Back to skill

Security audit

萤火网格1.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real automated crypto futures trading tool, but it gives live order authority with weak safety boundaries and some misleading operational wording.

Review carefully before installing. Use only exchange API keys with the minimum required permissions, prefer a sandbox or paper-trading setup first, and do not run watch or run against a real futures account unless you accept that it can place orders automatically and permanently log trading activity locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Intent-Code Divergence

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The CLI help and usage text describe run as a heartbeat that fetches price/ATR and outputs alerts, but run() calls _auto_reduce_pct(), _auto_reduce_one(), and _auto_add(), each of which submits live create_order() requests to Binance futures. This is dangerous because an operator may invoke a supposedly read-only command in production and unintentionally execute trades, add exposure, or close positions on a real account.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documentation describes a fully automated live perpetual-grid trading system, including exchange synchronization, automated order handling, and journaled position management, while the analyzed behavior reportedly does not implement those capabilities. This mismatch is dangerous because users may trust the skill for live trading or operational decisions under false assumptions, leading to financial loss or unsafe deployment choices.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill is about automated cryptocurrency derivatives trading, a high-risk domain involving real-money order execution, but the description does not present a clear warning about live trading, leverage, liquidation, or autonomous order placement. In this context, omission of safety warnings materially increases the risk that a user will run the skill against a real exchange without understanding the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The quick-start section provides commands for status checks, anchor registration, and continuous watch-mode automation that implies exchange synchronization and order execution, but no visible safety interlock or warning accompanies these instructions. Because the commands are immediately actionable and framed as normal startup steps, a user could trigger unintended live trading behavior with insufficient review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The top-level description promises that manually opened anchor positions will never be automatically touched, but _deduct_qty() explicitly reduces grid.anchor_qty after exhausting grid levels during automated stop-loss/take-profit actions. In a trading system that manages real exchange orders, this discrepancy can cause users to expose supposedly protected manual positions to automated liquidation, leading to unexpected financial loss.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/manual_grid_atr.py (reported line 300)May include surrounding context.

python
if self._exchange:
            return self._exchange
        from dotenv import load_dotenv
        load_dotenv(os.path.join(DIR, '.env'))
        self._exchange = ccxt.binanceusdm({
            'apiKey': os.getenv('BINANCE_API_KEY'),
            'secret': os.getenv('BINANCE_API_SECRET'),

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises operational behavior that would reasonably require filesystem and environment access, but it does not declare any explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can cause over-broad access or make users unaware that the skill may read/write local files and consume secrets from the environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The user-facing natural-language description and operating instructions are presented entirely in Chinese, with no indication that users may choose another language. This can violate a language/locale policy when a skill forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly describes permanent append-only local logging of trading activity, including timestamps, symbols, side, price, quantity, notional, entry, and realized PnL, but does not mention retention limits, access controls, redaction, or operator consent. In a live crypto trading system, these records can expose sensitive strategy behavior and financial activity if the host is shared, compromised, or backed up to less secure locations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring, command descriptions, and all user-facing output are in Chinese, effectively forcing a specific language for operation. There is no indication that the user can opt into another language or that the skill is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

At the execution points, the code automatically appends alerts and prints results after calling mgr.run(), but there is no strong user-facing warning at invocation time that this path may place real orders. In a high-risk crypto derivatives context, insufficient execution disclosure increases the chance of accidental live trading and operator error.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing natural language entirely in Chinese, and there is no indication that the skill is intentionally region-specific or that users can opt into another language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire strategy document is written in Chinese and does not indicate that language is optional, user-selectable, or required for a region-specific compliance reason. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains user-facing documentation and console output entirely in Chinese, which effectively forces a specific language on users. The policy allows locale constraints only when the skill offers opt-in or clearly documents a justified regional scope, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The only human-readable instruction in the file is written in Chinese, and there is no indication that users may choose another language or locale. This can violate a language-choice policy when the skill is expected to be generally usable across locales.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.