Back to skill

Security audit

Copy Trading Infrastructure: Protocol-Agnostic Copy Trading with Verified Leader Performance

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executing educational guide, but it gives production-adaptable financial automation examples with weak verification and automatic trade or escrow actions that users should review carefully.

Review this carefully before using it beyond a sandbox. Treat the code as architecture notes, not production-ready trading or escrow software; require paper trading first, authenticated webhooks, real Ed25519 verification, replay protection, server-side escrow enforcement, manual approval thresholds, and loss limits before connecting exchange credentials or moving funds.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:748
Finding

Unauthenticated Webhook Signals Can Trigger Financial Trades

Content
View full analysis
Optional[dict]: """Process an incoming trade signal from a leader.""" leader_id = signal.get("leader_id") sub = self._subscriptions.get(leader_id) if not sub or not sub.active: return None symbol = signal.get("symbol") # Check symbol whitelist if sub.allowed_symbols and symbol not in sub.allowed_symbols: return {"status": "skipped", "reason": "symbol_not_allowed"} # Check drawdown limit if sub.cumulative_pnl < 0 and abs(sub.cumulative_pnl) >= sub.max_drawdown_pct: sub.active = False return {"status": "stopped", "reason": "max_drawdown_reached"} # Check total allocation to this leader current_allocation = sum( pos.get("allocated_usd", 0) for pos in sub.positions.values() ) max_allocation_usd = self.portfolio_value * (sub.max_allocation_pct / 100) if current_allocation >= max_allocation_usd: return {"status": "skipped", "reason": "max_allocation_reached"} # Calculate position size leader_size_pct = float(signal.get("size_pct", 0)) capped_size_pct = min(leader_size_pct, sub.max_position_size_pct) position_usd = self.portfolio_value * (capped_size_pct / 100) # Ensure we do not exceed remaining allocation remaining = max_allocation_usd - current_allocation position_usd = min(position_usd, remaining) if position_usd < 10: # Minimum ...[truncated 4445 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:690
Finding

Claim-Chain Verification Accepts Fabricated Signatures and Hashes

Content
View full analysis
bool: """Verify the integrity of a leader's performance claim chain.""" chain = claims.get("chains", []) if not chain: return False # Verify each link is signed and the chain is unbroken for i, link in enumerate(chain): if "signature" not in link: return False if i > 0 and link.get("previous_hash") != chain[i - 1].get("hash"): return False return True ``` ### Technical Analysis The method does not perform the cryptographic operations implied by its name and documentation. It only checks that each link contains a field named `signature` and that one attacker-controlled string equals another attacker-controlled string. It does not: - Decode and verify an Ed25519 signature. - Obtain an authenticated public key for the claimed leader. - Canonicalize the signed payload. - Recalculate each claim's hash from its contents. - Validate the first link against a trusted root or anchor. - Bind the chain to the requested leader. - Validate timestamps, ordering, claim types, or duplicate entries. Consequently, any non-empty chain containing arbitrary `signature` values and internally consistent fake `hash` and `previous_hash` strings is accepted as verified. ### Attack Path 1. A malicious leader, compromised API, intercepted test environment, or mocked response supplies a fabricated `chains` array. 2. Each fabricated entry contains any value in its `signature` field. 3. The attacker assigns an arbitrary `hash` to each entry and copies it into the following entry's `previous_hash`. 4. The method observes that every signature field exists and that the attacker-selected strings match. 5. `_verify_claim_chain()` returns `True`. 6. `evaluate_leader()` reports the fabr ...[truncated 825 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:1507
Finding

Escrow Release Logic Does Not Bind Payouts to Immutable Escrow Terms

Content
View full analysis
dict: """Evaluate whether a leader met performance criteria for escrow release.""" # Fetch the leader's verified metrics for the evaluation period reputation = self._execute("get_agent_reputation", { "agent_id": leader_id, }) metrics = reputation.get("metrics", {}) sharpe = float(metrics.get("sharpe_ratio", "0")) drawdown = float(metrics.get("max_drawdown_pct", "100")) win_rate = float(metrics.get("win_rate_pct", "0")) total_trades = int(metrics.get("total_trades", "0")) # Check against criteria criteria_met = { "min_sharpe": sharpe >= 1.0, "max_drawdown": drawdown <= 20.0, "min_win_rate": win_rate >= 45.0, "min_trades": total_trades >= 10, } all_met = all(criteria_met.values()) if all_met: # Release escrow to the leader release = self._execute("release_escrow", { "escrow_id": escrow_id, "release_to": leader_id, "reason": "performance_criteria_met", "evidence": { "sharpe": str(sharpe), "max_drawdown_pct": str(drawdown), "win_rate_pct": str(win_rate), "total_trades": total_trades, }, }) return {"status": "released", "release": release, "criteria": criteria_met} else: # Refund escrow to the follower refund = self._execute("release_escrow", { "escrow_id": escrow_id, "release_to": self.agent_id, "reason": "performance_criteria_not_met", "evidence": { "sharpe": str(sharpe), "max_drawdown_pct": str(drawdown), "win_rat ...[truncated 3088 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide contains detailed automation and execution examples for copy trading but does not prominently warn that adapting them outside the sandbox can trigger real-money trading and substantial losses. In a financial automation context, omission of a strong operational-risk warning increases the chance that users deploy examples directly against live exchanges without adequate safeguards.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The skill is explicitly about automating leader-follower trade replication, escrow release, and performance-based actions, which are forms of autonomous decision-making in a high-risk financial domain. Even with educational framing, the surrounding content includes concrete code paths for broadcasting signals, executing follower trades, and automatically releasing escrow based on computed criteria, so the operational context makes autonomy materially risky if reused in production.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
> - `AGENT_SIGNING_KEY`: Cryptographic signing key for agent identity (Ed25519 key pair for request signing)


