Back to skill

Security audit

Perp Lobster

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is purpose-aligned, but it asks users to run mutable remote trading code with wallet credentials and on-chain fee approval without enough integrity controls or warnings.

Review this carefully before installing. Use only a low-value subaccount, verify the upstream repository and dependencies yourself, avoid main-wallet credentials, and require clear confirmation before fee approvals, trades, bot starts, and emergency-stop actions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:95
Finding

Execution of Mutable, Unreviewed Remote Trading Code and Dependencies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

4. User must configure credentials (you cannot do this for them). Tell them:

text
Edit the .env file with your Hyperliquid credentials:
  nano perplobster/.env

Fill in:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

4. User must configure credentials (you cannot do this for them). Tell them:

text
Edit the .env file with your Hyperliquid credentials:
  nano perplobster/.env

Fill in:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The builder-fee approval step is an actual on-chain wallet action, but the instructions frame it like routine setup without a clear warning about transaction effects, permissions, or possible cost. In a trading skill connected to user funds, that omission is especially risky because it may lead users to authorize blockchain actions they do not fully understand.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The help trigger is defined too broadly for a high-risk trading skill, making accidental invocation more likely during ordinary conversation. In this context, broad intent matching can cause the agent to switch into operational trading/setup behavior unexpectedly, increasing the chance of unsafe command execution paths.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
## Security Rules

- **NEVER ask the user to paste their private key in chat.** The user must edit the `.env` file themselves.
- **NEVER read, cat, echo, or display the contents of `.env`** or any file containing credentials.
- The `.env` file stays local and is excluded from git via `.gitignore`.
- Always show the user what a script does (via `cat`) and get their approval before running it for the first time.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The emergency stop command is presented as a quick fix without explaining what actions it takes, such as canceling orders or closing positions. In a live trading environment, undocumented emergency automation can have financially significant side effects if invoked hastily or mistakenly.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The setup instructions tell the user that the script sends 'no data externally,' but the documented flow clones from GitHub and then installs dependencies, which inherently performs network activity and may fetch third-party code. This is dangerous because it gives the user a false sense of safety about external communications and supply-chain exposure during setup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.