Back to skill

Security audit

Dsl Exit Engine

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a trading-strategy guidance skill with no evidence of hidden code or unsafe installation behavior, though users should treat its financial guidance carefully.

Install only if you understand it as trading guidance, not financial advice or a trading safety guarantee. Before using any generated strategy with real funds, confirm the scope, risk controls, budget limits, and exit rules yourself.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is overly broad and uses catch-all phrasing like 'anything described as' plus many generic trading terms, which can cause the agent to invoke this skill in contexts where it is not the best or safest fit. In an agentic system, ambiguous routing increases the chance of inappropriate guidance being applied to unrelated strategy tasks, leading to degraded decision quality or unsafe automation behavior.

Static analysis

No suspicious patterns detected.