Back to skill

Security audit

UnifAI Trading Suite

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is mostly coherent as a market-analysis tool, but it includes under-scoped credential-backed tool execution and misleading trade-related behavior that should be reviewed before use.

Review this before installing. Use dedicated low-privilege API keys, do not run the web server on a public interface, and do not rely on any trade or portfolio action unless you have verified that it is read-only, simulated, or protected by explicit human confirmation and platform-side limits.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/api/server.py:19
Finding

Unauthenticated API Exposes Credential-Backed Dynamic Tool Execution

Content
View full analysis
TradingAgent: """Get or create an agent for a session.""" if session_id not in agents: agents[session_id] = TradingAgent() return agents[session_id] ``` ```python # src/api/server.py app.add_middleware( CORSMiddleware, allow_origins=["*"], allow_credentials=True, allow_methods=["*"], allow_headers=["*"], ) ``` ```python # src/api/server.py @app.post("/api/chat", response_model=ChatResponse) async def chat(request: ChatRequest): """Send a message to the trading agent.""" try: agent = get_or_create_agent(request.session_id) # Clear history for each chat to avoid accumulation issues agent.clear_history() response = await agent.chat(request.message) return ChatResponse(response=response, session_id=request.session_id) except Exception as e: raise HTTPException(status_code=500, detail=str(e)) ``` ```python # src/api/server.py if __name__ == "__main__": import uvicorn uvicorn.run(app, host="0.0.0.0", port=8000) ``` ```python # src/agents/trading_agent.py async def get_tools(self) -> list: """Get dynamic tools from UnifAI.""" return await self.tools.get_tools(dynamic_tools=True) async def execute_tool_calls(self, tool_calls) -> list: """Execute tool calls and return results.""" return await self.tools.call_tools(tool_calls) ``` ```python # src/agents/trading_agent.py available_tools = await self.get_tools() # Allow multiple rounds of tool calls max_iterations = 5 for _ in range(max_iterations): response = await litellm.acompletion( model=self.model, ...[truncated 3196 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/api/static/index.html:478
Finding

Stored and Reflected DOM XSS Through Unsanitized Chat Rendering

Content
View full analysis
$2') .replace(/`([^`]+)`/g, '$1') .replace(/\*\*([^*]+)\*\*/g, '$1') .replace(/\*([^*]+)\*/g, '$1') .replace(/^## (.+)$/gm, '

$1

') .replace(/^- (.+)$/gm, '
  • $1
  • ') .replace(/\n/g, '
    '); div.innerHTML = formatted; messages.appendChild(div); messages.scrollTop = messages.scrollHeight; } ``` ### Technical Analysis `addMessage()` accepts content from several untrusted sources, including user input, LLM responses, remote UnifAI tool results, market data, and API error details. It applies regular-expression substitutions that add formatting tags but never HTML-escapes the original content. Assigning the resulting string to `innerHTML` causes the browser to parse attacker-controlled HTML. The formatting replacements are not an HTML sanitizer and do not remove dangerous elements, event-handler attributes, malicious links, or other executable browser content. Because assistant output can incorporate data retrieved from third-party tools, exploitation does not necessarily require the local user to type the payload directly. A malicious or compromised remote data source could place an HTML payload in a market title, social-media result, news snippet, or tool error that the model reproduces in its answer. ### Attack Path 1. An attacker submits HTML-bea ...[truncated 1359 chars]
    Remediation
    View remediation

    T07 · Tool Hijacking and Spoofing

    Error
    Location
    src/toolkits/trading_toolkit.py:84
    Finding

    Trade Execution Tool Returns Fabricated Success Without Executing a Trade

    Content
    View full analysis
    Remediation
    View remediation

    T08 · Insecure Dependencies

    Warning
    Location
    pyproject.toml:6
    Finding

    Unpinned Privileged Dependencies Produce Non-Reproducible Builds

    Content
    View full analysis
    =0.3.3", "litellm>=1.40.0", "google-generativeai>=0.5.0", "aiohttp>=3.9.0", "httpx>=0.27.0", "web3>=6.15.0", "pydantic>=2.6.0", "python-dotenv>=1.0.0", ] ``` ```text # requirements.txt unifai-sdk>=0.3.3 # LLM Integration litellm>=1.80.5 google-generativeai>=0.8.0 # Async HTTP aiohttp>=3.9.0 httpx>=0.27.0 # On-chain Analysis web3>=6.15.0 # Data Validation pydantic>=2.6.0 # Utilities python-dotenv>=1.0.0 # API Server fastapi>=0.109.0 uvicorn>=0.27.0 # Testing pytest>=8.0.0 pytest-asyncio>=0.23.0 ``` ### Technical Analysis All dependencies use open-ended minimum-version constraints. A fresh installation can therefore select future releases that were never reviewed or tested with this project. Several dependencies operate with particularly sensitive capabilities: - UnifAI handles credential-backed remote tool discovery and execution. - LiteLLM and Google Generative AI transmit prompts and tool context to model providers. - HTTP libraries perform outbound network requests. - Web3 handles blockchain-related data and may later be used for wallet interactions. - FastAPI and Uvicorn expose the application over the network. The two dependency manifests also disagree on minimum versions, including different LiteLLM and Google Generative AI baselines. This can cause development, test, and production environments to resolve materially different software sets. This finding does not establish that any currently named package is malicious. The risk arises from non-reproducible resolution of privileged third-party code. ### Attack Path 1. A developer or deployment pipeline installs the project without a lockfile. 2. The package resolver selects the latest versions satisfyi ...[truncated 875 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    Findings (67)

