T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:95- Finding
Execution of Mutable, Unreviewed Remote Trading Code and Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This trading skill is purpose-aligned, but it asks users to run mutable remote trading code with wallet credentials and on-chain fee approval without enough integrity controls or warnings.
Review this carefully before installing. Use only a low-value subaccount, verify the upstream repository and dependencies yourself, avoid main-wallet credentials, and require clear confirmation before fee approvals, trades, bot starts, and emergency-stop actions.
SKILL.md:95Execution of Mutable, Unreviewed Remote Trading Code and Dependencies
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
4. User must configure credentials (you cannot do this for them). Tell them:
Edit the .env file with your Hyperliquid credentials:
nano perplobster/.env
Fill in:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
4. User must configure credentials (you cannot do this for them). Tell them:
Edit the .env file with your Hyperliquid credentials:
nano perplobster/.env
Fill in:
The builder-fee approval step is an actual on-chain wallet action, but the instructions frame it like routine setup without a clear warning about transaction effects, permissions, or possible cost. In a trading skill connected to user funds, that omission is especially risky because it may lead users to authorize blockchain actions they do not fully understand.
The help trigger is defined too broadly for a high-risk trading skill, making accidental invocation more likely during ordinary conversation. In this context, broad intent matching can cause the agent to switch into operational trading/setup behavior unexpectedly, increasing the chance of unsafe command execution paths.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Security Rules
- **NEVER ask the user to paste their private key in chat.** The user must edit the `.env` file themselves.
- **NEVER read, cat, echo, or display the contents of `.env`** or any file containing credentials.
- The `.env` file stays local and is excluded from git via `.gitignore`.
- Always show the user what a script does (via `cat`) and get their approval before running it for the first time.
The emergency stop command is presented as a quick fix without explaining what actions it takes, such as canceling orders or closing positions. In a live trading environment, undocumented emergency automation can have financially significant side effects if invoked hastily or mistakenly.
The setup instructions tell the user that the script sends 'no data externally,' but the documented flow clones from GitHub and then installs dependencies, which inherently performs network activity and may fetch third-party code. This is dangerous because it gives the user a false sense of safety about external communications and supply-chain exposure during setup.
No suspicious patterns detected.