Back to skill

Security audit

Hyperscaled Funded Account

Security checks for vulnerabilities and agentic risk

Overview

This Hyperscaled trading skill appears purpose-aligned, but it needs review because it can install unpinned code and perform high-impact trading/account actions.

Review this skill before installing. Only use it if you trust the Hyperscaled package source, preferably install a reviewed pinned version in an isolated environment, and require explicit confirmation for any purchase, KYC, config change, order cancellation, or trade. Do not pass private keys on the command line; use narrowly scoped credentials where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:12
Finding

Unpinned Third-Party Package Installation in a Financial Context

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12–16
Vulnerability Type: Insecure, unpinned third-party dependency installation
Risk Level: High

Vulnerable Code:

markdown
If the `hyperscaled` CLI is not available, install it first:

pip install hyperscaled

text

Technical Analysis

The skill directs the agent to install hyperscaled from the package index without specifying an audited version, cryptographic hashes, a trusted index, or publisher verification. Package resolution therefore depends on mutable external package-index state at installation time.

Python package installation can execute package-controlled build or installation logic. The installed CLI is subsequently trusted to handle wallet configuration, account information, registration, and trade operations. The repository provides no lockfile, hash manifest, vendored dependency, or other mechanism for verifying that the retrieved artifact matches reviewed code.

This creates a software supply-chain exposure: compromise of the package, its dependencies, the configured package index, or package-name ownership could cause attacker-controlled code to execute under the agent's operating-system identity.

Attack Path

  1. An attacker compromises or replaces the hyperscaled package, one of its transitive dependencies, or the package-index resolution path.
  2. A user invokes this skill on a system where the CLI is not installed.
  3. Following SKILL.md, the agent runs pip install hyperscaled.
  4. The package manager downloads the current unverified artifact and may execute attacker-controlled build or installation code.
  5. The malicious package executes with the permissions of the agent process.
  6. When later used for account or trading operations, the malicious CLI can inspect supplied data, manipulate command behavior, alter trade parameters, or attempt to access wallet-related environment variables and local confi ...[truncated 787 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically reviewed version, for example hyperscaled==X.Y.Z.
  2. Publish and enforce a dependency lockfile that includes all transitive dependencies.
  3. Require cryptographic hashes during installation, such as through a hashed requirements file and pip install --require-hashes.
  4. Use an explicit, trusted package index and disable unintended fallback indexes to reduce dependency-confusion risk.
  5. Verify package provenance, publisher identity, signatures or attestations, and release integrity before installation.
  6. Avoid automatic installation during skill execution. Require informed user confirmation and clearly identify the package source and pinned version.
  7. Install into an isolated virtual environment or sandbox with minimal filesystem, credential, and network access.
  8. Review the pinned package and its dependency tree before authorizing it to process wallet data or execute trades.
  9. Separate read-only account operations from trade-capable operations and grant only the minimum credentials required for each action.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description includes broad everyday terms like 'position', 'order', and 'balance', which can cause the skill to activate in unrelated conversations. Because this skill can facilitate sensitive financial actions, unintended invocation increases the risk of unnecessary account lookups or initiating trade-related flows in the wrong context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.