Back to skill

Security audit

Bybit Futures

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Bybit futures trading skill, but it needs Review because it can place real leveraged orders and recommends persistent root-level deployment with weakly documented safety controls.

Install only if you are prepared to audit and modify it before any live use. Keep API keys restricted to contract trading with no withdrawals, run paper mode manually first, avoid the provided root systemd deployment or convert it to a locked-down user service, disable Telegram unless you accept sending trading details to that chat, and fix the risk-control gaps before connecting real funds.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:63
Finding

Paper Trading Service Is Installed as a Persistent Root-Level System Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/risk_manager.py:23
Finding

Live Trading Risk Limits Fail Open After Restart and Do Not Track Realized Losses

Content
View full analysis
0 and pos["side"] == side: close_side = "sell" if side == "long" else "buy" order = self.exchange.create_order( symbol, "market", close_side, float(pos["contracts"]), params={"reduceOnly": True} ) self.risk.position_closed() log.info(f"CLOSED {symbol} {side} order={order['id']}") return order ...[truncated 2143 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/paper_trading_ws.py:91
Finding

Paper Trading Bypasses Documented Daily-Loss and Concurrent-Position Controls

Content
View full analysis
[Paper] {strategy} OPEN\n{coin} {side.upper()} @ ${price:,.2f}\nMargin: ${margin:.2f} | {leverage}x\nSL: ${sl:,.2f} | TP: ${tp:,.2f}" log.info(msg) send_tg(msg) ``` ### Technical Analysis The Skill documentation states that all trades are enforced by `risk_manager.py`, including the daily loss limit and maximum number of concurrent positions. The paper-trading implementation does not instantiate or invoke `RiskManager`. `open_position()` calculates a per-position margin, but it does not verify: - Whether the daily simulated loss limit has been reached. - Whether `MAX_OPEN_POSITIONS` has been reached. - Whether sufficient uncommitted capital remains. - Whether the requested size is valid and finite. Positions are keyed by strategy name, so every additional strategy can create another concurrent simulated position without a global count check. This makes paper-trading behavior inconsistent with the docum ...[truncated 952 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill documents Telegram notifications and other operational behaviors that are not surfaced clearly in the top-level declaration, creating a transparency gap around third-party data flows. In a trading skill that may handle account activity and operational alerts, undeclared outbound messaging materially changes the privacy and security posture.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill documents Telegram notifications and other operational behaviors that are not surfaced clearly in the top-level declaration, creating a transparency gap around third-party data flows. In a trading skill that may handle account activity and operational alerts, undeclared outbound messaging materially changes the privacy and security posture.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions tell users to move from paper trading to live execution without an explicit warning that this can place real market orders and cause immediate financial loss. In this context, the omission is especially dangerous because the skill is expressly designed for leveraged futures trading, where mistakes can rapidly liquidate positions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises capabilities that inherently require network, file, and environment access, but it does not declare any explicit tool scope or permissions boundary. That makes the operational surface ambiguous and increases the risk that an agent may invoke the skill with broader access than the user expects, especially given it handles API keys and live trading workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation text is extremely broad and could cause the skill to be selected for many generic coding or trading-related requests, including contexts where users did not intend live-trading or credential-handling behavior. Overbroad routing is risky here because the skill spans networked automation, persistent deployment, and real-money execution.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Recommending a systemd service on a VPS normalizes unattended persistent execution for an autonomous trading bot. That increases risk of long-lived unintended behavior, especially when combined with live trading, auto-reconnect, and state persistence features documented elsewhere in the skill.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

Recommended: systemd service on a VPS.

bash
# Create service file
sudo tee /etc/systemd/system/paper-trading.service << 'EOF'
[Unit]
Description=Paper Trading Bot (WebSocket)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
82% confidence
Finding

The documentation instructs use of sudo to write a systemd service file under /etc/systemd/system, which requires elevated privileges and can modify system startup behavior. While common for deployment, embedding privileged commands in a skill increases the chance of unnecessary root use or accidental system-wide changes by users following instructions blindly.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

bash
# Create service file
sudo tee /etc/systemd/system/paper-trading.service << 'EOF'
[Unit]
Description=Paper Trading Bot (WebSocket)
After=network.target

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
81% confidence
Finding

Using sudo systemctl enable --now both starts the service and persists it across reboots, requiring elevated privileges and changing the host's startup configuration. In a network-connected trading bot, that persistence can prolong unintended operation or keep a misconfigured bot trading continuously.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

WantedBy=multi-user.target EOF

sudo systemctl enable --now paper-trading

text

## Telegram Notifications

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The instructions explicitly enable the bot as a persistent service, causing it to survive reboots and continue operating without interactive oversight. In this skill's context, persistence is more dangerous than usual because the service may perform autonomous trading and continue placing orders or sending data after mistakes or changed conditions.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

WantedBy=multi-user.target EOF

sudo systemctl enable --now paper-trading

text

## Telegram Notifications

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages Telegram notifications without warning that trade events, timing, errors, and possibly other sensitive operational details are transmitted to a third party. That creates privacy and operational-security risk, particularly for a trading bot where account activity and incident data may be sensitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code sends messages to the Telegram Bot API containing trade opens/closes and periodic account summaries, which transmits potentially sensitive financial activity to an external service. Although the function name implies Telegram use, there is no confirmation prompt or explicit warning comment/docstring near the network call disclosing that user trading data will be sent off-system.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

This code transmits trading activity and account summary information to Telegram, a third-party external service, using credentials from local configuration. In the context of a futures trading system, those messages can reveal positions, balances, and strategy behavior, which may create privacy and operational security risk if tokens, chat IDs, or Telegram access are compromised.

Content

Scanner excerpt · scripts/paper_trading_ws.py (reported line 41)May include surrounding context.

python
if not config.TG_BOT_TOKEN:
        return
    try:
        requests.post(
            f"https://api.telegram.org/bot{config.TG_BOT_TOKEN}/sendMessage",
            json={"chat_id": config.TG_CHAT_ID, "text": msg, "parse_mode": "HTML"},
            timeout=10,

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The hardcoded Telegram API endpoint confirms outbound transmission of bot-generated trade data to an external network service. In a trading-bot context, this increases risk because operationally sensitive market actions and account summaries leave the local environment and may be exposed through third-party retention, compromised bot credentials, or misdirected chat configuration.

Content

Scanner excerpt · scripts/paper_trading_ws.py (reported line 42)May include surrounding context.

python
return
    try:
        requests.post(
            f"https://api.telegram.org/bot{config.TG_BOT_TOKEN}/sendMessage",
            json={"chat_id": config.TG_CHAT_ID, "text": msg, "parse_mode": "HTML"},
            timeout=10,
        )

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · references/bybit_api_notes.md (reported line 6)May include surrounding context.

md
## Account Setup

- Use **Unified Trading Account (UTA)** — supports spot + derivatives in one account
- API permissions: **Read-Write** for Contract. Never enable Assets/Withdrawal for trading bots
- Testnet available at `https://api-testnet.bybit.com` (set `sandbox: true` in ccxt)

## ccxt Configuration

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code makes an external HTTP/API call to Bybit via ccxt to retrieve market data, but the function itself has no docstring, comment, or user-facing notice explaining that external network access will occur. While the main script prints the candle count afterward, it does not disclose the outbound request before or at the point of execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill writes capital, positions, trades, prices, and timestamps to paper_state.json, which persists potentially sensitive trading records to disk. While logging exists for state loading, there is no nearby disclosure or warning that this data is stored locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.