Back to skill

Security audit

Prediction Trade Journal

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its trade-journal purpose, but it needs review because it can send the user's API bearer token to an undocumented environment-selected host and installs an unused unpinned package.

Review before installing. Use this only in an environment where SIMMER_API_URL cannot be set by untrusted configuration, or remove/lock it to the official Simmer API host before using SIMMER_API_KEY. Consider removing the unused simmer-sdk dependency or pinning it to a reviewed version. Treat data/trades.json, data/context.json, and exported CSVs as sensitive financial records.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
tradejournal.py:101
Finding

Bearer API Credential Can Be Redirected to an Untrusted Host

Content
View full analysis
Dict: """Make authenticated request to Simmer API.""" if not SIMMER_API_KEY: raise ValueError("SIMMER_API_KEY environment variable not set") url = f"{SIMMER_API_URL}{endpoint}" if params: # Filter None values and URL-encode parameters filtered = {k: v for k, v in params.items() if v is not None} url = f"{url}?{urlencode(filtered)}" headers = { "Authorization": f"Bearer {SIMMER_API_KEY}", "Content-Type": "application/json", } req = Request(url, headers=headers, method=method) try: with urlopen(req, timeout=REQUEST_TIMEOUT_SECONDS) as response: ``` ### Technical Analysis The complete API origin is read from the undocumented `SIMMER_API_URL` environment variable. The program then attaches the `SIMMER_API_KEY` bearer credential to requests sent to that origin. No validation restricts the destination to `https://api.simmer.markets`, verifies that HTTPS is used, or prevents credentials from being sent to an unrelated hostname. Consequently, any party capable of influencing the process environment can redirect authenticated synchronization requests to a server under its control. Using an environment variable for an endpoint can be legitimate in development, but forwarding a production bearer credential to an unrestricted origin violates least-privilege and credential-boundary principles. The documented functionality only requires authenticated communication with the official Simmer API. ### Attack Path 1. An attacker gains the a ...[truncated 1402 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Unpinned and Unused Third-Party Dependency Expands the Supply-Chain Attack Surface

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tainted flow: 'req' from os.environ.get (line 196, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request URL is derived in part from the SIMMER_API_URL environment variable and then used in urlopen with the Bearer API key attached. If an attacker can influence that environment variable, they can redirect authenticated requests to an attacker-controlled server and capture the API key and trade metadata. In an agent/automation context, environment and runtime configuration are common control points, which makes this more dangerous than a normal hardcoded-client pattern.

Content

Scanner excerpt · tradejournal.py (reported line 199)May include surrounding context.

python
req = Request(url, headers=headers, method=method)

    try:
        with urlopen(req, timeout=REQUEST_TIMEOUT_SECONDS) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        error_body = e.read().decode("utf-8")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes capabilities that access environment variables, perform network requests to an external API, and read/write local files, but it does not declare an explicit tool scope or permissions boundary. That mismatch is dangerous because users and hosting agents cannot reliably understand or constrain what the skill is allowed to do, increasing the risk of over-privileged execution or unintended data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill stores detailed local trade history, including market questions, positions, cost basis, outcomes, and potentially enriched thesis/confidence metadata, but it does not clearly warn users about the privacy sensitivity of this data. This is dangerous because trade history can reveal financial behavior, strategies, and potentially identifying context, leading users to expose sensitive information without informed consent or appropriate local protections.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code persists fetched trade history to data/trades.json, and elsewhere supports exporting the same data to CSV. Although the module docstring describes functionality, it does not clearly warn users that their trading activity and related context will be stored on disk, which is a user-impacting data handling behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill makes authenticated HTTP requests to the Simmer API using the user's API key and retrieves account trade data. While contacting the API is part of the skill's purpose, the code does not give a clear user-facing disclosure that running sync operations will transmit authenticated requests and fetch account-linked data from a remote service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.