Back to skill

Security audit

Aevo Trading Skill

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate AEVO trading helper, but it asks for highly sensitive trading and private-key credentials and can place real orders through an externally installed MCP server.

Review this skill carefully before installing. Prefer testnet or read-only credentials first, pin and verify the MCP server package before use, avoid pasting wallet private keys into chat, use limited and revocable AEVO keys, and only enable live trading after you understand that confirmed actions can place or cancel real orders and affect funds.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
README.md:15
Finding

Unpinned Third-Party MCP Package Executes with Trading Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:40
Finding

Skill Directs Users to Submit Private Keys Through the AI and MCP Tool Channel

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to ask users for API secrets and private keys in-session, including signing and wallet private keys, but does not warn users not to paste sensitive secrets into chat or redirect them to a secure credential entry flow. This is especially dangerous in a trading skill with live account write access because exposure of these credentials can lead to unauthorized trades, account takeover, and potential loss of funds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises live order execution, portfolio management, and use of trading credentials, but it does not prominently warn that connecting to mainnet tools can place real orders and directly affect user funds. In an AI-agent context, users may assume actions are informational unless explicitly told otherwise, increasing the risk of unintended trades or destructive account actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to activate the skill for generic crypto trading, derivatives, volatility, and portfolio discussions even when the user did not intend to use AEVO or connect exchange tools. In this context, over-triggering is risky because the skill has read/write trading capabilities and may steer the assistant into credential collection or potentially destructive account actions in the wrong conversation context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example gives concrete trading recommendations such as directional bias, perp positioning guidance, and options strategies without any warning about financial risk, suitability, or the possibility of loss. In a skill explicitly designed for trading and order execution on a derivatives platform, this can encourage users to act on speculative advice as if it were safe or personalized, increasing the chance of harmful financial decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file explicitly instructs users to move from planning and previewing to aevo_execute_strategy with dry_run=false, which places real orders, but it provides no accompanying warning about financial loss, live execution, or the need for explicit confirmation. In a trading skill—especially one involving multi-leg options strategies with leverage and volatility exposure—omitting execution-risk messaging increases the chance of accidental or insufficiently informed real-money trades.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly exposes a tool that stores highly sensitive secrets in session state, including API secrets, wallet private keys, and signing keys, but it does not provide an explicit warning about the sensitivity, retention, or misuse risk of that data. In an AI-agent context, this is dangerous because users may paste live credentials into a conversational workflow without understanding that they are being stored for later authenticated trading actions, increasing the risk of secret exposure and unauthorized account activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The registration flow states that returned credentials are auto-stored when store_credentials=true by default, but the documentation does not clearly warn users that newly issued API credentials may be persisted in session state automatically. In this trading skill, automatic storage materially increases risk because the same session also exposes real order-placement and account-management tools, so silently retained credentials could be used for unintended or unauthorized trading actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.