Back to skill

Security audit

x-trading

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is coherent and not malicious, but it needs review because it can access sensitive financial data and cancel orders without explicit cancellation safeguards.

Install only if you are comfortable giving the agent access to your X trading account. Use the least-privileged API key possible, avoid enabling cancellation or trading permissions unless needed, and manually confirm any order cancellation or sensitive account/history display until the skill adds stronger safeguards.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
api-orders.md:9
Finding

Order Cancellation Lacks an Explicit User Confirmation Checkpoint

Content
View full analysis
Only orders with status `open` or `partial` can be cancelled. > If the order is already filled or cancelled, the API returns 400. ``` ### Technical Analysis The Skill defines an explicit confirmation control only for `POST /orders`. The wording “Before calling POST /orders” excludes the `DELETE /orders/{order_id}` operation from those safeguards. Order cancellation is a state-changing and financially consequential action. Nevertheless, its documented workflow does not require the agent to: - Retrieve and display the target order before cancellation. - Verify the order identifier supplied by the user. - Show the symbol, side, price, and unfilled quantity. - Obtain explicit confirmation immediately before issuing the DELETE request. - Revalidate that the order remains open or partially filled after confirmation. Consequently, the agent can follow the documented can ...[truncated 1624 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · api-orders.md (reported line 78)May include surrounding context.


DELETE /orders/{order_id} — Cancel an order

Request

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · api-orders.md (reported line 82)May include surrounding context.

Request

text
DELETE /orders/ORD-20250325-001
X-API-KEY: {X_TRADING_API_KEY}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

text

The key is stored in the environment variable `X_TRADING_API_KEY`.  
Base URL: `https://api.xtrading.com/v1`

> ⚠️ Never expose, log, or repeat the API key in any response.  
> If `X_TRADING_API_KEY` is missing, ask the user to set it before proceeding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file describes direct access to profile, balance, and positions data but does not instruct the agent to treat this information as sensitive or to confirm the user's intent before displaying it. In a financial trading skill, missing privacy guidance can lead to disclosure of personally identifiable and financial information in response to ambiguous prompts or in shared-device/chat scenarios.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough that ordinary user messages about balances, holdings, or assets could automatically load this skill and expose account functionality in contexts where the user did not clearly intend sensitive financial access. In a trading/account module, overbroad activation increases the chance of unnecessary retrieval or display of private portfolio data and accidental use of authenticated endpoints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very broad generic terms like "history," "report," and "transactions," plus common multilingual variants, which can cause this skill to load in response to ambiguous user requests unrelated to trading. In a trading context, unintended invocation is risky because the module exposes access patterns for sensitive financial history and may lead to unnecessary retrieval or display of account activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This module documents access to highly sensitive account and transaction history, including deposits, withdrawals, balances, and trade settlements, but provides no warning or consent guidance before surfacing that data. In the context of a trading skill, this increases the chance of exposing private financial information through casual invocation, over-broad responses, or display in shared environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very generic terms such as "price," "quote," and "走势," which can match ordinary conversational requests and cause this skill to load outside narrowly intended trading contexts. In a trading skill, over-broad activation increases the chance of unnecessary access to market/trading functionality and can route unrelated user prompts into a sensitive financial workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary conversation about buying, selling, or orders, which could cause the trading skill to load in contexts the user did not intend as a trading action. In a financial-trading skill, accidental activation is risky because it can lead to collection of order parameters or progression toward sensitive actions unless the agent has very strong downstream confirmation controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The trigger list explicitly includes both English and Chinese phrases, but the document does not explain how language or locale is selected or whether multilingual behavior is user-driven. This can create an implicit language-policy issue because the skill appears to force or assume multilingual activation behavior without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.