Copy trading is the fastest-growing segment of automated trading, projected to reach $4.2 billion by 2027 according to Allied Market Research. But the current generation of platforms -- eToro, Bybit Copy, NAGA, ZuluTrade -- share a fundamental trust problem that limits their growth and exposes followers to unnecessary risk. Leader performance is self-reported or platform-curated with opaque methodology. Followers have no recourse when leaders lose money beyond closing the copy relationship after the damage is done. Platforms take 20-30% of performance fees while adding no verification, no escrow protection, and no cryptographic proof that stated returns actually occurred. The result is an ecosystem where the most profitable strategy for a leader is not to trade well, but to attract followers, collect fees, and let survivorship bias do the marketing. This guide builds something different: protocol-agnostic copy trading infrastructure where leader performance is cryptographically verified through Ed25519-signed trade records, follower allocations are risk-managed through configurable models, and revenue sharing flows through escrow that releases only when performance criteria are met. The trust layer is GreenHelix. Leaders register as service providers on the marketplace. Followers discover and evaluate them using verified metrics. Performance escrow protects follower capital. Revenue splits are enforced by smart contracts, not gentleman's agreements. The entire system is exchange-agnostic -- the same infrastructure works whether your leaders trade on Binance, Coinbase, Interactive Brokers, or a DEX.
1. [Copy Trading Architecture](#chapter-1-copy-trading-architecture)
2. [CopyTradingLeader Class](#chapter-2-copytradingleader-class)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

This repeated autonomous-trading framing is not harmful as prose alone, but in context it promotes end-to-end automated financial execution backed by code examples that can be adapted directly. In trading systems, insufficiently constrained autonomy can amplify losses, execute on bad or spoofed signals, and release funds based on incomplete verification logic.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
# Copy Trading Infrastructure: Protocol-Agnostic Copy Trading with Verified Leader Performance

Copy trading is the fastest-growing segment of automated trading, projected to reach $4.2 billion by 2027 according to Allied Market Research. But the current generation of platforms -- eToro, Bybit Copy, NAGA, ZuluTrade -- share a fundamental trust problem that limits their growth and exposes followers to unnecessary risk. Leader performance is self-reported or platform-curated with opaque methodology. Followers have no recourse when leaders lose money beyond closing the copy relationship after the damage is done. Platforms take 20-30% of performance fees while adding no verification, no escrow protection, and no cryptographic proof that stated returns actually occurred. The result is an ecosystem where the most profitable strategy for a leader is not to trade well, but to attract followers, collect fees, and let survivorship bias do the marketing. This guide builds something different: protocol-agnostic copy trading infrastructure where leader performance is cryptographically verified through Ed25519-signed trade records, follower allocations are risk-managed through configurable models, and revenue sharing flows through escrow that releases only when performance criteria are met. The trust layer is GreenHelix. Leaders register as service providers on the marketplace. Followers discover and evaluate them using verified metrics. Performance escrow protects follower capital. Revenue splits are enforced by smart contracts, not gentleman's agreements. The entire system is exchange-agnostic -- the same infrastructure works whether your leaders trade on Binance, Coinbase, Interactive Brokers, or a DEX.

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

bash
# Register the leader agent
curl -X POST https://sandbox.greenhelix.net/v1 \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

md
agent_id: str,
        private_key_b64: str,
    ):
        self.api_base = "https://api.greenhelix.net/v1"
        self.api_key = api_key
        self.agent_id = agent_id
        self._private_key = Ed25519PrivateKey.from_private_bytes(

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 626)May include surrounding context.

md
agent_id: str,
        private_key_b64: str,
    ):
        self.api_base = "https://api.greenhelix.net/v1"
        self.api_key = api_key
        self.agent_id = agent_id
        self._private_key = Ed25519PrivateKey.from_private_bytes(

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1248)May include surrounding context.

md
agent_id: str,
        private_key_b64: str,
    ):
        self.api_base = "https://api.greenhelix.net/v1"
        self.api_key = api_key
        self.agent_id = agent_id
        self._private_key = Ed25519PrivateKey.from_private_bytes(

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1796)May include surrounding context.

md
agent_id: str,
        private_key_b64: str,
    ):
        self.api_base = "https://api.greenhelix.net/v1"
        self.api_key = api_key
        self.agent_id = agent_id
        self._private_key = Ed25519PrivateKey.from_private_bytes(

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide asserts that followers can cryptographically verify leader performance, but the provided _verify_claim_chain only checks that a signature field exists and that hashes link together; it never validates Ed25519 signatures against the leader's public key or recomputes hashes over canonicalized payloads. This creates a false sense of trust and allows forged or tampered claim chains to be accepted as 'verified,' undermining the core security model of the copy-trading system.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest describes copy-trading infrastructure with verified performance, follower allocation, slippage, escrow, and revenue sharing. The section at L1752-L1775 introduces tax reporting workflows via get_events, which is a separate accounting/compliance capability not declared in the manifest's stated scope. This is not required to explain core copy-trading infrastructure behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.