Back to skill

Security audit

Trade Signal

Security checks for vulnerabilities and agentic risk

Overview

This finance skill is a thin remote trading-signal API wrapper, but a crafted query can trigger local command execution and the skill is broadly scoped for high-stakes trading advice.

Review before installing. Treat outputs as unverified informational signals, not personalized financial advice. Do not use this version with sensitive portfolio details or untrusted query text unless the query-encoding bug is fixed and the skill is given explicit, narrow permission boundaries for shell and network use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search.sh:11
Finding

Arbitrary Command Execution via Python Code Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/search.sh, line 11
Vulnerability Type: User-controlled input interpolated into executable Python source code
Risk Level: High

Vulnerable Code

bash
ENCODED=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''$QUERY'''))")

Technical Analysis

The QUERY variable is controlled by the first command-line argument and is inserted directly into a Python program passed to python3 -c. Although the value is enclosed in triple quotes, an attacker can include a matching ''' sequence to terminate the Python string and append arbitrary Python statements.

The shell quoting around the -c argument does not make this safe because variable expansion occurs before Python parses the generated program. Consequently, the query is treated as executable Python syntax rather than strictly as data.

For example, a query shaped like the following can terminate the intended string and invoke an operating-system command:

text
x''')); __import__('os').system('id'); #

The exact payload may be adapted to the target environment. The underlying issue permits arbitrary Python execution and, through modules such as os or subprocess, arbitrary local command execution.

Attack Path

  1. The attacker causes the Skill to process a crafted market-search query containing Python syntax.
  2. scripts/search.sh assigns that content to QUERY.
  3. Line 11 expands QUERY into the source text supplied to python3 -c.
  4. The crafted triple-quote sequence closes the intended Python string.
  5. Python parses and executes the attacker's appended statements.
  6. The injected Python can invoke local commands, read accessible files, alter data, or initiate network connections under the identity running the Skill.

Impact Assessment

Successful exploitation provides arbitrary code execution with the privileges of the user or Agent process invoking the s ...[truncated 446 chars]

Remediation
View remediation

Remediation Suggestions

Pass the query as a separate argument so Python receives it as data rather than generated source code:

bash
ENCODED=$(python3 -c 'import sys, urllib.parse; print(urllib.parse.quote(sys.argv[1]))' "$QUERY")

Additional hardening measures:

  1. Retain the quoted "$QUERY" argument to prevent shell word splitting and pathname expansion.
  2. Consider enforcing a reasonable maximum query length to limit resource abuse.
  3. Use curl --fail-with-body --show-error --location so HTTP failures are handled explicitly.
  4. Add regression tests containing triple quotes, newlines, semicolons, shell metacharacters, and Python expressions, and verify that they are only URL-encoded.
  5. Run the Skill with least privilege and without unnecessary access to credentials or sensitive local files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims sophisticated trade-signal generation, technical analysis, and actionable investment recommendations, but the described implementation appears to be generic query forwarding to a remote service with no visible local validation, analysis logic, or safeguards. This mismatch is dangerous because users and orchestrators may trust the skill as if it performs verifiable financial reasoning, when in reality it may simply proxy opaque remote outputs and trigger high-risk decisions based on unverified external content.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises executable shell usage (./scripts/search.sh) and remote API access but declares no permissions or allowed-tools scope. That weakens least-privilege controls and makes it harder for the host agent to constrain what the skill may execute or access if installed. In this context, a finance skill handling broad user prompts should be explicit about shell and network requirements because silent capability assumptions increase the attack surface.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation scope is very broad, covering many common finance and investment questions, which can cause the skill to trigger in situations where the user did not explicitly request external trade advice. In a high-stakes financial context, overbroad invocation increases the chance of unintended data sharing to a third-party API and inappropriate injection of actionable trading recommendations into otherwise general conversations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill prominently offers actionable Buy/Sell/Hold recommendations, options strategies, stop losses, and price targets without any visible financial-risk warning, suitability notice, or limitation on reliance. In a trading context, omission of such warnings is dangerous because users may treat the output as personalized, trustworthy investment advice and make irreversible financial decisions based on opaque model-generated signals.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The automatic invocation examples use broad, everyday prompts like 'Should I buy NVDA?' and 'What's your call on AAPL?' without constraints or counterexamples, encouraging aggressive auto-routing. That is risky because it normalizes sending routine user finance queries to an external recommendation engine and may over-trust a third-party service for personalized or high-impact trading guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the user-supplied query to a remote third-party endpoint with curl, but gives no user-facing disclosure or consent prompt that their input will leave the local environment. This is a genuine privacy/security issue because user queries in a trading skill may contain sensitive investment intentions, portfolio context, or proprietary research terms, and silent exfiltration to an external service can violate user expectations or policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.