Back to skill

Security audit

Tamper-Proof Audit Trails for Trading Bots

Security checks for vulnerabilities and agentic risk

Overview

This non-executing guide is coherent, but it should be reviewed because its examples handle signing keys and sensitive trading audit data in risky ways.

Install only if you want a GreenHelix-focused trading audit guide and are prepared to harden the examples before production use. Do not print or log private signing keys, redact sensitive fields before sending audit events, verify signatures explicitly, secure local buffers with restrictive permissions and encryption, and confirm GreenHelix data handling, retention, and regulatory suitability with compliance counsel.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:183
Finding

Ed25519 Private Signing Key Exposed Through Standard Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:590
Finding

Unrestricted Function Arguments and Exception Data Sent to an External Audit API

Content
View full analysis
dict: resp = self._session.post( f"{self.api_base}/v1", json={"tool": tool, "input": input_data} ) resp.raise_for_status() return resp.json() ``` ### Technical Analysis The generic audit decorator converts every positional and keyword argument into a string whenever the wrapped operation raises an exception. It also records the complete exception message. The resulting payload is passed to `log_event`, which sends it to the configured GreenHelix API. Function arguments can contain API credentials, customer identifiers, account information, proprietary strategy parameters, order details, session tokens, or other regulated data. Exception messages may similarly contain request bodies, file paths, database details, or remote-service responses. The external network operation itself is consistent with the declared remote audit-trail functionality. However, transmitting unrestricted arguments is not necessary to document that an operation failed and violates least-data and data-minimization principl ...[truncated 1805 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:986
Finding

Sensitive Audit Events Buffered in Plaintext with Insufficient Filesystem Protections

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
### EU AI Act (Effective August 2, 2026)

The EU AI Act classifies AI systems that autonomously execute financial transactions as **high-risk** under Annex III, Category 5(b). Article 14 imposes specific obligations on providers and deployers of high-risk AI systems:

- **Automatic logging** (Article 12): The system must automatically record events relevant to identifying risks, including each decision point, the inputs that triggered it, and the output action taken.
- **Tamper detection**: Logs must be designed so that unauthorized modification is detectable. A mutable database row does not satisfy this requirement.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

Step 2: Register Your Bot as an Agent

bash
curl -X POST https://sandbox.greenhelix.net/v1 \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

python
import requests

API_BASE = "https://api.greenhelix.net/v1"
API_KEY = "your-api-key"  # from /v1/register

def execute_tool(tool: str, input_data: dict) -> dict:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 403)May include surrounding context.

python
import requests

API_BASE = "https://api.greenhelix.net/v1"
API_KEY = "your-api-key"  # from /v1/register

def execute_tool(tool: str, input_data: dict) -> dict:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 2412)May include surrounding context.

python
import requests

API_BASE = "https://api.greenhelix.net/v1"
API_KEY = "your-api-key"  # from /v1/register

def execute_tool(tool: str, input_data: dict) -> dict:

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
API_KEY = "your-api-key"  # from /v1/register

def execute_tool(tool: str, input_data: dict) -> dict:
    response = requests.post(
        f"{API_BASE}/v1",
        headers={
            "Authorization": f"Bearer {API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 674)May include surrounding context.

md
PAYLOAD='{"order_id":"ORD-001","symbol":"ETH/USD","side":"buy","quantity":"10.5","price":"1842.30","order_type":"limit","timestamp_us":1717200000000000}'
SIGNATURE=$(echo -n "$PAYLOAD" | openssl pkeyutl -sign -inkey ed25519_private.pem | base64 -w0)

curl -X POST https://sandbox.greenhelix.net/v1 \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 734)May include surrounding context.

bash
# Build chain
curl -X POST https://sandbox.greenhelix.net/v1 \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide explicitly claims the compliance validator checks Ed25519 signatures, but the implementation only checks event presence, timestamp types, and chain verification. This creates a false assurance gap: operators may believe integrity/authenticity is being validated when forged or malformed events could pass the documented validation flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The BaFin formatter hard-codes German field names and explicitly states that BaFin reports require German-language summary sections. This imposes a specific language/locale in the skill content without presenting a user choice or opt-in, which matches the natural-language language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring describes sec_worm_verification as running verification and logging the result, implying a normal compliance-verification record. The code instead emits a trade.system_error event with error_type set to compliance_verification, which contradicts the event's documented purpose elsewhere as an unhandled exception/system error record.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.