Back to skill

Security audit

Trading212 API

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Trading 212 API guide, but it needs Review because it can place real-money trades and has credential-destination and cache-handling risks.

Install only if you are comfortable letting an agent access your Trading 212 account. Use DEMO first, require explicit confirmation before any live order or cancellation, avoid pre-setting T212_AUTH_HEADER with a custom T212_BASE_URL, use only the official live.trading212.com or demo.trading212.com hosts, and do not rely on the shared /tmp instrument cache for trade decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:118
Finding

Trading 212 credentials may be transmitted to an arbitrary base URL

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:566
Finding

Predictable shared temporary cache permits symlink overwrite and metadata poisoning

Content
View full analysis
**CACHE FIRST:** Always check `/tmp/t212_instruments.json` before calling the API. The instruments endpoint has a 50-second rate limit and returns ~5MB. Only call the API if cache is missing or older than 1 hour. ```bash # SEARCH_TERM = user query (e.g. TSLA, Tesla, AAPL, SAP) SEARCH_TERM="TSLA" CACHE_FILE="/tmp/t212_instruments.json" if [ -f "$CACHE_FILE" ] && [ $(($(date +%s) - $(stat -f %m "$CACHE_FILE" 2>/dev/null || stat -c %Y "$CACHE_FILE"))) -lt 3600 ]; then # Search ticker, name, or shortName fields jq --arg q "$SEARCH_TERM" '[.[] | select((.ticker // "" | test($q; "i")) or (.name // "" | test($q; "i")) or (.shortName // "" | test($q; "i")))]' "$CACHE_FILE" else curl -s -H "Authorization: $T212_AUTH_HEADER" \ "$T212_BASE_URL/api/v0/equity/metadata/instruments" > "$CACHE_FILE" fi ``` ``` The same unsafe cache pattern is repeated in `SKILL.md` lines 1115–1132. ### Technical Analysis The cache uses a fixed, predictable filename in the shared `/tmp` directory. The Skill neither creates a private directory nor verifies that the cache is a regular file owned by the current user. Shell redirection follows symbolic links, so writing API output with: ```bash ... > "$CACHE_FILE" ``` can overwrite the target of an attacker-created symlink if the Skill's process has permission to write that target. The read path is also vulnerable to cache poisoning. A local attacker can pre-create a sufficiently recent file at the expected path containing fabricated instrument records. The Skill then trusts that data during ticker lookup without validating its provenance or schema. Because ticker resolution informs later financial operations, poisoned metadata can misrepresent which instrument corresponds to a user's requested company or symbol. ### Attack Path #### Symli ...[truncated 1972 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables real-money trading and order cancellation, both of which are high-impact, irreversible financial actions, yet the warning is not sufficiently prominent at the top-level usage boundary. In an agent setting, weak gating around destructive financial operations increases the chance of accidental or misunderstood execution.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The skill includes a direct DELETE operation for order cancellation, a state-changing and potentially financially harmful action, without enforcing a strong confirmation or validation workflow at the point of use. In an autonomous agent context, parameter misuse or ambiguity around the order ID could cause unintended cancellation of a live order.

Content

Scanner excerpt · SKILL.md (reported line 463)May include surrounding context.

Cancel Order

DELETE /api/v0/equity/orders/{id} (50 req/min)

bash
curl -X DELETE -H "Authorization: $T212_AUTH_HEADER" \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says the skill should be used when the user asks to "buy stock", "sell shares", "check my balance", or "view portfolio". These phrases are broad, common requests that could overlap with non-Trading-212 contexts, and the description does not provide exclusion conditions or tighter scope constraints.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

fi

text

If any complete set is present, skip the full setup and proceed with API calls; when making requests, use the resolution order in "Making Requests" below (pick the pair that matches the user's account context when multiple sets exist). Do not ask the user to run derivation one-liners or merge keys into a header. Only guide users through the full setup process below when no complete credential set exists.

