Back to skill

Security audit

Agent-Powered P2P Energy Trading for Prosumer Microgrids

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable educational guide, but it teaches financial escrow and physical energy-asset control workflows without enough safety, authorization, or production-use guardrails.

Read this as a high-impact integration guide, not a drop-in production recipe. Use sandbox credentials first; do not connect production payment keys, real smart-meter data, or physical battery controllers until you have explicit owner consent, operator approval workflows, device-scoped authorization, transaction limits, idempotency, rollback/reconciliation, and local safety interlocks.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

other

Warning
Location
SKILL.md:174
Finding

Excessive Disclosure of Household and Critical-Grid Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:574
Finding

Non-Transactional Escrow and SLA Workflow Is Described as Atomic

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:827
Finding

Safety-Critical Battery Dispatch Lacks Demonstrated Authorization and Operational Guardrails

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The escrow and settlement examples show how to create escrows, execute trades, and release funds, but they do not prominently warn that using production endpoints or real API keys could lock, transfer, or dispute actual money. Because the skill references live credentials like GREENHELIX_API_KEY and STRIPE_API_KEY, a user may underestimate the financial consequences of copying the sample flow outside the sandbox.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide provides concrete examples for autonomous battery discharge, load shedding, and emergency island-mode actions against physical energy assets without a prominent safety warning, human-approval gate, or simulation-only constraint. In a real deployment, readers could adapt these patterns to trigger unsafe control actions that affect power availability, equipment protection, or essential services, making the omission materially dangerous even though the file is presented as educational.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.