Security patterns for autonomous trading agents with wallet or transaction authority. Covers prompt injection, spend limits, pre-send simulation, circuit breakers, MEV protection, and key handling.
Detected risks:
The llm-trading-agent-security skill provides security guidance and defensive patterns for autonomous AI trading agents that can sign transactions, manage wallets, or execute on-chain operations. It addresses the unique threat model of execution-capable LLM systems, where prompt injection, unsafe tool usage, or poor wallet isolation can directly lead to financial loss. The skill focuses on layered security controls for trading bots and execution assistants, helping developers reduce operational risk when granting AI systems transaction authority.
The skill covers several core security mechanisms, including prompt injection detection and sanitization for on-chain or external data, hard spend limits for transaction and daily exposure control, transaction simulation before execution, trading circuit breakers for automated risk shutdowns, wallet isolation using dedicated hot wallets, and MEV-aware execution protections such as private RPC usage and transaction deadlines. The included examples demonstrate practical Python-based implementations for enforcing transaction policies, validating execution outputs, and managing sensitive key material through environment variables.
This skill is intended for developers, auditors, security engineers, and teams building AI-powered trading infrastructure or blockchain automation systems. It is useful for projects involving automated swaps, treasury management, order execution, or wallet-enabled agents that interact with decentralized finance protocols. The guidance is especially relevant for organizations seeking to improve operational safeguards, reduce exploit exposure, and implement defense-in-depth security strategies for LLM-driven financial applications.
This skill is designed for autonomous trading agents, on-chain execution assistants, and AI systems that can sign or send blockchain transactions.
Yes. The documentation includes examples of detecting and rejecting suspicious prompt patterns in on-chain data, webhooks, token labels, and other external inputs.
The examples are written in Python and demonstrate patterns for transaction validation, spend controls, wallet handling, and execution safeguards.
Yes. It provides defensive controls such as spend limits, transaction simulation, slippage validation, circuit breakers, and wallet isolation to reduce the likelihood of unsafe execution.
No. The skill focuses on security patterns and defensive techniques rather than a complete trading framework or exchange integration.
Quick Setup:
.claude/skills/Repository
affaan-m/everything-claude-code