Agent skill

LLM Trading Agent Security

by affaan-m in affaan-m/ECC

具有钱包或交易权限的自主交易代理的安全模式。涵盖提示注入、支出限制、发送前模拟、断路器、MEV保护和密钥处理. An agent skill from affaan-m/ECC.

MITAuto-check passedSecurity

Install LLM Trading Agent Security

skills CLI
$ npx skills add affaan-m/ECC --skill llm-trading-agent-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC llm-trading-agent-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/zh-CN/skills/llm-trading-agent-security .claude/skills/llm-trading-agent-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
llm-trading-agent-security
GitHub stars
276k
Token cost
~854 tokens
SKILL.md length
39 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

具有钱包或交易权限的自主交易代理的安全模式。涵盖提示注入、支出限制、发送前模拟、断路器、MEV保护和密钥处理. An agent skill from affaan-m/ECC.

  • Tasks that involve Prompt injection and agent security
  • SKILL.md covers 适用场景, 工作原理, 示例 and 部署前检查清单
  • Reaches rpc.flashbots.net; needs TRADING_WALLET_PRIVATE_KEY
  • Tasks that involve Trading and backtesting

What it does

LLM Trading Agent Security is an agent skill from affaan-m/ECC. 具有钱包或交易权限的自主交易代理的安全模式。涵盖提示注入、支出限制、发送前模拟、断路器、MEV保护和密钥处理。

Its SKILL.md is about 850 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security and Trading and backtesting. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Tasks that involve Prompt injection and agent security
  • Tasks that involve Trading and backtesting

Example prompts

  • “/llm-trading-agent-security”

Requirements

  • Python 3
  • A credential in TRADING_WALLET_PRIVATE_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 4eb71d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • rpc.flashbots.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TRADING_WALLET_PRIVATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

LLM Trading Agent Security loads about 854 tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 39 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~854

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 4eb71d9, republished under its MIT licence (© affaan-m). 39 words, ~854 tokens.

Download SKILL.mdSave it as .claude/skills/llm-trading-agent-security/SKILL.md (or your agent's skills folder).
name
llm-trading-agent-security
description
具有钱包或交易权限的自主交易代理的安全模式。涵盖提示注入、支出限制、发送前模拟、断路器、MEV保护和密钥处理。
origin
ECC direct-port adaptation
version
1.0.0

LLM 交易代理安全

自主交易代理面临比普通 LLM 应用更严苛的威胁模型:一次注入或错误的工具路径可能直接导致资产损失。

适用场景

  • 构建能够签署并发送交易的 AI 代理
  • 审计交易机器人或链上执行助手
  • 为代理设计钱包密钥管理方案
  • 授予 LLM 订单下达、代币兑换或资金操作权限

工作原理

构建多层防御体系。单一检查不足以保障安全。应将提示词卫生、支出策略、模拟执行、执行限制和钱包隔离视为独立控制措施。

示例

将提示注入视为金融攻击
python
import re

INJECTION_PATTERNS = [
    r'ignore (previous|all) instructions',
    r'new (task|directive|instruction)',
    r'system prompt',
    r'send .{0,50} to 0x[0-9a-fA-F]{40}',
    r'transfer .{0,50} to',
    r'approve .{0,50} for',
]

def sanitize_onchain_data(text: str) -> str:
    for pattern in INJECTION_PATTERNS:
        if re.search(pattern, text, re.IGNORECASE):
            raise ValueError(f"Potential prompt injection: {text[:100]}")
    return text

