skills/ruvnet/ruflo/trader-signal/Gen Agent Trust Hub

trader-signal

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill initiates a download of the neural-trader package from the npm registry using npm install. It employs the --ignore-scripts flag, which is a recognized security measure to prevent the execution of potentially malicious scripts during the installation phase.\n- [REMOTE_CODE_EXECUTION]: The skill uses npx to execute the neural-trader package downloaded from the public registry. This allows the execution of external code that is not verified as a trusted resource from the skill author's known infrastructure.\n- [COMMAND_EXECUTION]: The skill relies on the Bash tool to perform system checks and execute the core trading logic and dependency management commands.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to how it handles external data.\n
  • Ingestion points: User-supplied values for <TICKERS> and <strategy> are interpolated into shell commands in SKILL.md.\n
  • Boundary markers: The instructions lack delimiters or explicit warnings to the agent to treat these inputs as literal data rather than command components.\n
  • Capability inventory: The skill has access to the Bash tool and several MCP tools for persistent memory storage and retrieval (e.g., mcp__plugin_ruflo-core_ruflo__memory_store) as defined in SKILL.md.\n
  • Sanitization: There is no evidence of input validation, escaping, or filtering to prevent shell meta-characters in the <TICKERS> or <strategy> placeholders from affecting the resulting npx command execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — trader-signal