trader-signal
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill initiates a download of the
neural-traderpackage from the npm registry usingnpm install. It employs the--ignore-scriptsflag, which is a recognized security measure to prevent the execution of potentially malicious scripts during the installation phase.\n- [REMOTE_CODE_EXECUTION]: The skill usesnpxto execute theneural-traderpackage downloaded from the public registry. This allows the execution of external code that is not verified as a trusted resource from the skill author's known infrastructure.\n- [COMMAND_EXECUTION]: The skill relies on theBashtool to perform system checks and execute the core trading logic and dependency management commands.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to how it handles external data.\n - Ingestion points: User-supplied values for
<TICKERS>and<strategy>are interpolated into shell commands inSKILL.md.\n - Boundary markers: The instructions lack delimiters or explicit warnings to the agent to treat these inputs as literal data rather than command components.\n
- Capability inventory: The skill has access to the
Bashtool and several MCP tools for persistent memory storage and retrieval (e.g.,mcp__plugin_ruflo-core_ruflo__memory_store) as defined inSKILL.md.\n - Sanitization: There is no evidence of input validation, escaping, or filtering to prevent shell meta-characters in the
<TICKERS>or<strategy>placeholders from affecting the resultingnpxcommand execution.
Audit Metadata