Back to skill

Security audit

0xArchive

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed 0xArchive market-data helper, but it includes credential handling and wallet/payment-related workflows that need user review before installation.

Install only if you trust 0xArchive with your API key and intended wallet queries. Avoid putting long-lived API keys in WebSocket URLs or command lines that may be logged, and require explicit human approval before signing wallet messages, revoking keys, or starting paid subscriptions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:224
Finding

API Key Exposed in WebSocket URL Query Parameter

Content
View full analysis
`. 3. A local diagnostic system, reverse proxy, API gate ...[truncated 1282 chars]
Remediation
View remediation
``` 2. **Use short-lived connection tokens if headers are unsupported.** Add an authenticated HTTPS endpoint that exchanges the long-lived API key for a narrowly scoped, single-use WebSocket token with a short expiration period. 3. **Consider an authenticated WebSocket subprotocol.** If supported by the server and client ecosystem, transmit a temporary credential through a designated WebSocket subprotocol rather than the URL. 4. **Apply least privilege.** Scope WebSocket tokens to required channels, symbols, subscription tier, and connection duration. They should not authorize key management, billing changes, or unrelated API operations. 5. **Redact sensitive query parameters.** Configure clients, gateways, proxies, telemetry platforms, and server logs to redact `apiKey` and similar credential parameters. Avoid printing complete connection URLs in errors and diagnostics. 6. **Rotate potentially exposed keys.** Revoke and replace keys that may already have appeared in logs, shell history, traces, or monitoring systems. 7. **Update the Skill documentation.** Replace the credential-bearing example with the secure authentication mechanism and explicitly warn agents not to place long-lived API keys in URLs, command-line arguments, logs, or generated output. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (38)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 374)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 378)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 407)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 411)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 416)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 421)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 425)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 430)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 435)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 439)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 444)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 449)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 453)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 457)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 461)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 466)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 470)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 474)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 478)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 482)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 486)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 491)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 501)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 510)May include surrounding context.

All endpoints require the x-api-key header. The key is read from $OXARCHIVE_API_KEY.

bash
curl -s -H "x-api-key: $OXARCHIVE_API_KEY" "https://api.0xarchive.io/v1/..."

Venue Scopes & Coin Naming

Static analysis

No suspicious patterns detected.