T05 · Unauthorized Access and Privilege Escalation
- Location
dawn-sdk-tools/SKILL.md:752- Finding
LLM Agent Receives Excessive Live-Trading Privileges
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed Dawn trading workflow, but it gives agents broad live-trading, wallet, dependency-install, and LLM-tool authority that users should review carefully before installing.
Review this skill before installing. Use paper mode by default, require a fresh explicit confirmation before any live launch or direct trade, avoid giving LLM agents buy/sell tools, review and pin npm/Python dependencies, and be aware that wallet balances, portfolio data, strategy prompts, and logs may be exposed to Dawn services or configured model providers.
dawn-sdk-tools/SKILL.md:752LLM Agent Receives Excessive Live-Trading Privileges
dawn-sdk-tools/SKILL.md:48Unpinned Third-Party Dependencies Are Installed and Executed
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
)
response: str = agent.run(prompt: str) # send message, get response (history preserved) agent.clear_history() # reset conversation
**Stateful pattern — agent remembers across iterations:**
The skill documents --live mode for real trades and wallet selection, but the surrounding guidance does not present a strong, prominent warning that these commands can cause immediate real-money financial loss. Because the same skill also covers code generation and launching, an agent could move from research to live execution with insufficient friction or user acknowledgement.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- **Deep multi-source research, several markets, or debugging a failing run:** usually 15-30+ minutes.
Example first message:
> "I’ll research the market, check tool docs, write the local strategy, and launch it in paper mode. This usually takes about 10-15 minutes; I’ll update you as I find the market and again before launch."
If the task grows, update the estimate rather than silently continuing.
The skill is scoped as authentication/setup, but it instructs the agent to pivot immediately into strategy execution and wallet management after login. This broadens the authority and behavioral surface of an auth skill, increasing the chance that a caller invoking a narrow login action is steered into higher-risk operations such as trading or funding flows without a separate explicit skill boundary.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
> Start with a pre-built strategy and see how it performs with simulated money.
>
> **2. Build a strategy from scratch**
> Research markets and write your own strategy with an LLM Agent's help.
>
> **3. Connect or create a wallet**
> Set up a wallet for live trading with real funds.
Template launching, editing, relaunching, and log monitoring are operational trading actions that exceed the declared purpose of authentication/setup. Embedding these steps in the auth skill encourages privilege and workflow creep, making it easier for an agent to move from obtaining access to executing strategies without a clean separation of duties.
Including wallet selection, creation, and funding guidance inside an authentication skill creates an unjustified path from simple login to handling financial assets. In an agent setting, this can normalize or trigger sensitive actions involving real funds under the umbrella of a low-risk auth task, which materially raises the risk of unintended financial operations.
The skill explicitly expands beyond a bounded SDK reference by telling the agent that any pip dependency and custom HTTP client may be used. In an agentic coding workflow, this materially enlarges the execution and exfiltration surface: generated strategies can fetch arbitrary remote content, contact attacker-controlled endpoints, or introduce risky packages that bypass the intended Dawn tool boundary.
Documenting a general-purpose Agent/run_agent with broad tool access turns a narrow trading-tools reference into a generic autonomous execution framework. That increases the chance that generated strategy code delegates decisions to an LLM that can invoke sensitive tools, amplifying prompt-injection, unintended tool use, and unsafe trade execution risks.
The skill encourages use of arbitrary external model providers and the user's own API keys, creating a data egress path outside the Dawn environment. Market data, portfolio state, prompts, and potentially sensitive strategy context may be sent to third-party providers without clear necessity or trust boundaries, increasing confidentiality and supply-chain risk.
The skill description is broad enough to encourage use for end-to-end trading strategy creation, launch, monitoring, and management without clearly constraining when automation is appropriate. In a financial context, overly broad invocation guidance increases the chance an agent will take consequential actions, including launching strategies or placing trades, in situations where the user intended only analysis or low-risk assistance.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Write the strategy to ~/.dawn-cli/strategies/ using the strategy name (kebab-case) as the filename:
~/.dawn-cli/strategies/btc-election-2026.py (or a project directory with __main__.py)The manifest frames the skill as creating, launching, monitoring, and managing Dawn strategies, but this section specifically promotes a 'copy-trade the top trader' workflow. That is a distinct strategic capability and behavioral recommendation beyond neutral workflow management and research guidance.
No suspicious patterns detected.