Back to skill

Security audit

backtest-expert

Security checks for vulnerabilities and agentic risk

Overview

This skill is a static backtesting guidance package with no executable code, credential handling, persistence, or hidden behavior.

Installers should treat this as educational backtesting methodology, not financial advice. Before using any strategy live, independently validate assumptions and remember that backtest results do not guarantee future performance and real-money trading can lose capital.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description defines activation in very broad terms such as 'developing, testing, stress-testing, or validating quantitative trading strategies' and 'when user asks about backtesting... or systematic trading development.' This can cause the skill to trigger on a wide range of generic trading discussions, increasing the chance of inappropriate routing, instruction bleed, or over-application of the skill in contexts where more specific controls or expertise boundaries are needed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file applies to SQP-2, which requires warnings when described behavior could affect user data, privacy, or system integrity. The document includes a decision point to 'Deploy' a strategy for live implementation, but it does not include an explicit caution that backtests do not guarantee live performance and that real-money trading carries risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.