Back to skill

Security audit

Crypto Signals Automation

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about building automated crypto trading, but it asks for high-impact exchange credentials and scheduled trading execution without enough containment or secure secret handling.

Install only if you are comfortable reviewing and constraining an automated trading workflow yourself. Use testnet or dry-run first, avoid passing secrets on the command line, lock down any env file before adding credentials, and require explicit human approval before any live dYdX order execution or cron enablement.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rapidapi_fetch.py:23
Finding

RapidAPI Key Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bootstrap_env.py:28
Finding

Sensitive Environment File Created Without Enforced Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises end-to-end automated trading, credential bootstrap, cron execution, TP/SL, cleanup, and notifications, but the analyzed content does not implement those controls and instead appears limited to signal retrieval guidance. This mismatch is dangerous because operators may rely on non-existent safeguards or execution logic, leading to unsafe deployment decisions, mishandled credentials, or unmonitored trading behavior in a high-risk financial context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes operations that inherently require sensitive capabilities—network access, file writes, and likely shell/cron orchestration—but it declares no explicit tool scope or permission boundaries. In an agent setting, this creates an overbroad and ambiguous execution surface where a caller or runtime may grant more access than necessary, which is especially risky because the workflow handles API keys, trading credentials, and automated order execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The checklist explicitly asks operators to collect highly sensitive secrets, including a RapidAPI key, dYdX mnemonic path, and Telegram bot token, but provides no guidance on secure storage, masking, least-privilege handling, or avoiding disclosure in logs and chat. In a trading automation skill, these credentials can enable account takeover, unauthorized trading, data exposure, or abuse of notification infrastructure if mishandled.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
return
    out.write_text(TEMPLATE)
    print(f"Wrote {out}")
    print("Run: chmod 600 .env.crypto-signals")


if __name__ == "__main__":

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/bootstrap_env.py (reported line 36)May include surrounding context.

python
return
    out.write_text(TEMPLATE)
    print(f"Wrote {out}")
    print("Run: chmod 600 .env.crypto-signals")


if __name__ == "__main__":

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code performs an outbound HTTP request to a third-party RapidAPI host and transmits the provided API key in request headers, but there is no docstring, comment, or other in-code disclosure explaining that behavior. For code files, network calls that transmit user or system data should have some visible warning or explanation unless clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.