切勿将代币名称、交易对标签、网络钩子或社交信息流盲目注入具备执行能力的提示词中。

硬性支出限额
python
from decimal import Decimal

MAX_SINGLE_TX_USD = Decimal("500")
MAX_DAILY_SPEND_USD = Decimal("2000")

class SpendLimitError(Exception):
    pass

class SpendLimitGuard:
    def check_and_record(self, usd_amount: Decimal) -> None:
        if usd_amount > MAX_SINGLE_TX_USD:
            raise SpendLimitError(f"Single tx ${usd_amount} exceeds max ${MAX_SINGLE_TX_USD}")

        daily = self._get_24h_spend()
        if daily + usd_amount > MAX_DAILY_SPEND_USD:
            raise SpendLimitError(f"Daily limit: ${daily} + ${usd_amount} > ${MAX_DAILY_SPEND_USD}")

        self._record_spend(usd_amount)
发送前模拟执行
python
class SlippageError(Exception):
    pass

async def safe_execute(self, tx: dict, expected_min_out: int | None = None) -> str:
    sim_result = await self.w3.eth.call(tx)

    if expected_min_out is None:
        raise ValueError("min_amount_out is required before send")

    actual_out = decode_uint256(sim_result)
    if actual_out < expected_min_out:
        raise SlippageError(f"Simulation: {actual_out} < {expected_min_out}")

    signed = self.account.sign_transaction(tx)
    return await self.w3.eth.send_raw_transaction(signed.raw_transaction)
断路器机制
python
class TradingCircuitBreaker:
    MAX_CONSECUTIVE_LOSSES = 3
    MAX_HOURLY_LOSS_PCT = 0.05

    def check(self, portfolio_value: float) -> None:
        if self.consecutive_losses >= self.MAX_CONSECUTIVE_LOSSES:
            self.halt("Too many consecutive losses")

        if self.hour_start_value <= 0:
            self.halt("Invalid hour_start_value")
            return

        hourly_pnl = (portfolio_value - self.hour_start_value) / self.hour_start_value
        if hourly_pnl < -self.MAX_HOURLY_LOSS_PCT:
            self.halt(f"Hourly PnL {hourly_pnl:.1%} below threshold")
钱包隔离
python
import os
from eth_account import Account

private_key = os.environ.get("TRADING_WALLET_PRIVATE_KEY")
if not private_key:
    raise EnvironmentError("TRADING_WALLET_PRIVATE_KEY not set")

account = Account.from_key(private_key)

使用仅包含所需会话资金的专用热钱包。切勿将代理指向主资金钱包。

MEV 与截止时间保护
python
import time

PRIVATE_RPC = "https://rpc.flashbots.net"
MAX_SLIPPAGE_BPS = {"stable": 10, "volatile": 50}
deadline = int(time.time()) + 60

部署前检查清单

  • 外部数据在进入 LLM 上下文前已完成清理
  • 支出限额独立于模型输出强制执行
  • 交易在发送前经过模拟
  • min_amount_out 为强制要求
  • 断路器在出现回撤或无效状态时触发
  • 密钥来自环境变量或密钥管理器,绝不写入代码或日志
  • 在适当时使用私有内存池或受保护路由
  • 根据策略设置滑点和截止时间
  • 所有代理决策均记录审计日志,不仅限于成功发送的交易

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/zh-CN/skills/llm-trading-agent-security of affaan-m/ECC.

Open the folder on GitHubat commit 4eb71d9

Compare with similar skills

LLM Trading Agent Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

LLM Trading Agent Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
LLM Trading Agent Security this skillaffaan-m/ECC276k—~854Automated safety check: PassMIT
Tushare Datazillionare/zillionare3222 repos~2.3kAutomated safety check: PassNone
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Tradingview MCPatilaahmettaner/tradingview-mcp5k—~1.3kAutomated safety check: PassMIT
Digital Oraclekomako-workshop/digital-oracle878—~5.9kAutomated safety check: PassMIT
Polyclawchainstacklabs/polyclaw3591 repos~2kAutomated safety check: PassApache-2.0

