T08 · Insecure Dependencies
- Location
README.md:15- Finding
Unpinned Third-Party MCP Package Executes with Trading Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a legitimate AEVO trading helper, but it asks for highly sensitive trading and private-key credentials and can place real orders through an externally installed MCP server.
Review this skill carefully before installing. Prefer testnet or read-only credentials first, pin and verify the MCP server package before use, avoid pasting wallet private keys into chat, use limited and revocable AEVO keys, and only enable live trading after you understand that confirmed actions can place or cancel real orders and affect funds.
README.md:15Unpinned Third-Party MCP Package Executes with Trading Credentials
SKILL.md:40Skill Directs Users to Submit Private Keys Through the AI and MCP Tool Channel
The skill instructs the agent to ask users for API secrets and private keys in-session, including signing and wallet private keys, but does not warn users not to paste sensitive secrets into chat or redirect them to a secure credential entry flow. This is especially dangerous in a trading skill with live account write access because exposure of these credentials can lead to unauthorized trades, account takeover, and potential loss of funds.
The README advertises live order execution, portfolio management, and use of trading credentials, but it does not prominently warn that connecting to mainnet tools can place real orders and directly affect user funds. In an AI-agent context, users may assume actions are informational unless explicitly told otherwise, increasing the risk of unintended trades or destructive account actions.
The trigger conditions are broad enough to activate the skill for generic crypto trading, derivatives, volatility, and portfolio discussions even when the user did not intend to use AEVO or connect exchange tools. In this context, over-triggering is risky because the skill has read/write trading capabilities and may steer the assistant into credential collection or potentially destructive account actions in the wrong conversation context.
The example gives concrete trading recommendations such as directional bias, perp positioning guidance, and options strategies without any warning about financial risk, suitability, or the possibility of loss. In a skill explicitly designed for trading and order execution on a derivatives platform, this can encourage users to act on speculative advice as if it were safe or personalized, increasing the chance of harmful financial decisions.
The file explicitly instructs users to move from planning and previewing to aevo_execute_strategy with dry_run=false, which places real orders, but it provides no accompanying warning about financial loss, live execution, or the need for explicit confirmation. In a trading skill—especially one involving multi-leg options strategies with leverage and volatility exposure—omitting execution-risk messaging increases the chance of accidental or insufficiently informed real-money trades.
The documentation explicitly exposes a tool that stores highly sensitive secrets in session state, including API secrets, wallet private keys, and signing keys, but it does not provide an explicit warning about the sensitivity, retention, or misuse risk of that data. In an AI-agent context, this is dangerous because users may paste live credentials into a conversational workflow without understanding that they are being stored for later authenticated trading actions, increasing the risk of secret exposure and unauthorized account activity.
The registration flow states that returned credentials are auto-stored when store_credentials=true by default, but the documentation does not clearly warn users that newly issued API credentials may be persisted in session state automatically. In this trading skill, automatic storage materially increases risk because the same session also exposes real order-placement and account-management tools, so silently retained credentials could be used for unintended or unauthorized trading actions.
No suspicious patterns detected.