Back to skill

Security audit

technical-indicator-signal-engine

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed technical-analysis tool with a small OKX market-data demo, but users should treat its trading signals as informational and not investment advice.

Use this skill only as an educational or analytical aid, install dependencies in an isolated virtual environment, and avoid relying on its buy/sell output for real trades without independent review. Be aware that running scripts/signal_engine.py directly will contact OKX for BTC, ETH, and SOL candle data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:59
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Exposure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56-60
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

Vulnerable Code

markdown
## Dependencies

```bash
pip install pandas numpy requests
text

### Technical Analysis

The installation instruction retrieves the latest available versions of `pandas`, `numpy`, and `requests` without version constraints, integrity hashes, or a reviewed lock file. Consequently, installations are not reproducible and the package contents may differ from those originally audited.

Python package installation can execute package-controlled build or installation logic. If a dependency release or its package-distribution account is compromised, following this instruction could run attacker-controlled code with the privileges of the user performing the installation.

The listed package names are established packages rather than apparent typosquatting or dependency-confusion names. Therefore, exploitation depends on an upstream repository, maintainer account, release, or delivery-path compromise; the project itself does not contain a malicious dependency.

### Attack Path

1. An attacker compromises an upstream dependency release, maintainer account, or package-distribution channel.
2. A malicious version is published under one of the dependency names.
3. A user follows the documented unpinned `pip install` command.
4. `pip` resolves the compromised release because no approved version or hash is enforced.
5. Malicious build, installation, or imported runtime code executes in the user's Python environment.

### Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user running `pip`. Depending on those privileges, this could permit access to user-readable files, modification of the active Python environment, credential theft, or further system compromise.

No privilege escalation is inherent in th
...[truncated 187 chars]
Remediation
View remediation

Remediation Suggestions

  1. Move dependencies into a reviewed requirements or lock file with exact versions.
  2. Record cryptographic hashes and require hash verification during installation:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Generate the lock file from a trusted environment and review transitive dependencies.
  4. Use an isolated virtual environment rather than installing into a system-wide interpreter.
  5. Configure a trusted package index explicitly where appropriate.
  6. Automate dependency vulnerability scanning and controlled update review.
  7. Avoid recommending installation with administrator privileges.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/signal_engine.py:268
Finding

OKX HTTP Request Has No Timeout or Response Validation

Content
View full analysis

Vulnerability Details

File Location: scripts/signal_engine.py, lines 268-273
Vulnerability Type: Unbounded network request and unsafe response assumptions
Risk Level: Low

Vulnerable Code

python
resp = requests.get(
    "https://www.okx.com/api/v5/market/candles",
    params={"instId": inst_id, "bar": bar, "limit": str(limit)},
)
candles = resp.json()["data"]

Technical Analysis

The call to requests.get does not set a connection or read timeout. As a result, execution can remain blocked for an implementation-dependent and potentially indefinite period if the remote service accepts a connection but does not complete the response.

The code also does not call raise_for_status() before parsing the response and assumes that every response is valid JSON containing a top-level data field. HTTP error pages, rate-limit responses, service failures, or malformed JSON can therefore cause uncaught exceptions or unexpected processing failures.

HTTPS certificate verification remains enabled by default, and the endpoint is a declared public market-data source. The code does not transmit credentials or execute response content as code. The primary security consequence is availability and robustness rather than confidentiality, privilege escalation, or remote code execution.

Attack Path

  1. A user directly runs scripts/signal_engine.py, which invokes _fetch_okx for the configured cryptocurrency symbols.
  2. The OKX endpoint, an intermediary, or the user's network stalls after the connection is initiated, or returns an HTTP error or malformed response.
  3. Because no timeout is configured, the process may remain blocked.
  4. Alternatively, JSON parsing or direct access to resp.json()["data"] raises an uncaught exception.
  5. Signal generation fails, creating a denial of service for that execution.

Exploitation by an active network attacker is constrained by normal TLS verification. A serv ...[truncated 561 chars]

Remediation
View remediation

Remediation Suggestions

  1. Apply explicit connection and read timeouts:
    python
    resp = requests.get(
        "https://www.okx.com/api/v5/market/candles",
        params={"instId": inst_id, "bar": bar, "limit": str(limit)},
        timeout=(5, 15),
    )
    
  2. Call resp.raise_for_status() before parsing the response.
  3. Catch requests.RequestException, JSON decoding errors, and schema-validation errors.
  4. Verify that the decoded response is a mapping and that data is a list with the expected candle structure.
  5. Add bounded retries with exponential backoff and jitter for transient failures.
  6. Preserve default TLS verification and do not introduce verify=False.
  7. Return a controlled error to the caller rather than allowing an uncaught exception to terminate the complete multi-symbol analysis.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This is a genuine description-behavior mismatch: the skill is presented as a pure pandas indicator engine for supplied OHLCV data, but analysis indicates undeclared live network access to OKX and other implementation differences from the stated logic. Such mismatches are dangerous because reviewers and users may approve or invoke the skill under false assumptions, enabling unexpected external communication and producing misleading trading outputs based on undocumented behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "分析 XXXX" is broad and overlaps with ordinary conversational language, which can cause the skill to activate unintentionally when a user is simply asking for generic analysis. In an agent ecosystem, ambiguous activation can lead to confused routing, unintended execution of financial-analysis behavior, or accidental handling of inputs that were meant for another skill or the base assistant.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill documentation and detected capabilities indicate external network access may be used, but the skill declares no tool scope such as permissions or allowed-tools. Undeclared network behavior is dangerous because it prevents operators and users from understanding or constraining outbound data flows, increasing the risk of unexpected data exfiltration, privacy issues, or supply-chain style misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description specifies the trigger phrase only as the Chinese command "分析 XXXX", which imposes a language-specific interaction pattern. Under the stated policy, locale or language constraints should either be optional, user-selectable, or clearly justified as region-specific; this file provides no such opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The overview states that users should invoke the skill by entering "分析 XXXX" and does not offer alternative languages or a language preference mechanism. This is a natural-language policy issue because it prescribes a specific language for activation without user opt-in or documented regional necessity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language descriptions entirely in Chinese, including the top-level module description and subsequent docstrings, with no indication that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description says it is a pure pandas OHLCV signal engine, but the file also contains built-in network-fetching logic to pull market data from OKX. This creates a capability mismatch: importing or running the script can cause outbound data access that a user may not expect from a local indicator engine, expanding the trust boundary and introducing privacy, reliability, and supply-chain risk through dependence on an external service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code performs external HTTP requests to OKX despite the skill's stated purpose being local technical indicator calculation. Even though the target is a legitimate market-data API, unnecessary network access increases attack surface, can leak usage metadata, can hang or fail unpredictably, and may violate environments that expect offline-only analytical skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

文件中的标题、市场展示名、安装说明和触发口令均固定为中文,且未说明是否允许用户以其他语言触发或查看说明。按规则,若技能强制特定语言而无用户选择或明确的地域性正当说明,属于自然语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and descriptive text are entirely in Chinese and provide no indication that other languages are supported or that Chinese is a required locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.