Back to skill

Security audit

YH8.5 双引擎信号系统

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a local trading-signal/backtest package, but its strategy configuration can emit signals for assets the documentation says are disabled or outside the stated crypto scope.

Review and correct the playbook assignments before relying on this skill, especially disabled assets and non-crypto symbols. Treat outputs as research signals, not automatic trading authority, and avoid connecting it to live execution until the asset universe, risk controls, and local state-writing behavior are explicit and tested.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undisclosed persistent local JSON loading/saving and performance/reflection logging introduce real side effects beyond the declared signal-generation role. In an agent setting, hidden statefulness and file persistence can leak sensitive trading data, create tamperable local state, and enable unexpected modifications to future behavior through local config overrides.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed persistent local JSON loading/saving and performance/reflection logging introduce real side effects beyond the declared signal-generation role. In an agent setting, hidden statefulness and file persistence can leak sensitive trading data, create tamperable local state, and enable unexpected modifications to future behavior through local config overrides.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Undisclosed persistent local JSON loading/saving and performance/reflection logging introduce real side effects beyond the declared signal-generation role. In an agent setting, hidden statefulness and file persistence can leak sensitive trading data, create tamperable local state, and enable unexpected modifications to future behavior through local config overrides.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The strategy documentation states DOGE/FIL are disabled, but DOGE/USDT is still actively assigned to the bb20_range strategy. In a trading-signal skill, this kind of documentation/configuration drift is dangerous because operators may believe a known-bad asset is blocked while the system continues emitting live signals for it, directly undermining risk controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The entire skill description is written in Chinese, and there is no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises executable usage and references components that may write local files, but it declares no explicit tool scope or permissions boundary. In an agent environment, missing scope declarations can allow broader-than-expected file write behavior, making it easier for the skill to modify local state, configs, or outputs without clear operator consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says this skill is a '双引擎量化信号系统' for generating perpetual futures trading signals using ST(10,3) trend and BB20(20,2) mean-reversion engines with playbook routing. This file instead documents and implements a separate market-regime analysis component based on ADX, ATR percentile, EMA453, and optional BB width, producing regime labels and adaptation parameters rather than the claimed dual-engine trading signals.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains its primary natural-language documentation in Chinese, including the module docstring and many explanatory comments. Under the stated policy, forcing a specific language without user choice or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation for get_global_regime says more than 50% CHOPPY/SQUEEZE yields GLOBAL_CHOPPY and more than 50% TREND_* yields GLOBAL_TREND. The actual code applies different criteria: ranging >= 40% and trending >= 65%, which materially changes behavior and directly contradicts the stated logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The docstring and user-facing print messages are written only in Chinese, so the skill effectively enforces a specific language for its interface. Under the policy, locale restrictions should either be optional for the user or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON manifest contains natural-language descriptions and operational rules in Chinese, starting in the metadata description and continuing throughout the strategy rule strings. Because the file does not indicate that the skill is region-specific or offer a language/locale choice, it may violate an organizational policy requiring user-facing language flexibility or explicit locale justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trend engine text says it is 'BTC/AAVE专用', but actual assignments include several other assets and exclude AAVE entirely. This inconsistency weakens operator trust and can cause incorrect deployment assumptions, especially when asset-specific tuning and historical performance claims are being used to justify live trading decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is explicitly described as generating crypto perpetual contract signals, yet the instrument assignment list includes non-crypto symbols such as SOXL, SOXS, BABA, SMCI, UBER, GOOGL, MRVL, and META. This scope mismatch is dangerous because downstream agents or operators may assume crypto-specific risk controls, market hours, liquidity, and indicator behavior apply universally, causing misrouting of trades or unsafe execution on inapplicable assets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The _auto_summarize function always generates Chinese summaries, and surrounding docstrings/title text also present the skill as Chinese-only. There is no user opt-in, language selection, or documented justification for a mandatory locale, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The top-level documentation says '三指标' and lists only ADX(14) + ATR百分位 + EMA453方向. However, the implementation computes BB width in compute_bb_width, passes it into classify_regime, and includes bb_width in the returned metrics, so the documentation understates the actual analyzed indicators.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code creates a CCXT Binance USD-M exchange client and calls fetch_ohlcv to retrieve remote data. Although the script prints that it is loading historical data, it does not clearly disclose that it will contact an external service and transmit requested symbols/timeframe parameters, which is the kind of network operation this rule asks to check for in code files.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The scan() docstring says the trend pool routes to "ST(10,3)+Gann ... or ST(10,3)纯信号", implying a possible Gann-enhanced path. However, this file's top-level changelog explicitly says "ST+Gann代码全量删除" and the actual routing only invokes scan_st_pure for trend signals, with no Gann computation or branch present.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language comment on L17 is written only in Chinese and does not provide an opt-in, alternative language, or any justification for a locale-specific restriction. Under the policy, forcing a specific language without user choice is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.