Similar skills

  • Tushare Data

    zillionare/zillionare

    面向中文自然语言的 Tushare 数据研究技能。用于把“看看这只股票最近怎么样”“帮我查财报趋势”“最近哪个板块最强”“北向资金在买什么”“给我导出一份行情数据”这类请求,转成可执行的数据获取、清洗、对比、筛选、导出与简要分析流程。适用于 A 股、指数、ETF/基金、财务、估值、资金流、公告新闻、板块概念与宏观数据等研究场景。

    322 GitHub starsUsed in 2 repos~2.3k tokens
    Business, Finance & HRAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Tradingview MCP

    atilaahmettaner/tradingview-mcp

    AI Trading Intelligence — live prices, 30+ technical indicators, backtesting (6 strategies), walk-forward overfitting detection, trade logs, equity curves, licensed news sentiment (Marketaux), and…

    5k GitHub stars~1.3k tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Digital Oracle

    komako-workshop/digital-oracle

    Answer prediction questions using market trading data, not opinions.

    878 GitHub stars~5.9k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Polyclaw

    chainstacklabs/polyclaw

    Trade on Polymarket via split + CLOB execution. An agent skill from chainstacklabs/polyclaw.

    359 GitHub starsUsed in 1 repo~2k tokens
    Business, Finance & HRAuto-check passed
  • Markdown

    facioquo/stock-indicators-dotnet

    Format and lint Markdown in this repository against GitHub Flavored Markdown and its markdownlint-cli2 configuration — headers, lists, code fences, callouts (VitePress containers on docs-site pages…

    1.2k GitHub stars~812 tokensUpdated yesterday
    Business, Finance & HRAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Questions about LLM Trading Agent Security

What does LLM Trading Agent Security do?

具有钱包或交易权限的自主交易代理的安全模式。涵盖提示注入、支出限制、发送前模拟、断路器、MEV保护和密钥处理. An agent skill from affaan-m/ECC. LLM Trading Agent Security is an agent skill from affaan-m/ECC.

When should I use LLM Trading Agent Security?

LLM Trading Agent Security fits situations like: tasks that involve Prompt injection and agent security; tasks that involve Trading and backtesting.

How do I install LLM Trading Agent Security in Claude Code?

Run `npx skills add affaan-m/ECC --skill llm-trading-agent-security -a claude-code`. Or copy the skill folder (docs/zh-CN/skills/llm-trading-agent-security in affaan-m/ECC) into .claude/skills/llm-trading-agent-security in your project. Claude Code loads it when a task matches its description.

How do I install LLM Trading Agent Security in Codex?

Run `npx skills add affaan-m/ECC --skill llm-trading-agent-security -a codex`. Or copy the skill folder (docs/zh-CN/skills/llm-trading-agent-security in affaan-m/ECC) into .agents/skills/llm-trading-agent-security in your project. Codex loads it when a task matches its description.

Can I use LLM Trading Agent Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill llm-trading-agent-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/llm-trading-agent-security, .gemini/skills/llm-trading-agent-security, .github/skills/llm-trading-agent-security and .opencode/skills/llm-trading-agent-security in your project.

What does LLM Trading Agent Security need to run?

Going by SKILL.md and its folder, LLM Trading Agent Security needs credentials named TRADING_WALLET_PRIVATE_KEY. Our summary lists: Python 3; A credential in TRADING_WALLET_PRIVATE_KEY.

Does LLM Trading Agent Security access the network?

SKILL.md names 1 domain. In commands or code: rpc.flashbots.net; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is LLM Trading Agent Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does LLM Trading Agent Security use?

LLM Trading Agent Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does LLM Trading Agent Security use?

About 854 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to LLM Trading Agent Security?

Skills that share tags, products or a category with LLM Trading Agent Security: Tushare Data (zillionare/zillionare, 322 stars), Skill Scanner (getsentry/skills, 1k stars), Tradingview MCP (atilaahmettaner/tradingview-mcp, 5k stars) and Digital Oracle (komako-workshop/digital-oracle, 878 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains LLM Trading Agent Security?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,111 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 10, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.