Back to skill

Security audit

Options Trading Backtester

Security checks for vulnerabilities and agentic risk

Overview

This options backtesting skill is not malware, but it overstates its financial analysis capabilities in ways users could mistake for realistic trading evidence.

Review this before installing if you might use it for trading decisions. Treat the outputs as a synthetic demo only, not as historical backtest evidence or investment advice, unless the author narrows the claims or implements the missing data ingestion, strategies, risk filters, and disclaimers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises historical and real-data options backtesting across multiple strategies, but the implementation only performs a simplified iron condor simulation with random prices. This can materially mislead users into trusting outputs as realistic financial analysis, creating a safety risk in a finance context where users may make real trading decisions based on false assumptions about methodology and coverage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation guidance says to use the skill when the user asks to 'backtest an options strategy, test a config, or analyze trade history.' The latter two phrases are especially broad and lack boundaries or exclusion conditions, which could cause the skill to activate for general analysis or configuration tasks beyond this backtester's intended scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill presents simulated backtest outputs without a clear warning that they are synthetic estimates and not financial advice. In a finance context, lack of disclaimer increases the chance that users treat approximate or unrealistic outputs as actionable investment guidance, especially given the overstated claims elsewhere in the file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation claims guardrails that reject low-IV, wide-spread, and near-expiry trades, but the code does not enforce any of them. In a trading/backtesting skill, absent risk filters can cause users to overestimate robustness and use results for scenarios the tool explicitly implied it would screen out.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.