> **Important:** Before making any API calls, always ask the user which environment they want to use: **LIVE** (real money) or **DEMO** (paper trading). Do not assume the environment.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example embeds a full-looking API key and secret directly in a shell command, normalizing unsafe handling of credentials and encouraging users to paste secrets into prompts, terminals, or shell history. This materially increases the risk of secret leakage through logs, history files, screenshots, or transcript storage.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
### Common Auth Errors

| Code | Cause                | Solution                                                                                      |
| ---- | -------------------- | --------------------------------------------------------------------------------------------- |
| 401  | Invalid credentials  | Check API key/secret, ensure no extra whitespace                                              |
| 401  | Environment mismatch | **LIVE API keys don't work with DEMO and vice versa** - verify key matches target environment |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 330)May include surrounding context.

bash
# Buy 5 shares
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
  -H "Content-Type: application/json" \
  "$T212_BASE_URL/api/v0/equity/orders/market" \
  -d '{"ticker": "AAPL_US_EQ", "quantity": 5}'

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 350)May include surrounding context.

md
**Request Fields:**

| Field           | Type    | Required | Description                                                                                                            |
| --------------- | ------- | -------- | ---------------------------------------------------------------------------------------------------------------------- |
| `ticker`        | string  | Yes      | Instrument ticker (e.g., `AAPL_US_EQ`)                                                                                 |
| `quantity`      | number  | Yes      | Positive for buy, negative for sell                                                                                    |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 352)May include surrounding context.

md
| Field           | Type    | Required | Description                                                                                                            |
| --------------- | ------- | -------- | ---------------------------------------------------------------------------------------------------------------------- |
| `ticker`        | string  | Yes      | Instrument ticker (e.g., `AAPL_US_EQ`)                                                                                 |
| `quantity`      | number  | Yes      | Positive for buy, negative for sell                                                                                    |
| `extendedHours` | boolean | No       | Set `true` to allow execution in pre-market (4:00-9:30 ET) and after-hours (16:00-20:00 ET) sessions. Default: `false` |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 353)May include surrounding context.

md
| Field           | Type    | Required | Description                                                                                                            |
| --------------- | ------- | -------- | ---------------------------------------------------------------------------------------------------------------------- |
| `ticker`        | string  | Yes      | Instrument ticker (e.g., `AAPL_US_EQ`)                                                                                 |
| `quantity`      | number  | Yes      | Positive for buy, negative for sell                                                                                    |
| `extendedHours` | boolean | No       | Set `true` to allow execution in pre-market (4:00-9:30 ET) and after-hours (16:00-20:00 ET) sessions. Default: `false` |

**Response:**

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 385)May include surrounding context.

POST /api/v0/equity/orders/limit (1 req/2s)

bash
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
  -H "Content-Type: application/json" \
  "$T212_BASE_URL/api/v0/equity/orders/limit" \
  -d '{"ticker": "AAPL_US_EQ", "quantity": 5, "limitPrice": 150.00, "timeValidity": "DAY"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 405)May include surrounding context.

POST /api/v0/equity/orders/stop (1 req/2s)

bash
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
  -H "Content-Type: application/json" \
  "$T212_BASE_URL/api/v0/equity/orders/stop" \
  -d '{"ticker": "AAPL_US_EQ", "quantity": -5, "stopPrice": 140.00, "timeValidity": "GOOD_TILL_CANCEL"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 425)May include surrounding context.

POST /api/v0/equity/orders/stop_limit (1 req/2s)

bash
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
  -H "Content-Type: application/json" \
  "$T212_BASE_URL/api/v0/equity/orders/stop_limit" \
  -d '{"ticker": "AAPL_US_EQ", "quantity": -5, "stopPrice": 145.00, "limitPrice": 140.00, "timeValidity": "DAY"}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs storing the full instruments dataset in /tmp, which is commonly world-readable or shared across users/processes on multi-tenant systems. Even if the dataset is not secret, writing API-derived data to a predictable shared path can enable unintended disclosure, tampering, or cache poisoning that could affect later trading decisions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 934)May include surrounding context.

Request report: POST /api/v0/equity/history/exports (1 req/30s)

bash
curl -X POST -H "Authorization: $T212_AUTH_HEADER" \
  -H "Content-Type: application/json" \
  "$T212_BASE_URL/api/v0/equity/history/exports" \
  -d '{

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest covers exporting transactions and generating CSV reports, so requesting report generation via the Trading 212 API is in scope. However, the documented workflow then fetches the resulting file from a separate trading212-reports.s3.amazonaws.com download URL, adding third-party network access not explicitly described in the skill purpose. This is a mild context expansion rather than a core mismatch.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.