Back to skill

Security audit

Maxxit 0G Trading

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real trading skill, but it needs review because bundled scripts can place leveraged trades automatically and send trading API credentials to a configurable API URL.

Review this carefully before installing. Only use it with trading API keys you are willing to delegate, verify `MAXXIT_API_URL` is exactly the intended Maxxit HTTPS origin, and avoid running the bundled strategy scripts on funded accounts unless you have separate exposure limits, dry-run behavior, and explicit approval for each live order. Pin installer versions where possible and revoke keys promptly if anything looks wrong.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
strategy_common.py:15
Finding

Unrestricted API Base URL Can Expose Credentials and Financial Account Data

Content
View full analysis
requests.Session: session = requests.Session() session.headers.update({"X-API-KEY": MAXXIT_API_KEY, "Content-Type": "application/json"}) return session def api_get(session: requests.Session, path: str, params: Optional[Dict[str, Any]] = None) -> Optional[Dict[str, Any]]: url = f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/{path}" try: response = session.get(url, params=params, timeout=REQUEST_TIMEOUT) response.raise_for_status() return response.json() except requests.RequestException as exc: log(f"GET {path} failed: {exc}") return None def api_post(session: requests.Session, path: str, payload: Dict[str, Any]) -> Optional[Dict[str, Any]]: url = f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/{path}" try: response = session.post(url, json=payload, timeout=REQUEST_TIMEOUT) response.raise_for_status() return response.json() except requests.RequestException as exc: log(f"POST {path} failed: {exc}") return None ``` Equivalent unrestricted URL construction also occurs in: - `breakout-strategy.py:18-19, 62-69, 113-120` - `mean-reversion-strategy.py:18-19, 64-71, 118-125` - `taker-strategy.py:18-19, 72-90, 135-137` - `vwap-strategy.py:19, 61-68, 112-119` The shared behavior affects `ema-strategy.py`, `rsi-bollinger-strategy.py`, and `donchian-adx-strategy.py` through their use of `strategy_common.py`. ### Technical Analysis `MAXXIT_API_URL` is taken directly from the process environment and used as the destination for sessions containing `MAXXIT_API_KEY`. There is no validation that the destination: - Uses ...[truncated 2175 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
strategy_common.py:439
Finding

Automated Strategies Can Commit Most of the Account Balance at High Leverage Without Per-Trade Approval

Content
View full analysis
skipping") return False ``` ```python positions_resp = fetch_positions(session, venue, user_address, agent_address) existing_position = find_existing_position(positions_resp, config) if existing_position: existing_side = str(existing_position.get("side", "")).lower() if existing_side != signal: close_resp: Optional[Dict[str, Any]] if venue == "ostium": close_resp = api_post( session, "close-position", { "agentAddress": agent_address, "userAddress": user_address, "market": market, "actualTradeIndex": existing_position.get("tradeIndex"), }, ) elif venue == "aster": close_resp = api_post( ...[truncated 4041 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:5
Finding

Mutable Latest-Version Package Is Downloaded and Executed During Installation and Updates

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (51)

Tainted flow: 'url' from os.environ.get (line 63, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · breakout-strategy.py (reported line 77)May include surrounding context.

python
url = "https://api.binance.com/api/v3/klines"
    params = {"symbol": symbol, "interval": interval, "limit": limit}
    try:
        resp = requests.get(url, params=params, timeout=10)
        resp.raise_for_status()
        return [
            {"h": float(item[2]), "l": float(item[3]), "c": float(item[4])}

Tainted flow: 'MAXXIT_API_URL' from os.environ.get (line 18, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

MAXXIT_API_URL is taken directly from the environment and used to build an authenticated request with the API key in headers. If an attacker can influence the environment, they can redirect requests to an arbitrary host, causing credential leakage, SSRF-like behavior, and potentially malicious trade orchestration based on forged responses.

