Back to skill

Security audit

Backtest

Security checks for vulnerabilities and agentic risk

Overview

The skill is a finance backtesting helper, but it asks for command execution and file access while giving broad troubleshooting guidance, including administrator-level execution, without clear limits or user controls.

Review this skill carefully before installing. Use it only for specific backtesting tasks, avoid administrator privileges, approve any command or package installation explicitly, and do not provide API keys or sensitive financial files unless you understand exactly what will be read or executed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The skill claims it has removed risky code and improved security, but the same file also declares powerful capabilities such as exec and later documents command execution, file handling, and API/network troubleshooting. These contradictory assurances can mislead users or calling agents into trusting the skill too broadly and reducing scrutiny around higher-risk operations.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The troubleshooting guidance explicitly covers command execution failure and advises running with administrator privileges, despite the skill being presented as a backtesting engine. In context, the skill also declares the exec tool, so this broadens the operational scope into potentially dangerous local execution and privilege escalation patterns that are not justified by the stated finance-analysis purpose.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation text says to use the skill whenever the user needs backtesting-related functionality, which is overly broad and lacks concrete boundaries for sensitive actions. In a skill with read and exec tools, vague invocation criteria increase the chance the agent will apply the skill in contexts involving files, external APIs, or command execution without sufficiently narrow user intent.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The description highlights automation and structured processing but omits warnings that the skill may execute commands, handle files, and interact with external APIs or network resources. Because the skill advertises operational convenience while hiding risky side effects, users and orchestrators may underestimate the trust boundary and permit unsafe actions.

Static analysis

No suspicious patterns detected.