affaan-m/ECC

llm-trading-agent-security

Review llm-trading-agent-security's use cases, installation, workflow, and original source instructions.

64CollectingNetwork access
See how to use itView GitHub source
npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/llm-trading-agent-security"
Automated source guideDocumentationStandard source

Source checked Jul 28, 2026·Refresh due Oct 26, 2026

Reorganized from the pinned upstream SKILL.md

Source-grounded documentation guide: llm-trading-agent-security

自主交易代理面临比普通 LLM 应用更严苛的威胁模型:一次注入或错误的工具路径可能直接导致资产损失。

npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/llm-trading-agent-security"
Check the pinned source

The pinned source supports a structured brief, but not an expanded tutorial. Only detected inputs, outputs, and sections are shown.

269 source words · 10 usable sections

Documentation workflow

Read llm-trading-agent-security through these 4 source sections

Sections are extracted automatically from the pinned SKILL.md and link back to the source.

01

适用场景

构建能够签署并发送交易的 AI 代理 审计交易机器人或链上执行助手 为代理设计钱包密钥管理方案 授予 LLM 订单下达、代币兑换或资金操作权限

SKILL.md · 适用场景
构建能够签署并发送交易的 AI 代理审计交易机器人或链上执行助手为代理设计钱包密钥管理方案
02

工作原理

构建多层防御体系。单一检查不足以保障安全。应将提示词卫生、支出策略、模拟执行、执行限制和钱包隔离视为独立控制措施。

SKILL.md · 工作原理
构建多层防御体系。单一检查不足以保障安全。应将提示词卫生、支出策略、模拟执行、执行限制和钱包隔离视为独立控制措施。
03

示例

切勿将代币名称、交易对标签、网络钩子或社交信息流盲目注入具备执行能力的提示词中。

SKILL.md · 示例
切勿将代币名称、交易对标签、网络钩子或社交信息流盲目注入具备执行能力的提示词中。使用仅包含所需会话资金的专用热钱包。切勿将代理指向主资金钱包。
04

将提示注入视为金融攻击

切勿将代币名称、交易对标签、网络钩子或社交信息流盲目注入具备执行能力的提示词中。

SKILL.md · 将提示注入视为金融攻击
切勿将代币名称、交易对标签、网络钩子或社交信息流盲目注入具备执行能力的提示词中。

Documentation checklist

Verify each item before delivery

The source section “适用场景” has been checked.

The source section “工作原理” has been checked.

The source section “示例” has been checked.

The source section “将提示注入视为金融攻击” has been checked.

Static permission evidence

Inspect the exact source lines that triggered a signal

These are source excerpts matched by deterministic rules, not findings of malicious behavior, safety, or actual execution.

Choose a different workflow

When another Skill is the better fit

FAQ

What does the llm-trading-agent-security source document cover?

自主交易代理面临比普通 LLM 应用更严苛的威胁模型:一次注入或错误的工具路径可能直接导致资产损失。

How do I install llm-trading-agent-security?

The source record exposes this install command: npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/llm-trading-agent-security". Inspect the command and pinned source before running it.

Which permission-related actions were detected?

Static rules flagged network in the source; the page lists the matching lines and excerpts.

Repository stars
234,327
Repository forks
35,711
Quality
64/100
Source repository last pushed

Quality breakdown

Based on traceable docs and repository signals; stars are not treated as quality.

64/100
Documentation22/30
Specificity11/25
Maintenance20/20
Trust signals11/25
View original Skill.mdThis page is parsed directly from the repository SKILL.md without editorial rewriting. Collected: Jul 28, 2026 · about 1 min

LLM 交易代理安全

自主交易代理面临比普通 LLM 应用更严苛的威胁模型:一次注入或错误的工具路径可能直接导致资产损失。

适用场景

  • 构建能够签署并发送交易的 AI 代理
  • 审计交易机器人或链上执行助手
  • 为代理设计钱包密钥管理方案
  • 授予 LLM 订单下达、代币兑换或资金操作权限

