T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
Plaintext WebSocket Endpoint Exposes Trading Notifications to Network Interception
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 39
Vulnerability Type:T09: Insecure Skill Coding Practices
Risk Level: MediumVulnerable Code:
markdown | WebSocket | `ws://ai4trade.ai/ws/notify/{client_id}` | Real-time notifications |Technical Analysis
The documented real-time notification endpoint uses plaintext WebSocket transport (
ws://) instead of TLS-protected WebSocket transport (wss://). Plaintext WebSocket traffic does not provide transport-layer confidentiality, integrity, or server authentication.If an agent follows this documentation while connected through an untrusted or compromised network, an on-path attacker may observe notification contents or modify WebSocket frames in transit. Because the Skill concerns trading signals and account-related notifications, manipulated messages could affect downstream agent decisions. The documentation does not require encrypted transport, certificate validation, or rejection of plaintext fallback.
The separate registration example uses HTTPS and sends credentials only as part of the declared account-registration function. No evidence was found that the Skill intentionally steals credentials, executes remote payloads, establishes persistence, or requests unnecessary local privileges.
Attack Path
- An agent connects to
ws://ai4trade.ai/ws/notify/{client_id}as documented. - The connection traverses an attacker-controlled or otherwise untrusted network, such as a malicious access point or compromised gateway.
- Because the connection is not protected by TLS, the attacker intercepts the WebSocket handshake and subsequent frames.
- The attacker reads, suppresses, replays, or alters real-time notification messages.
- If the consuming agent treats those messages as trusted market or account events, forged notifications may influence its trading-related behavior.
Impact Assessment
Exploitation does not directly gra ...[truncated 375 chars]
- An agent connects to
- Remediation
View remediation
Remediation Suggestions
- Replace the endpoint with
wss://ai4trade.ai/ws/notify/{client_id}and remove support for plaintext WebSocket connections. - Require normal TLS certificate and hostname validation; do not permit invalid certificates or insecure fallback to
ws://. - Authenticate and authorize each WebSocket connection using a short-lived credential bound to the intended client and minimum required scope.
- Avoid placing reusable secrets in URLs, where they may be exposed through logs, browser history, or monitoring systems.
- Add message-level integrity controls, sequence identifiers, timestamps, and replay protection where notifications can trigger consequential agent behavior.
- Validate notification schemas and require explicit confirmation or independent verification before executing trading actions based on received messages.
- Update the Skill documentation to warn users that credentials are sent to an external service and recommend unique credentials with explicit user consent.
- Replace the endpoint with
