Back to skill

Security audit

Aion Test Skill

Security checks for vulnerabilities and agentic risk

Overview

This automated trading skill is coherent, but needs review because its default dry-run and scheduled mode can still perform real account redemptions.

Install only after confirming dry-run cannot redeem funds, scheduled runs are disabled or explicitly authorized, dependencies are pinned or otherwise verified, and the AION credential is limited to the minimum authority you are willing to grant to this skill. There is no artifact-backed evidence of credential exfiltration or OS persistence, but the current dry-run boundary is not safe for a financial automation tool.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
momentum_trader.py:169
Finding

Dry-Run Mode Performs Real Auto-Redemption Operations

Content
View full analysis
Dict: """ Execute one trading cycle Returns: Dictionary containing execution summary """ client = get_client() print(f"\n{'='*70}") print(f"Skill: {SKILL_SLUG}") print(f"Venue: {VENUE}") print(f"Mode: {'DRY-RUN (simulation)' if dry_run else 'LIVE TRADING ⚠️'}") print(f"{'='*70}\n") # 1. Auto-redeem resolved positions print("🔄 Checking for positions to redeem...") redeemed = auto_redeem_positions() ``` ### Technical Analysis The `dry_run` argument protects order placement inside `execute_trade()`, but it is not passed to or evaluated by `auto_redeem_positions()`. Consequently, `run_once(dry_run=True)` still calls `client.auto_redeem()` using an authenticated `AionClient`. Auto-redemption is an account or blockchain state-changing financial operation rather than a read-only simulation. The default command is documented as dry-run mode, so users can reasonably expect i ...[truncated 2079 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Security-Critical Dependencies Are Installed Without Reproducible Version Pinning

Content
View full analysis
=0.1.0 requests>=2.28.0 ``` The documented installation command in `README.md:21` consumes these unconstrained future releases: ```bash pip install -r requirements.txt ``` The documentation also recommends a moving npm installer version in `SKILL.md:151`: ```text 1. Install skill: `npx clawhub@latest install momentum-polymarket-trader` ``` ### Technical Analysis The lower-bound-only Python constraints permit installation of any future package release accepted by the resolver. There is no lockfile, exact version, or package hash to bind installation to artifacts reviewed with this skill. This is especially sensitive for `aion-sdk`: the package is imported at process startup, receives `AION_API_KEY`, and implements authenticated market, redemption, and trade operations. A compromised or unexpectedly changed SDK release would execute with all privileges granted to the Python process and could access the credential supplied to its constructor. The included source imports no `requests` module directly, so declaring it as a direct dependency unnecessarily expands the dependency surface unless it is required for an undocumented extension. Transitive dependencies should ordinarily be resolved and pinned through a reviewed lockfile rather than redundantly installed as broad direct requirements. The `npx clawhub@latest` instruction creates a similar moving-target risk for the installation tool. This does not prove that any current package is malicious; the vulnerability is the lack of reproducibility and integrity controls around security-critical executable dependencies. ### Attack Path 1. An attacker compromises an allowed future release of `aion-sdk`, one of its transitive dependencies, or the moving `clawhub@latest` package. Alternatively ...[truncated 1686 chars]
Remediation
View remediation
``` 2. Generate and commit a lockfile containing all transitive dependencies. 3. Require cryptographic hashes during installation, for example through a hash-locked requirements file and: ```bash pip install --require-hashes -r requirements.lock ``` 4. Remove `requests` from direct requirements if the project does not import or otherwise require it directly. If it is necessary, pin and hash it with the rest of the dependency graph. 5. Replace `npx clawhub@latest` with a specific reviewed CLI version. 6. Review the provenance, maintainers, release history, and package index source of `aion-sdk`. Use a trusted private mirror or allowlist where appropriate. 7. Run the skill in an isolated environment with: - A minimally scoped API key. - Only required environment variables. - Restricted filesystem access. - Outbound network access limited to documented service endpoints. - No unnecessary operating-system privileges. 8. Establish a controlled dependency-update process that performs vulnerability scanning, provenance verification, change review, and dry-run regression testing before accepting new releases. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (12)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · README.md (reported line 138)May include surrounding context.

The skill will automatically appear in the AION registry within 6 hours: https://pm-t1.bxingupdate.com/agents

4. Update Skill

bash
npx clawhub@latest publish . --slug momentum-polymarket-trader --bump patch

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
- Fetches market context and trading discipline data
   - Calculates price momentum indicators
   - Evaluates trading edge
4. **Executes Trades** - Trades when positive edge is found with no warnings
5. **Auto-Redeems** - Periodically redeems winnings from resolved markets

## Remixable Template

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to execute npx clawhub@latest ..., which pulls and runs the latest remote package version at execution time rather than a fixed, reviewed release. If the upstream package is compromised or a breaking/malicious version is published, users following the documentation could execute attacker-controlled code on their system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This installation command uses npx clawhub@latest, causing the tool to fetch and execute whatever the current latest package is at runtime. That creates a supply-chain execution risk for anyone following the setup instructions, especially because npx executes package code directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The update command again directs users to run npx clawhub@latest, which exposes them to arbitrary changes in the upstream package at the moment they execute the command. In a trading-skill context, compromised tooling is particularly concerning because it may lead to credential theft, malicious publication changes, or workstation compromise.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises behavior that depends on environment variables, including sensitive credentials such as API keys and potentially a wallet private key, but it does not declare an explicit tool scope or permissions boundary. In an agent ecosystem, missing scope declarations can cause over-broad access assumptions and make it harder for operators to enforce least privilege around secret access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command uses npx clawhub@latest, which pulls an unpinned package version at execution time. This creates a supply-chain risk: a compromised upstream package, malicious update, or typo-squatted dependency could cause users to install and run attacker-controlled code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is configured to run automatically every 15 minutes with no stated trigger guardrails, market-state checks, cooldowns, or exclusion conditions in the metadata. In an automated trading context, unconstrained periodic execution increases the risk of unintended or repeated trades, especially if upstream signals, wallet state, or market conditions are abnormal.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The env var description directs users to a single external URL to obtain credentials, but the manifest provides no language or locale choice or indication that this is region-specific by design. This can be a natural-language policy concern when a skill effectively assumes one locale or language path without opt-in or justification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency specification aion-sdk>=0.1.0 is unpinned, which allows future installs to resolve to different versions over time. That creates supply-chain and reproducibility risk: a later compromised or breaking release could be pulled into an automated trading skill without review, potentially affecting trade execution or exposing secrets.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
aion-sdk>=0.1.0
requests>=2.28.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency requests>=2.28.0 is not pinned to a specific version, so installations may pull different releases with different security properties. In a trading automation context that likely performs network requests and may handle credentials, nondeterministic dependency resolution increases the risk of introducing vulnerable or malicious package versions.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
aion-sdk>=0.1.0
requests>=2.28.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
97% confidence
Finding

requests has multiple published advisories, and because the manifest does not pin an exact version, it is impossible to verify whether deployed environments will install a safe release. This is especially relevant for an automated Polymarket trading skill, where HTTP handling may involve API keys, session state, or outbound requests that could be affected by credential leakage, TLS verification issues, or other client-side flaws present in vulnerable versions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.