Back to skill

Security audit

Crypto Self-Learning

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local crypto trade journal and rules generator; it stores trading data and can update an agent memory file, but those behaviors are disclosed and aligned with its purpose.

Install only if you are comfortable storing trade history locally in plaintext and letting generated trading rules be written into an agent memory file. Use the dry-run mode and review the target MEMORY.md changes before applying them, especially because those rules may influence future trading decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code only analyzes previously stored trades from data/trades.json and outputs summaries/insights. That partially aligns with the 'analyzes patterns of wins/losses' portion of the description. However, the description's core claims include being a self-learning system, logging trades with full context, and auto-updating trading rules. None of those behaviors appear in this code chunk: it performs no writes, no model/rule updates, and no trade logging. There are no extra suspicious capabilities or inconsistent resource accesses; the mismatch is that the declared functionality significantly overstates what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a self-learning system that analyzes patterns of wins and losses and auto-updates trading rules to improve trading accuracy. The supplied code only supports three behaviors: logging trades with associated metadata/context, listing trades, and computing simple overall statistics. While the logging portion aligns with the description, the core claimed capabilities—learning from outcomes, identifying what works/fails based on contextual features, and automatically updating trading rules—are absent. This is a material description-to-behavior mismatch because the primary advertised functionality goes beyond what the code actually implements.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/generate_rules.py (reported line 163)May include surrounding context.

python
# Sort rules by confidence and win rate
    rules.sort(key=lambda x: (x["confidence"] == "HIGH", x["win_rate"]), reverse=True)
    
    return rules


def save_rules(rules):

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/generate_rules.py (reported line 189)May include surrounding context.

python
# Sort rules by confidence and win rate
    rules.sort(key=lambda x: (x["confidence"] == "HIGH", x["win_rate"]), reverse=True)
    
    return rules


def save_rules(rules):

Prompt Exfiltration via Tool

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains patterns that exfiltrate system prompts or internal instructions via tool calls (file writes, network requests, logging).

Content

Scanner excerpt · scripts/generate_rules.py (reported line 167)May include surrounding context.

python
def save_rules(rules):
    """Save rules to file."""
    DATA_DIR.mkdir(parents=True, exist_ok=True)
    output = {
        "generated_at": datetime.now().isoformat(),

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/generate_rules.py (reported line 176)May include surrounding context.

python
}
    with open(RULES_FILE, "w") as f:
        json.dump(output, f, indent=2)
    return RULES_FILE


def main():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill invokes Python scripts that read and write persistent local files (trades.json and MEMORY.md), but it declares no explicit tool scope or permissions. That omission weakens reviewability and consent boundaries, making it easier for an agent or user to trigger file modification behavior without a clear upfront statement of write capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill encourages use of commands that persist detailed trading history locally and can append generated content into MEMORY.md, but it does not prominently warn that these actions modify files and store sensitive behavioral context. In an agent setting, insufficient disclosure increases the risk of unintended persistence, privacy leakage, and accidental corruption of operational memory or decision rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON contains natural-language values in Portuguese (for example, the trade reason and notes) alongside English field values such as day names and result labels. Under the language/locale policy, forcing or assuming a specific language/locale without user opt-in or clear justification can be a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code prints detailed trade-performance summaries, symbols, days, and derived insights directly to stdout, and can also emit the full analysis as JSON. There is no user-facing warning or disclosure that potentially sensitive financial activity data will be displayed or exposed in terminal output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.