Back to skill

Security audit

QuantClaw

Security checks for vulnerabilities and agentic risk

Overview

The skill openly describes a Bybit crypto trading assistant that needs API keys and can place live trades, but the reviewed artifact is only a stub and users must verify the paid CLI before use.

Install only in an isolated environment, prefer Homebrew or a pinned verified uv install, inspect the purchased QuantClaw source and checksum before running it, start with Bybit demo/testnet keys, and never provide keys with withdrawal permissions unless you fully trust the paid CLI.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–23
Vulnerability Type: Unpinned dependency installation from a mutable package repository
Risk Level: Medium

Vulnerable Code

yaml
    - id: uv-pip
      kind: shell
      command: "pip install uv"
      label: "Install uv via pip (alternative)"

Technical Analysis

The installation command retrieves and installs the latest available release of the uv package without specifying an audited version or validating a cryptographic hash. Consequently, the code executed during installation depends on mutable third-party package repository state rather than an immutable, previously reviewed artifact.

Python package installation may execute package-controlled build or installation logic. If the package, maintainer account, release process, or distribution channel is compromised, a malicious release could run code under the privileges of the user invoking the installation command.

This finding does not establish that the current uv package is malicious. The vulnerability is the absence of version pinning and artifact integrity verification in the supplied installation instruction.

Attack Path

  1. An attacker compromises the upstream package, a maintainer account, or the package publication pipeline.
  2. The attacker publishes a malicious or backdoored release under the expected package name.
  3. A user follows the Skill's alternative installation instruction and executes pip install uv.
  4. pip resolves the mutable latest release instead of a known, audited version.
  5. Malicious package installation or build logic executes locally with the invoking user's privileges.
  6. The payload may access files, environment variables, and credentials available to that user, including Bybit credentials if they are already present in the environment.

Impact Assessment

Successful exploitation could provide arbitrary code execution with t ...[truncated 548 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin uv to a specific version that has been reviewed and tested, for example uv==<approved-version>.
  • Require cryptographic hash validation by using a requirements file with --require-hashes and the expected SHA-256 hashes for all permitted artifacts.
  • Document the expected package publisher, repository, version, and artifact hashes through an authenticated project-controlled channel.
  • Prefer installation from an immutable, verified release artifact rather than resolving the latest package dynamically.
  • Establish a controlled upgrade process that reviews release notes, source changes, signatures, and hashes before changing the pinned version.
  • Advise users to install in an isolated environment without sensitive API credentials loaded and without elevated privileges.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.