” without clear constraints or exclusion conditions. These phrases are broad enough to overlap with many ordinary requests about strategy development or validation, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description, prompts, and required reply templates are entirely in Chinese, including prescribed user interaction text such as scene-selection prompts and reporting formats. There is no indication that the user may choose another language or that the Chinese-only constraint is required for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill tells the agent to append, deduplicate, and delete entries in the experience document, including user-maintained records, without an explicit consent or preservation policy. In an automated environment, this can destroy audit/history data, overwrite user knowledge, or silently remove records that may be operationally important.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to create directories and write configuration files, including under privileged paths like /opt/cirt/etc/, and even shows sudo cp without an explicit requirement for user confirmation before filesystem modification. In an agent setting, this can lead to unintended system changes, privilege escalation attempts, or modification of shared multi-user configuration if the instructions are followed automatically.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
92% confidence
Finding

Embedding a sudo command in a skill materially increases risk because an autonomous or semi-autonomous agent may attempt privileged execution on the host. In context, this is more dangerous because the skill is a setup guide for a backtesting engine and normalizes modifying /opt system paths, which could affect shared infrastructure or be abused to overwrite trusted configuration.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

建议:使用场景 2 或 3(无需系统权限),或手动创建配置文件。"

3. 如能写入,创建配置文件

sudo cp /opt/cirt/etc/cortex.conf.default /opt/cirt/etc/cortex.conf

4. 更新 TOOLS.md 登记

text

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description says the skill supports 日线回测 only, but the guidance explicitly offers --period values of daily or min and the result template also includes daily/min at L427. Even though minute backtesting is later described as very inefficient, the documentation still presents it as supported behavior, contradicting the manifest's stated scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example strategy uses context.portfolio.total_assets at L688 and L693, but the same document states at L586 and L587 that context.portfolio.total_assets is not supported in Cortex and should be replaced with total_value. This is an active contradiction between the documented intent/example and the stated actual engine behavior, which can mislead users into writing incompatible strategies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents order functions such as order_target_value, order_shares, and a full rebalance example that sells and buys positions, which can affect user assets or system state. Under the markdown-specific warning rule, the description should disclose that these operations can place trades or alter portfolio holdings, but no such warning appears in the trading sections or example.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and all operational guidance are written exclusively in Chinese, and line L003 instructs users to consult this document every time they use the skill. There is no indication that another language is supported or that the user can opt into this locale, which can violate language-choice policy for general-purpose skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file’s headings, explanations, and examples are presented in Chinese, effectively forcing a specific language for users of this reference. The policy allows fixed locale/language only when user choice or a justified regional constraint is explicitly documented, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document states earlier that handle_data is not supported and that Cortex uses time-triggered execution instead of data-push callbacks (L33-L41). But this line says run_daily(..., time='every_bar') is available due to a 'dual-drive' mode, which conflicts with the earlier explicit claim that data-push style execution is not currently supported.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

All instructional content is presented in Chinese, and the file does not indicate that other languages are available or that Chinese is a region-specific requirement. The policy requires flagging language or locale constraints when a specific language is imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents that running the CLI creates output directories and writes multiple files such as index.json, strategy.py copies, CSVs, JSON reports, and logs. Under the markdown-specific warning rule, descriptions should disclose behaviors that affect user data or filesystem state; here the operational side effects are described functionally but not explicitly warned about.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.