Back to skill

Security audit

Tiger Trading

Security checks for vulnerabilities and agentic risk

Overview

This is a real brokerage trading skill whose purpose is disclosed, but it handles highly sensitive keys and can submit orders without enough built-in safeguards.

Review this skill carefully before installing. Use only a paper-trading or simulated Tiger environment unless you intentionally want live trading, do not paste private keys into chats or command lines, prefer a protected key file or secret manager, and require a manual order review before any buy, sell, or cancellation action.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tiger_client.py:195
Finding

Brokerage Private Key Exposure Through Command-Line Arguments and Agent-Generated Content

Content
View full analysis

Vulnerability Details

File Location: scripts/tiger_client.py:195,222; additionally documented in SKILL.md:17,35-42
Vulnerability Type: Sensitive credential exposure
Risk Level: High

Vulnerable Code and Documentation

scripts/tiger_client.py:195 accepts either a private-key path or the complete private-key contents as a command-line argument:

python
parser.add_argument('--private-key', required=True, help='私钥路径或内容')

scripts/tiger_client.py:222 then passes that command-line value to the trading client:

python
client = TigerClient(args.tiger_id, args.account, args.license, args.private_key)

SKILL.md:17 explicitly instructs users that they can provide private-key contents:

markdown
- `private_key`: 私钥内容或私钥文件路径

SKILL.md:35-42 demonstrates embedding private-key material directly in application code:

python
# 方式2: 使用私钥内容
client = TigerClient(
    tiger_id='YOUR_TIGER_ID',
    account='YOUR_ACCOUNT_ID',
    license='TBNZ',
    private_key='MIICXAIBAAKBgQ...'
)

Technical Analysis

A brokerage private key is an authentication secret that must not be placed in command-line arguments, generated source code, conversations, or other routinely retained plaintext channels.

The CLI's --private-key option accepts complete private-key contents. Command-line arguments may be recorded in shell history, process-monitoring systems, terminal logs, job execution records, or operating-system process metadata. Because this project is distributed as an AI Agent Skill, instructions encouraging users to provide key contents also create a risk that the key will be pasted into an Agent conversation or embedded in Agent-generated code. Conversations and generated files may subsequently be retained, synchronized, audited, or exposed to users and services that should not possess the trading credential.

Although the implementation also supports a private-key file ...[truncated 1410 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove support for supplying complete private-key contents through command-line arguments. Make --private-key accept only a file path, or replace it with an explicitly named option such as --private-key-file.
  2. Prefer retrieval from an operating-system keychain, hardware-backed key store, protected file descriptor, or established secret-management service.
  3. Update SKILL.md to warn users never to paste brokerage private keys into Agent conversations, prompts, shell commands, or source code.
  4. Remove the direct private-key-content example and replace it with a protected file or secret-manager example.
  5. Validate private-key file ownership and permissions before use, rejecting files accessible to unauthorized users where the platform supports such checks.
  6. Ensure application and SDK errors are sanitized so that private-key contents and sensitive configuration cannot be included in returned exception messages or logs.
  7. Document credential rotation and revocation procedures, and advise users to rotate any key previously supplied through a conversation or command-line argument.
  8. If non-file secret input is essential, read it from a non-echoing interactive prompt or protected standard input rather than from process arguments, while ensuring that automation systems do not log the input stream.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly supports buy/sell orders and order cancellation for a brokerage account, but the description does not prominently warn that these actions may affect real funds, positions, or live orders. In a trading context, insufficient disclosure increases the risk of accidental high-impact financial actions by users or downstream agents that invoke the skill without understanding execution consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code submits live trade orders immediately with user-supplied symbol, side, quantity, type, and price, without any built-in confirmation, preview, or safety interlock. In a trading skill, that raises the risk of accidental or manipulated order execution, which can directly cause financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to provide a private key and even suggests pasting raw key material directly, without warning about secret handling, storage, logging, or reuse risks. This is dangerous because private keys are highly sensitive credentials that may be exposed through chat history, terminal history, logs, screenshots, or insecure files, enabling unauthorized brokerage access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI accepts a private key directly as an argument, including raw key material, which is highly sensitive because command-line arguments are often exposed through shell history, process listings, job logs, or orchestration metadata. In the context of a trading client, compromise of this credential can enable unauthorized access and potentially fraudulent trading actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest says the skill supports order management including order viewing and cancellation, but the executable CLI in this file only wires up account, positions, balance, and order placement commands. Although the class implements get_orders and cancel_order, the documented runnable interface here does not actually expose those claimed capabilities.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.