Back to skill

Security audit

Dawn

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Dawn trading workflow, but it gives agents broad live-trading, wallet, dependency-install, and LLM-tool authority that users should review carefully before installing.

Review this skill before installing. Use paper mode by default, require a fresh explicit confirmation before any live launch or direct trade, avoid giving LLM agents buy/sell tools, review and pin npm/Python dependencies, and be aware that wallet balances, portfolio data, strategy prompts, and logs may be exposed to Dawn services or configured model providers.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
dawn-sdk-tools/SKILL.md:752
Finding

LLM Agent Receives Excessive Live-Trading Privileges

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
dawn-sdk-tools/SKILL.md:48
Finding

Unpinned Third-Party Dependencies Are Installed and Executed

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · dawn-sdk-tools/SKILL.md (reported line 764)May include surrounding context.

)

response: str = agent.run(prompt: str) # send message, get response (history preserved) agent.clear_history() # reset conversation

text

**Stateful pattern — agent remembers across iterations:**

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents --live mode for real trades and wallet selection, but the surrounding guidance does not present a strong, prominent warning that these commands can cause immediate real-money financial loss. Because the same skill also covers code generation and launching, an agent could move from research to live execution with insufficient friction or user acknowledgement.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
- **Deep multi-source research, several markets, or debugging a failing run:** usually 15-30+ minutes.

Example first message:
> "I’ll research the market, check tool docs, write the local strategy, and launch it in paper mode. This usually takes about 10-15 minutes; I’ll update you as I find the market and again before launch."

If the task grows, update the estimate rather than silently continuing.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is scoped as authentication/setup, but it instructs the agent to pivot immediately into strategy execution and wallet management after login. This broadens the authority and behavioral surface of an auth skill, increasing the chance that a caller invoking a narrow login action is steered into higher-risk operations such as trading or funding flows without a separate explicit skill boundary.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · dawn-auth/SKILL.md (reported line 75)May include surrounding context.

md
> Start with a pre-built strategy and see how it performs with simulated money.
>
> **2. Build a strategy from scratch**
> Research markets and write your own strategy with an LLM Agent's help.
>
> **3. Connect or create a wallet**
> Set up a wallet for live trading with real funds.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Template launching, editing, relaunching, and log monitoring are operational trading actions that exceed the declared purpose of authentication/setup. Embedding these steps in the auth skill encourages privilege and workflow creep, making it easier for an agent to move from obtaining access to executing strategies without a clean separation of duties.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Including wallet selection, creation, and funding guidance inside an authentication skill creates an unjustified path from simple login to handling financial assets. In an agent setting, this can normalize or trigger sensitive actions involving real funds under the umbrella of a low-risk auth task, which materially raises the risk of unintended financial operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly expands beyond a bounded SDK reference by telling the agent that any pip dependency and custom HTTP client may be used. In an agentic coding workflow, this materially enlarges the execution and exfiltration surface: generated strategies can fetch arbitrary remote content, contact attacker-controlled endpoints, or introduce risky packages that bypass the intended Dawn tool boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Documenting a general-purpose Agent/run_agent with broad tool access turns a narrow trading-tools reference into a generic autonomous execution framework. That increases the chance that generated strategy code delegates decisions to an LLM that can invoke sensitive tools, amplifying prompt-injection, unintended tool use, and unsafe trade execution risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill encourages use of arbitrary external model providers and the user's own API keys, creating a data egress path outside the Dawn environment. Market data, portfolio state, prompts, and potentially sensitive strategy context may be sent to third-party providers without clear necessity or trust boundaries, increasing confidentiality and supply-chain risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill description is broad enough to encourage use for end-to-end trading strategy creation, launch, monitoring, and management without clearly constraining when automation is appropriate. In a financial context, overly broad invocation guidance increases the chance an agent will take consequential actions, including launching strategies or placing trades, in situations where the user intended only analysis or low-risk assistance.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · dawn-strategy/SKILL.md (reported line 177)May include surrounding context.

Launch

Write the strategy to ~/.dawn-cli/strategies/ using the strategy name (kebab-case) as the filename:

  • ~/.dawn-cli/strategies/btc-election-2026.py (or a project directory with __main__.py)
bash

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest frames the skill as creating, launching, monitoring, and managing Dawn strategies, but this section specifically promotes a 'copy-trade the top trader' workflow. That is a distinct strategic capability and behavioral recommendation beyond neutral workflow management and research guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.