Back to skill

Security audit

vibe-trading

Security checks for vulnerabilities and agentic risk

Overview

This finance toolkit is largely disclosed and purpose-aligned, but it should be reviewed because it documents persistent, wildcard-enabled loading of arbitrary external MCP tools.

Install only if you are comfortable with a broad finance agent. Do not enable arbitrary MCP servers or wildcard tool access unless you fully trust the server and its command, and keep broker/OAuth credentials limited to read-only or paper profiles unless you intentionally opt into higher-risk trading access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents a generic MCP client path that can load arbitrary local subprocesses or remote MCP servers, including wildcard-enabled tool exposure. That substantially expands the trust boundary beyond finance research and can let the agent invoke non-finance capabilities with filesystem, network, or trading side effects if an operator enables them.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill instructs users to create persistent configuration at ~/.vibe-trading/agent.json that defines executable commands, arguments, and enabled remote tools. Persistent agent config can outlive a session and silently alter future agent behavior, increasing the risk of long-term unauthorized tool execution if the config is modified or socially engineered.

Content

Scanner excerpt · SKILL.md (reported line 233)May include surrounding context.

Setup

Create ~/.vibe-trading/agent.json:

json
{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

md
"mcpServers": {
    "ibkr": {
      "type": "streamableHttp",
      "url": "https://api.ibkr.com/v1/api/mcp-public",
      "auth": {
        "type": "oauth",
        "scopes": ["mcp.read"],

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example workflow explicitly encourages using write_file() to create local files but does not warn about overwriting existing files or restricting output paths. In an agent setting, that can lead to unintended modification of local data or project files if prompts are ambiguous or maliciously crafted.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest emphasizes research, backtesting, factor analysis, and market-data workflows, but the tool list includes an unrestricted file-writing primitive. While useful for strategy workflows, generic file creation/modification is broader than the finance-analysis purpose and enables side effects unrelated to research itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.