Back to skill

Security audit

Trade Singal

Security checks for vulnerabilities and agentic risk

Overview

This skill needs review because it provides broad trading recommendations through a remote API and its query script has a command-execution flaw.

Review carefully before installing. Do not treat outputs as personalized investment advice or as the sole basis for trades. Avoid sending sensitive portfolio, account, or proprietary strategy details. The bundled search script should be fixed before use because a crafted query can run local commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search.sh:11
Finding

Arbitrary Command Execution Through Python Code Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/search.sh, line 11
Vulnerability Type: Python source-code injection caused by unsafe interpolation of user-controlled input
Risk Level: High

Vulnerable Code

bash
ENCODED=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''$QUERY'''))")

Technical Analysis

The script reads its first positional argument into QUERY and directly interpolates that value into the source code passed to python3 -c. Triple-quoting the value does not make it safe. A crafted query can terminate the Python string literal and append arbitrary Python statements.

For example, a query with the following structure can escape the intended string and invoke an operating-system command:

text
x'''); __import__('os').system('id'); #

The resulting Python program executes os.system('id'). Shell quoting does not prevent this issue because the injection occurs in the dynamically constructed Python source after the shell expands $QUERY.

Attack Path

  1. An attacker supplies a malicious financial query or induces an agent to process one.
  2. The agent invokes scripts/search.sh and passes the crafted content as its first argument.
  3. The script stores the content in QUERY.
  4. Line 11 interpolates QUERY into the program supplied to python3 -c.
  5. The malicious content closes the intended triple-quoted string and appends Python statements.
  6. Python executes the injected statements with the permissions of the Skill runner before the API request is made.

Impact Assessment

Successful exploitation provides arbitrary command execution with the operating-system privileges of the process running the Skill. An attacker could consequently:

  • Read files accessible to the Skill runner, including workspace data and available credentials.
  • Modify or delete accessible files.
  • Launch local programs and network clients.
  • Exfiltrate accessible information to external systems.
  • Establish addition ...[truncated 256 chars]
Remediation
View remediation

Remediation Suggestions

Never place untrusted input inside dynamically generated source code. Pass the query to Python as a separate argument:

bash
ENCODED=$(python3 -c \
  'import sys, urllib.parse; print(urllib.parse.quote(sys.argv[1]))' \
  "$QUERY")

A simpler and preferable solution is to let curl perform URL encoding, eliminating the dynamic Python execution entirely:

bash
curl --silent --show-error --fail-with-body \
  --location \
  --get \
  --data-urlencode "query=$QUERY" \
  --connect-timeout 10 \
  --max-time 30 \
  "https://terminal-x.ai/api/lite-search"

Additional hardening measures should include:

  • Keep every expansion of QUERY properly quoted.
  • Add automated tests containing quotes, triple quotes, semicolons, newlines, shell metacharacters, and the demonstrated payload.
  • Use explicit connection and overall request timeouts.
  • Use --fail-with-body so HTTP failures produce a nonzero exit status.
  • Run the Skill under a least-privileged account with minimal filesystem and credential access to limit the consequences of future defects.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to provide institution-grade trade signals and executable Buy/Sell/Hold recommendations, but the file only documents a generic search-style interface and examples, not any verifiable decision engine, controls, or methodology. This mismatch can mislead agents and users into trusting high-stakes financial outputs as authoritative when the underlying behavior may just be opaque remote retrieval or generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly markets actionable Buy/Sell/Hold recommendations and executable investment intelligence without any warning that outputs may be incomplete, probabilistic, or unsuitable as sole investment advice. In the financial context, this omission materially increases the risk of user harm, loss, and overreliance on automated recommendations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples present concrete pre-earnings trade actions, exit ranges, stop losses, and short time horizons in a way that encourages immediate trading behavior, yet they omit any warning about volatility, suitability, or irreversible financial loss. That combination is especially dangerous because it operationalizes risky decisions while signaling unwarranted confidence.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises executable shell usage and remote API access via ./scripts/search.sh and https://terminal-x.ai/api, but it does not declare any tool scope such as allowed tools or permissions. In an agent ecosystem, missing scope declarations weakens policy enforcement and can let the skill be invoked with broader shell/network capability than reviewers or orchestrators expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance is extremely broad, covering nearly any finance or investment question, which can cause the agent to over-trigger this skill for general discussion rather than narrowly scoped use cases. Overbroad routing increases exposure to remote content, shell/network actions, and unvetted financial recommendations in situations where the user did not explicitly request them.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The automatic-use section instructs the agent to invoke the skill for a wide range of ordinary finance prompts without meaningful constraints. In a sensitive domain like trading, broad autonomous invocation makes it more likely the agent will produce consequential recommendations or fetch external content without explicit consent or risk disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends the full user-provided query to an external service over the network without any disclosure, consent step, or data minimization. In a trading skill, queries may contain sensitive investment intent, portfolio details, watchlists, or proprietary strategy information, so silent transmission to a third party creates a real privacy and data-handling risk even though HTTPS is used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.