Back to skill

Security audit

Korea Flow — Orion

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Korea-focused crypto signal prompt, but it asks the agent to produce live-looking financial market readings without defining reliable data sources, timestamps, or verification steps.

Review this carefully before installing if you might act on the market signals. Treat any free snapshot as unverified unless the agent independently fetches and cites current exchange and FX data, and require confirmation before using any signal in a swap or automated trading workflow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:7
Finding

Unsupported Generation of Live-Looking Financial Market Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 7–19
Vulnerability Type: Unsupported financial data generation
Risk Level: Medium

Vulnerable Code

markdown
## What You Get (Free)

Ask: "Korea flow?" or "kimchi premium?" or "Upbit BTC status?"

The agent will return:
- Kimchi premium direction (positive / negative / neutral)
- Whether Korean volume is surging or flat
- One-line market read

Example output:

Kimchi Premium: +1.8% (elevated) Upbit BTC volume: surging (+34% vs 24h avg) Read: Korean retail buying ahead of Western session

text

Technical Analysis

The skill instructs the agent to return current-looking cryptocurrency exchange metrics and market analysis, but the project contains no implementation, API integration, data source, timestamp validation, or retrieval procedure for obtaining these values.

Consequently, an agent may infer, guess, or fabricate the kimchi premium, Upbit trading-volume changes, and associated market interpretation. The example resembles a live market report and does not explicitly state that its values are fictional placeholders. This creates a risk that generated values will be presented as verified facts.

This issue is classified as an insecure skill practice because the skill requests actionable financial information without defining the data integrity, provenance, availability, or freshness controls required to produce it reliably.

Attack Path

  1. A user invokes the skill with a prompt such as Korea flow?, kimchi premium?, or Upbit BTC status?.
  2. The agent attempts to satisfy the documented output requirements.
  3. No verified market-data interface is available in the skill package.
  4. The agent generates or estimates plausible-looking premium and volume figures.
  5. The output is presented without mandatory source, timestamp, or uncertainty information.
  6. A user or automated trading workflow treats the unsupported report as current market intelligence and makes a finan ...[truncated 785 chars]
Remediation
View remediation

Remediation Suggestions

  1. Integrate a documented and authenticated market-data provider for Upbit, Bithumb, and the relevant comparison exchanges.
  2. Define an explicit calculation method for the kimchi premium, including trading pairs, currency-conversion sources, fees, and time synchronization.
  3. Include the source exchange, retrieval timestamp, comparison window, and data freshness in every response.
  4. Refuse to provide current metrics when source data is unavailable, stale, incomplete, or inconsistent.
  5. Clearly label all sample values as fictional examples that must never be presented as live market data.
  6. Separate factual measurements from inferred market commentary and disclose uncertainty for interpretations.
  7. Validate volume comparisons against a precisely defined baseline, such as a rolling 24-hour average calculated from verified observations.
  8. Require user confirmation before passing any resulting signal into a swap or other transaction workflow.
  9. Add tests covering unavailable APIs, stale timestamps, malformed exchange responses, inconsistent currency conversions, and extreme or implausible values.
  10. State that the output is informational and not a guarantee or substitute for independent financial verification.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are very broad and conversational, which increases the chance the skill activates during unrelated crypto discussions and injects promotional or trading-oriented output without clear user intent. In this context, the skill is also designed to funnel users into a paid ACP service, so over-broad activation can become unsolicited commercial steering and influence financial decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The skill is explicitly framed around Korean market signals and uses Korea-specific terminology, but it does not state that this regional focus is optional, user-selected, or limited to users seeking Korea-specific analysis. Under the policy, locale-specific constraints should be clearly documented and justified or offered as an opt-in choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.