工作原理

构建多层防御体系。单一检查不足以保障安全。应将提示词卫生、支出策略、模拟执行、执行限制和钱包隔离视为独立控制措施。

示例

将提示注入视为金融攻击

import re

INJECTION_PATTERNS = [
    r'ignore (previous|all) instructions',
    r'new (task|directive|instruction)',
    r'system prompt',
    r'send .{0,50} to 0x[0-9a-fA-F]{40}',
    r'transfer .{0,50} to',
    r'approve .{0,50} for',
]

def sanitize_onchain_data(text: str) -> str:
    for pattern in INJECTION_PATTERNS:
        if re.search(pattern, text, re.IGNORECASE):
            raise ValueError(f"Potential prompt injection: {text[:100]}")
    return text

切勿将代币名称、交易对标签、网络钩子或社交信息流盲目注入具备执行能力的提示词中。

硬性支出限额

from decimal import Decimal

MAX_SINGLE_TX_USD = Decimal("500")
MAX_DAILY_SPEND_USD = Decimal("2000")

class SpendLimitError(Exception):
    pass

class SpendLimitGuard:
    def check_and_record(self, usd_amount: Decimal) -> None:
        if usd_amount > MAX_SINGLE_TX_USD:
            raise SpendLimitError(f"Single tx ${usd_amount} exceeds max ${MAX_SINGLE_TX_USD}")

        daily = self._get_24h_spend()
        if daily + usd_amount > MAX_DAILY_SPEND_USD:
            raise SpendLimitError(f"Daily limit: ${daily} + ${usd_amount} > ${MAX_DAILY_SPEND_USD}")

        self._record_spend(usd_amount)

发送前模拟执行

class SlippageError(Exception):
    pass

async def safe_execute(self, tx: dict, expected_min_out: int | None = None) -> str:
    sim_result = await self.w3.eth.call(tx)

    if expected_min_out is None:
        raise ValueError("min_amount_out is required before send")

    actual_out = decode_uint256(sim_result)
    if actual_out < expected_min_out:
        raise SlippageError(f"Simulation: {actual_out} < {expected_min_out}")

    signed = self.account.sign_transaction(tx)
    return await self.w3.eth.send_raw_transaction(signed.raw_transaction)

断路器机制

class TradingCircuitBreaker:
    MAX_CONSECUTIVE_LOSSES = 3
    MAX_HOURLY_LOSS_PCT = 0.05

    def check(self, portfolio_value: float) -> None:
        if self.consecutive_losses >= self.MAX_CONSECUTIVE_LOSSES:
            self.halt("Too many consecutive losses")

        if self.hour_start_value <= 0:
            self.halt("Invalid hour_start_value")
            return

        hourly_pnl = (portfolio_value - self.hour_start_value) / self.hour_start_value
        if hourly_pnl < -self.MAX_HOURLY_LOSS_PCT:
            self.halt(f"Hourly PnL {hourly_pnl:.1%} below threshold")

钱包隔离

import os
from eth_account import Account

private_key = os.environ.get("TRADING_WALLET_PRIVATE_KEY")
if not private_key:
    raise EnvironmentError("TRADING_WALLET_PRIVATE_KEY not set")

account = Account.from_key(private_key)

使用仅包含所需会话资金的专用热钱包。切勿将代理指向主资金钱包。

MEV 与截止时间保护

import time

PRIVATE_RPC = "https://rpc.flashbots.net"
MAX_SLIPPAGE_BPS = {"stable": 10, "volatile": 50}
deadline = int(time.time()) + 60

部署前检查清单

  • 外部数据在进入 LLM 上下文前已完成清理
  • 支出限额独立于模型输出强制执行
  • 交易在发送前经过模拟
  • min_amount_out 为强制要求
  • 断路器在出现回撤或无效状态时触发
  • 密钥来自环境变量或密钥管理器,绝不写入代码或日志
  • 在适当时使用私有内存池或受保护路由
  • 根据策略设置滑点和截止时间
  • 所有代理决策均记录审计日志,不仅限于成功发送的交易
Source repo
affaan-m/ECC
Skill path
docs/zh-CN/skills/llm-trading-agent-security/SKILL.md
Commit SHA
4e973d3eaf92
Repository license
MIT
Data collected