Back to skill

Security audit

Quote.Trade Operator — AI-Native Dark Pool DEX for Trading Bots and Autonomous Agents

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly disclosed guidance for Quote.Trade, but it includes a market-buy trade template that says approval is not required, which is risky for a financial trading workflow.

Review this skill carefully before using it for any trading workflow. Treat all trade proposals, paper or live, as requiring explicit user confirmation, and do not run the optional external bot repositories unless you inspect and pin the code in an isolated environment without wallet keys or exchange credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:76
Finding

Unpinned External Repository and Unsafe Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 76-84
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

text
- CLI bot (optional example): https://github.com/quoteTrade/quote-trade-CLI-trading-bot
  - Example reference for headless testing patterns, onboarding flows, and strategy command design.
- Telegram bot (optional example): https://github.com/quoteTrade/quote-trade-telegram-trading-bot
  - Example reference for chat-based interaction patterns and bot UX examples.

### Optional example commands (manual use only, not required)
```text
# Example only — run manually if explicitly approved by the user.
# git clone https://github.com/quoteTrade/quote-trade-CLI-trading-bot
# npm install
# npm run build

Technical Analysis

The documented workflow recommends cloning a mutable external Git repository and subsequently invoking npm install and npm run build. It does not pin the repository to a reviewed commit, verify a checksum or cryptographic signature, enforce lockfile integrity, or require inspection of package lifecycle and build scripts.

Both npm dependency installation and project builds can execute repository-controlled code, including lifecycle scripts such as preinstall, install, postinstall, prepare, prebuild, and the configured build command. Consequently, the effective code executed by this workflow can change after the skill itself has been reviewed.

The commands are commented examples, are described as optional, and require explicit user approval. These controls reduce the likelihood of exploitation, but they do not protect a user who follows the recommended workflow from a compromised upstream repository, malicious dependency update, or compromised maintainer account.

Attack Path

  1. An attacker compromises the referenced repository, one of its npm dependencies, or an upstream maintainer account.
  2. The a ...[truncated 1186 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the external repository to a specific, reviewed commit hash rather than cloning the mutable default branch.
  2. Record and verify the expected commit identity, release signature, or artifact checksum before use.
  3. Require a committed and reviewed npm lockfile, and use npm ci instead of an unconstrained npm install.
  4. Initially install dependencies with lifecycle scripts disabled, such as npm ci --ignore-scripts, then manually review every script that must be enabled.
  5. Audit package.json, lockfile changes, transitive dependencies, and build commands before execution.
  6. Pin and document the supported Node.js and npm versions to improve reproducibility.
  7. Run external code inside an isolated, disposable, least-privileged environment with no wallet keys, exchange credentials, SSH agents, cloud tokens, or unrelated host files.
  8. Restrict outbound network access during build and testing unless a reviewed operation explicitly requires it.
  9. Update the example to make commit pinning, provenance verification, and sandboxing mandatory rather than advisory.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s trade_proposal template explicitly sets "approvalRequired": false even though the surrounding guidance says to default to quote-only safe testing and to require explicit user approval before credential-related operations. In an agent context, machine-readable templates are often consumed more authoritatively than prose, so this mismatch can cause downstream systems to place trades without a human confirmation step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This specific example describes a MARKET buy order while marking approval as not required, which normalizes unattended execution of a trade. In a trading skill, even paper/live ambiguity or template reuse can lead agents or integrators to skip confirmation gates and execute unintended financial actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.