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    97% confidence
    Finding

    If the skill can execute trades, access portfolio-like holdings, or register services while presenting itself merely as a trading-insights and sentiment tool, that is a severe trust-boundary violation. In this context, concealed financial-action or account-access capability is especially dangerous because it can directly cause monetary loss and expose sensitive account data under the guise of passive analysis.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    89% confidence
    Finding

    If the skill can execute trades, access portfolio-like holdings, or register services while presenting itself merely as a trading-insights and sentiment tool, that is a severe trust-boundary violation. In this context, concealed financial-action or account-access capability is especially dangerous because it can directly cause monetary loss and expose sensitive account data under the guise of passive analysis.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    90% confidence
    Finding

    If the skill can execute trades, access portfolio-like holdings, or register services while presenting itself merely as a trading-insights and sentiment tool, that is a severe trust-boundary violation. In this context, concealed financial-action or account-access capability is especially dangerous because it can directly cause monetary loss and expose sensitive account data under the guise of passive analysis.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    95% confidence
    Finding

    If the skill can execute trades, access portfolio-like holdings, or register services while presenting itself merely as a trading-insights and sentiment tool, that is a severe trust-boundary violation. In this context, concealed financial-action or account-access capability is especially dangerous because it can directly cause monetary loss and expose sensitive account data under the guise of passive analysis.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    93% confidence
    Finding

    If the skill can execute trades, access portfolio-like holdings, or register services while presenting itself merely as a trading-insights and sentiment tool, that is a severe trust-boundary violation. In this context, concealed financial-action or account-access capability is especially dangerous because it can directly cause monetary loss and expose sensitive account data under the guise of passive analysis.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    92% confidence
    Finding

    If the skill can execute trades, access portfolio-like holdings, or register services while presenting itself merely as a trading-insights and sentiment tool, that is a severe trust-boundary violation. In this context, concealed financial-action or account-access capability is especially dangerous because it can directly cause monetary loss and expose sensitive account data under the guise of passive analysis.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    89% confidence
    Finding

    If the skill can execute trades, access portfolio-like holdings, or register services while presenting itself merely as a trading-insights and sentiment tool, that is a severe trust-boundary violation. In this context, concealed financial-action or account-access capability is especially dangerous because it can directly cause monetary loss and expose sensitive account data under the guise of passive analysis.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    95% confidence
    Finding

    If the skill can execute trades, access portfolio-like holdings, or register services while presenting itself merely as a trading-insights and sentiment tool, that is a severe trust-boundary violation. In this context, concealed financial-action or account-access capability is especially dangerous because it can directly cause monetary loss and expose sensitive account data under the guise of passive analysis.

    Content

    No source excerpt is available for this finding.

    Possible Typosquatting: 'uvicorn' resembles popular package 'gunicorn'

    High
    Category
    Supply Chain
    Confidence
    70% confidence
    Finding

    Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

    Content

    No source excerpt is available for this finding.

    Memory Manipulation

    High
    Category
    Memory Poisoning
    Confidence
    80% confidence
    Finding

    Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

    Content

    Scanner excerpt · src/agents/basic_agent.py (reported line 82)May include surrounding context.

    python
    return assistant_message.content or ""
    
        def clear_history(self):
            """Clear conversation history."""
            self.conversation_history = []
    

    Memory Manipulation

    High
    Category
    Memory Poisoning
    Confidence
    80% confidence
    Finding

    Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

    Content

    Scanner excerpt · src/agents/trading_agent.py (reported line 539)May include surrounding context.

    python
    return assistant_message.content or ""
    
        def clear_history(self):
            """Clear conversation history."""
            self.conversation_history = []
    

    Memory Manipulation

    High
    Category
    Memory Poisoning
    Confidence
    80% confidence
    Finding

    Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

    Content

    Scanner excerpt · src/api/server.py (reported line 125)May include surrounding context.

    python
    return assistant_message.content or ""
    
        def clear_history(self):
            """Clear conversation history."""
            self.conversation_history = []
    

