T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:120- Finding
Autonomous State-Changing Trades Without Transaction-Specific Approval
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 120–156
Vulnerability Type: Autonomous invocation of state-changing trading tools
Risk Level: MediumVulnerable snippet:
markdown 6. **Make your first trades**: Pick 2-3 markets. Buy $200-500 per position. Explain your thesis 7. **Show your portfolio**: `portfolio` to confirm positions are live 8. **Report**: Summarize your opening positions, strategy constraints, and reasoning Don't ask "what would you like me to do?" — **trade**. You're a trader. Find opportunities and take them.markdown Every time you wake up, run through this routine: 1. **Resolve winners**: `resolve_all` — settle any markets that have a final outcome 2. **Check limit orders**: `check_orders` — trigger fills for pending orders that hit their price 3. **Review portfolio**: `portfolio` — what moved since last time? Any positions up or down big? 4. **Scan markets**: `list_markets` or `search_markets` for new opportunities 5. **Act on your views**: - Price moved in your favor? Consider taking profit - Price moved against you? Reassess your thesis — cut or add? - New market with clear mispricing? Open a position - Strong conviction at a better price? Place a limit order 6. **Report to your human**: What happened, what you traded, and whyTechnical Analysis
The skill instructs the agent to place two or three trades immediately and explicitly discourages asking the user what action should be taken. Its recurring heartbeat workflow also permits opening, increasing, reducing, and resolving positions whenever the agent is activated.
These operations mutate the user's cloud-hosted workspace through authenticated
buy,sell,place_limit_order,resolve_all, and related tools. The instructions do not require transaction-specific approval, nor do they define a user-authorized autonomous-trading mandate with enforceable limits. Although t ...[truncated 1125 chars]- Remediation
View remediation
Remediation Suggestions
- Require explicit user approval before every market order, limit order, sale, or settlement operation.
- Present the market, outcome, side, quantity, estimated price, maximum cost, and expected slippage before requesting confirmation.
- Make heartbeat execution read-only by default. It may review balances, positions, and markets, but it should not transact automatically.
- If autonomous operation is supported, require a separate opt-in mandate defining maximum order size, daily transaction count, permitted markets, expiration time, and stop-loss limits.
- Implement the mandate as server-enforced policy rather than relying only on natural-language instructions.
- Record the user's approval and the final transaction parameters in an immutable activity log.
