Back to skill

Security audit

Crypto Trading Agents

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed crypto-trading helper, but it asks users to run mutable remote installation code and unpinned trading dependencies before handling exchange keys and trade execution.

Review before installing. Use a fresh virtual environment or container, install uv through a trusted pinned method instead of running the provided curl | sh path, pin the external repository and Python dependencies, start with BINANCE_TESTNET=true, and use Binance keys that cannot withdraw funds. Enable WeChat notifications only if you are comfortable sending trading and account activity to that webhook provider.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/setup.sh:15
Finding

Mutable Remote Installer Is Piped Directly Into a Shell

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:35
Finding

Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

在项目根目录创建 .env 文件:

bash
cp .env.example .env

编辑 .env,填入:

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Using 'curl ... | sh' is especially dangerous because it combines network retrieval and shell execution in one step without validation. In the context of a crypto-trading agent, this is more sensitive because users may run the installer on systems that later hold exchange API keys or trading infrastructure, increasing the consequences of compromise.

Content

Scanner excerpt · scripts/setup.sh (reported line 15)May include surrounding context.

sh
# 检测 uv 是否安装
if ! command -v uv &> /dev/null; then
    echo "📦 安装 uv..."
    curl -LsSf https://astral.sh/uv/install.sh | sh
    source "$HOME/.local/bin/env" 2>/dev/null || true
    export PATH="$HOME/.local/bin:$PATH"
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 51)May include surrounding context.

sh
echo ""
echo "下一步:"
echo "1. 复制环境配置文件:"
echo "   cp .env.example .env"
echo ""
echo "2. 编辑 .env,填入你的 API Key:"
echo "   nano .env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 54)May include surrounding context.

sh
echo ""
echo "下一步:"
echo "1. 复制环境配置文件:"
echo "   cp .env.example .env"
echo ""
echo "2. 编辑 .env,填入你的 API Key:"
echo "   nano .env"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents shell commands and operational workflows but does not declare any explicit tool scope such as allowed tools or permissions. In an agent setting, this increases the chance that a host or user grants broader shell access than intended, enabling cloning repos, installing packages, or running trading-related commands without clear confinement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description uses Chinese-only text to describe the skill's purpose and scope. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises automatic WeChat notifications for trading signals, executions, errors, and account status without clearly warning that sensitive financial and account activity data may be sent to a third-party webhook endpoint. This can lead to unintended disclosure of trading behavior, positions, balances, and operational metadata outside the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing comments and echo output are written in Chinese throughout the script, including setup instructions and next steps. This imposes a specific language on users without opt-in or justification that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script header comments and the user-facing echo message are in Chinese, which imposes a specific language on users. The policy allows locale constraints only when users are given a choice or the restriction is clearly justified, neither of which appears here.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The script downloads and executes a remote installer from the network at runtime, which creates a supply-chain and remote code execution risk. If the remote host, TLS trust chain, or delivery path is compromised, arbitrary code will run on the user's machine during setup.

Content

Scanner excerpt · scripts/setup.sh (reported line 15)May include surrounding context.

sh
# 检测 uv 是否安装
if ! command -v uv &> /dev/null; then
    echo "📦 安装 uv..."
    curl -LsSf https://astral.sh/uv/install.sh | sh
    source "$HOME/.local/bin/env" 2>/dev/null || true
    export PATH="$HOME/.local/bin:$PATH"
fi

Static analysis

No suspicious patterns detected.