T09 · Insecure Skill Coding Practices
- Location
SKILL.md:118- Finding
Trading 212 credentials may be transmitted to an arbitrary base URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent Trading 212 API guide, but it needs Review because it can place real-money trades and has credential-destination and cache-handling risks.
Install only if you are comfortable letting an agent access your Trading 212 account. Use DEMO first, require explicit confirmation before any live order or cancellation, avoid pre-setting T212_AUTH_HEADER with a custom T212_BASE_URL, use only the official live.trading212.com or demo.trading212.com hosts, and do not rely on the shared /tmp instrument cache for trade decisions.
SKILL.md:118Trading 212 credentials may be transmitted to an arbitrary base URL
SKILL.md:566Predictable shared temporary cache permits symlink overwrite and metadata poisoning
The skill enables real-money trading and order cancellation, both of which are high-impact, irreversible financial actions, yet the warning is not sufficiently prominent at the top-level usage boundary. In an agent setting, weak gating around destructive financial operations increases the chance of accidental or misunderstood execution.
The skill includes a direct DELETE operation for order cancellation, a state-changing and potentially financially harmful action, without enforcing a strong confirmation or validation workflow at the point of use. In an autonomous agent context, parameter misuse or ambiguity around the order ID could cause unintended cancellation of a live order.
DELETE /api/v0/equity/orders/{id} (50 req/min)
curl -X DELETE -H "Authorization: $T212_AUTH_HEADER" \
The manifest description says the skill should be used when the user asks to "buy stock", "sell shares", "check my balance", or "view portfolio". These phrases are broad, common requests that could overlap with non-Trading-212 contexts, and the description does not provide exclusion conditions or tighter scope constraints.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
fi
If any complete set is present, skip the full setup and proceed with API calls; when making requests, use the resolution order in "Making Requests" below (pick the pair that matches the user's account context when multiple sets exist). Do not ask the user to run derivation one-liners or merge keys into a header. Only guide users through the full setup process below when no complete credential set exists.
> **Important:** Before making any API calls, always ask the user which environment they want to use: **LIVE** (real money) or **DEMO** (paper trading). Do not assume the environment.
The example embeds a full-looking API key and secret directly in a shell command, normalizing unsafe handling of credentials and encouraging users to paste secrets into prompts, terminals, or shell history. This materially increases the risk of secret leakage through logs, history files, screenshots, or transcript storage.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
### Common Auth Errors
| Code | Cause | Solution |
| ---- | -------------------- | --------------------------------------------------------------------------------------------- |
| 401 | Invalid credentials | Check API key/secret, ensure no extra whitespace |
| 401 | Environment mismatch | **LIVE API keys don't work with DEMO and vice versa** - verify key matches target environment |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Buy 5 shares
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
-H "Content-Type: application/json" \
"$T212_BASE_URL/api/v0/equity/orders/market" \
-d '{"ticker": "AAPL_US_EQ", "quantity": 5}'
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
**Request Fields:**
| Field | Type | Required | Description |
| --------------- | ------- | -------- | ---------------------------------------------------------------------------------------------------------------------- |
| `ticker` | string | Yes | Instrument ticker (e.g., `AAPL_US_EQ`) |
| `quantity` | number | Yes | Positive for buy, negative for sell |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| Field | Type | Required | Description |
| --------------- | ------- | -------- | ---------------------------------------------------------------------------------------------------------------------- |
| `ticker` | string | Yes | Instrument ticker (e.g., `AAPL_US_EQ`) |
| `quantity` | number | Yes | Positive for buy, negative for sell |
| `extendedHours` | boolean | No | Set `true` to allow execution in pre-market (4:00-9:30 ET) and after-hours (16:00-20:00 ET) sessions. Default: `false` |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| Field | Type | Required | Description |
| --------------- | ------- | -------- | ---------------------------------------------------------------------------------------------------------------------- |
| `ticker` | string | Yes | Instrument ticker (e.g., `AAPL_US_EQ`) |
| `quantity` | number | Yes | Positive for buy, negative for sell |
| `extendedHours` | boolean | No | Set `true` to allow execution in pre-market (4:00-9:30 ET) and after-hours (16:00-20:00 ET) sessions. Default: `false` |
**Response:**
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST /api/v0/equity/orders/limit (1 req/2s)
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
-H "Content-Type: application/json" \
"$T212_BASE_URL/api/v0/equity/orders/limit" \
-d '{"ticker": "AAPL_US_EQ", "quantity": 5, "limitPrice": 150.00, "timeValidity": "DAY"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST /api/v0/equity/orders/stop (1 req/2s)
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
-H "Content-Type: application/json" \
"$T212_BASE_URL/api/v0/equity/orders/stop" \
-d '{"ticker": "AAPL_US_EQ", "quantity": -5, "stopPrice": 140.00, "timeValidity": "GOOD_TILL_CANCEL"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST /api/v0/equity/orders/stop_limit (1 req/2s)
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
-H "Content-Type: application/json" \
"$T212_BASE_URL/api/v0/equity/orders/stop_limit" \
-d '{"ticker": "AAPL_US_EQ", "quantity": -5, "stopPrice": 145.00, "limitPrice": 140.00, "timeValidity": "DAY"}'
The skill instructs storing the full instruments dataset in /tmp, which is commonly world-readable or shared across users/processes on multi-tenant systems. Even if the dataset is not secret, writing API-derived data to a predictable shared path can enable unintended disclosure, tampering, or cache poisoning that could affect later trading decisions.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Request report: POST /api/v0/equity/history/exports (1 req/30s)
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
-H "Content-Type: application/json" \
"$T212_BASE_URL/api/v0/equity/history/exports" \
-d '{
The manifest covers exporting transactions and generating CSV reports, so requesting report generation via the Trading 212 API is in scope. However, the documented workflow then fetches the resulting file from a separate trading212-reports.s3.amazonaws.com download URL, adding third-party network access not explicitly described in the skill purpose. This is a mild context expansion rather than a core mismatch.
No suspicious patterns detected.