Back to skill

Security audit

AgentFeed Liquidations & Funding

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for paid live market-data API calls, with costs and payment controls disclosed.

Install only if you are comfortable with an agent making live API requests and, after your approval, spending small USDC amounts through your own x402 wallet/client. Review the live price before each paid call, keep per-call limits tight, and treat the returned market data as informational rather than trading advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file states the skill 'covers its liquidation and funding routes' and describes only liquidation/funding-focused scope, yet later includes options, market-state, macro-calendar, equity-24h, and MCP endpoints as part of the skill guidance. That broadens the effective behavior beyond the manifest's stated purpose of liquidation, funding radar, and options.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Early documentation narrows intent to liquidation and funding routes, but later sections document options-summary, options-gex, market-state, tradfi-radar, and even additional macro/equity routes. This is an active contradiction in the file's own description of what the skill covers.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The prose says the skill 'runs no code of its own,' but the manifest requires external binaries (curl, base64) and the file instructs the agent to execute HTTP/payment command flows. While this may be intended as usage guidance, it contradicts the claim that the skill has no operational code path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.