    Memory Manipulation

    High
    Category
    Memory Poisoning
    Confidence
    80% confidence
    Finding

    Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

    Content

    Scanner excerpt · src/agents/trading_agent.py (reported line 635)May include surrounding context.

    python
    print("")
        print("Commands:")
        print("  'quit'     - Exit")
        print("  'clear'    - Reset conversation")
        print("  'fed'      - Show Fed interest rate markets (Kalshi)")
        print("  'gdp'      - Show GDP/economics markets (Kalshi)")
        print("  'compare X'- Compare topic X across platforms")
    

    Memory Manipulation

    High
    Category
    Memory Poisoning
    Confidence
    80% confidence
    Finding

    Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

    Content

    Scanner excerpt · src/api/server.py (reported line 80)May include surrounding context.

    python
    """Send a message to the trading agent."""
        try:
            agent = get_or_create_agent(request.session_id)
            # Clear history for each chat to avoid accumulation issues
            agent.clear_history()
            response = await agent.chat(request.message)
            return ChatResponse(response=response, session_id=request.session_id)
    

    Anti-Refusal Statement

    High
    Category
    Anti-Refusal
    Confidence
    70% confidence
    Finding

    Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

    Content

    Scanner excerpt · src/signals/social.py (reported line 72)May include surrounding context.

    python
    2. Extract and structure the relevant signals
    3. Return the data in a clean JSON format
    
    Always respond with valid JSON containing the extracted data."""
    
        def __init__(self, api_key: str | None = None, model: str | None = None):
            self.api_key = api_key or os.getenv("UNIFAI_AGENT_API_KEY")
    

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    This documentation explicitly describes live trading and order-placement capabilities, including market and limit orders, but does not prominently warn that these actions can affect real accounts and cause irreversible financial loss. In an agent-skill context, omission of safety boundaries increases the chance that users or downstream agents invoke trading actions as if they were informational only.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The installation and usage instructions encourage copying and running prediction-market skills without clearly stating that API-backed commands may interact with live market accounts. Because the skills are presented as easy CLI utilities, users may execute them in environments containing valid credentials and unintentionally trigger real-money operations.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The README presents an AI agent that can create and execute trading strategies across prediction market platforms, but it does not warn users about financial loss, irreversible market actions, or the need for human review before live use. In a skill intended for agent reuse, this omission can encourage unsafe deployment of autonomous trading behavior by making high-risk functionality appear routine and low-friction.

    Content

    No source excerpt is available for this finding.

    Undeclared Tool Scope

    Medium
    Category
    MCP Least Privilege
    Confidence
    92% confidence
    Finding

    The skill metadata declares required environment variables and presents commands that invoke Python tools, which implies code execution with environment and likely network access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens sandboxing and review because operators cannot easily tell what capabilities the skill expects, increasing the chance of unintended secret exposure or network use.

    Content

    No source excerpt is available for this finding.

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    90% confidence
    Finding

    The example invocations are phrased as ordinary conversational crypto questions, which can cause the assistant to trigger this user-invocable skill when a user is merely discussing a topic rather than explicitly requesting tool use. Because the skill queries external services and produces trading-related analysis, unintended activation can lead to unnecessary external data disclosure, unexpected API usage, and overreliance on tool-generated financial signals.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    89% confidence
    Finding

    This CLI sends user-provided tokens, queries, and keywords into network-backed processors without any explicit user-facing disclosure at the point of use that inputs may be transmitted to external APIs or third-party services. In a trading/social-signals context, user queries may reveal research interests, trading strategies, or sensitive watchlist data, so silent transmission creates a meaningful privacy and operational-security risk even though it is not direct code execution.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    The chat method forwards the accumulated conversation history, including raw user messages, to litellm.acompletion, which transmits data to an external model provider. This file does not present any warning, consent step, or user-facing notice that their prompts will be sent to third-party services.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The code executes model-requested dynamic tool calls directly through self.tools.call_tools(...) with no allowlist, argument validation, risk classification, or user confirmation. In an agent that loads dynamic tools from a remote source, prompt injection or model misbehavior could trigger unintended actions, data access, or transactions, which is especially dangerous in a trading context.

    Content

    No source excerpt is available for this finding.

    Description-Behavior Mismatch

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The manifest describes an 'AI-powered trading insights suite' focused on prediction markets and social sentiment. However, the system prompt explicitly tells the model to 'execute trades' and exposes Polymarket tools for 'trading', which goes beyond insights/analysis into transactional market actions.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The interactive session accepts arbitrary user queries and sends them to external LLM/tool providers without clearly warning users that their prompts may be transmitted to third-party services. This can expose sensitive financial interests, trading strategies, or personal data if a user assumes the interaction is local or first-party only.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.