Content

Scanner excerpt · breakout-strategy.py (reported line 120)May include surrounding context.

python
log(f"Starting Volatility Breakout Bot | Market: {MARKET} | Venue: {VENUE}")
    
    # 1. Get Club Details
    club = requests.get(f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/user-details", headers=session.headers).json()
    user_address = club.get("user_wallet")
    agent_address = club.get("ostium_agent_address")

Tainted flow: 'url' from os.environ.get (line 65, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · mean-reversion-strategy.py (reported line 79)May include surrounding context.

python
url = "https://api.binance.com/api/v3/klines"
    params = {"symbol": symbol, "interval": interval, "limit": limit}
    try:
        resp = requests.get(url, params=params, timeout=10)
        resp.raise_for_status()
        return [float(item[4]) for item in resp.json()] # Just close prices
    except Exception as exc:

Tainted flow: 'MAXXIT_API_URL' from os.environ.get (line 18, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The code builds a request URL directly from MAXXIT_API_URL in the environment and immediately sends authenticated headers containing the API key. If an attacker can influence the environment or deployment config, they can redirect the request to an arbitrary host and capture credentials or sensitive account metadata, making this an SSRF-style secret exfiltration risk.

Content

Scanner excerpt · mean-reversion-strategy.py (reported line 125)May include surrounding context.

python
log(f"Starting Mean Reversion Bot | Market: {MARKET} | Venue: {VENUE}")
    
    # 1. Get Club Details
    club = requests.get(f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/user-details", headers=session.headers).json()
    user_address = club.get("user_wallet")
    agent_address = club.get("ostium_agent_address")

Tainted flow: 'url' from os.environ.get (line 83, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · taker-strategy.py (reported line 98)May include surrounding context.

python
url = "https://api.binance.com/api/v3/klines"
    params = {"symbol": symbol, "interval": interval, "limit": limit}
    try:
        resp = requests.get(url, params=params, timeout=10)
        resp.raise_for_status()
        data = resp.json()
        # [OpenTime, Open, High, Low, Close, Vol, CloseTime, QuoteVol, Trades, TakerBuyBase, TakerBuyQuote, Ignore]

Tainted flow: 'url' from os.environ.get (line 62, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · vwap-strategy.py (reported line 76)May include surrounding context.

python
url = "https://api.binance.com/api/v3/klines"
    params = {"symbol": symbol, "interval": interval, "limit": limit}
    try:
        resp = requests.get(url, params=params, timeout=10)
        resp.raise_for_status()
        # [OpenTime, Open, High, Low, Close, Vol, CloseTime, QuoteVol, Trades, TakerBuyBase, TakerBuyQuote, Ignore]
        return [

Tainted flow: 'MAXXIT_API_URL' from os.environ.get (line 19, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The bot sends its API key in headers to a base URL taken directly from the MAXXIT_API_URL environment variable without validation. If that environment variable is misconfigured or attacker-controlled, the script can exfiltrate credentials and sensitive account metadata to an arbitrary host, which is especially dangerous in an automated trading skill.

Content

Scanner excerpt · vwap-strategy.py (reported line 119)May include surrounding context.

python
log(f"Starting VWAP Bot | Market: {MARKET} | Venue: {VENUE}")
    
    # 1. Get Club Details
    club = requests.get(f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/user-details", headers=session.headers).json()
    user_address = club.get("user_wallet")
    agent_address = club.get("ostium_agent_address")

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a comprehensive trading and research platform with decentralized AI/storage integration and multiple workflows, but the code only performs a narrow automated trading task: a volatility breakout strategy using Binance OHLC data plus Maxxit API calls to inspect balances/positions and open a trade. There is no evidence of 0G services, portfolio analysis, alpha marketplace/listings, copy-trading, or broad DEX/market-research functionality. This is a material description-to-behavior mismatch, not just an incomplete implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a comprehensive Maxxit skill with decentralized AI/storage integrations and multiple workflow categories: portfolio-aware trade decisions, alpha listings, market research, copy-trading, and marketplace functionality. The supplied code chunk instead implements a single technical trading strategy: it parses CLI args, fetches Binance OHLCV data, calculates ADX and EMA, checks Donchian breakout conditions, and executes a long/short signal with TP/SL. This is materially narrower and lacks the major advertised capabilities. While it is related to trading, its actual purpose is a specific strategy executor rather than the broad multi-workflow platform described.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a comprehensive trading platform/skill with decentralized AI compute, decentralized storage, portfolio-aware decisions, alpha listings, market research, copy-trading, and marketplace functionality. The supplied code instead implements a specific technical-analysis strategy: it parses CLI args, fetches Binance klines, computes fast/slow EMAs, detects crossover signals, and executes long/short trades on configured venues with TP/SL controls. This is materially narrower and different in primary purpose than the declared description. While both relate to trading, the code does not substantiate the major advertised capabilities, so the description does not accurately represent the actual behavior of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description claims a comprehensive Maxxit trading skill with 0G decentralized AI/storage integration and multiple workflow categories (DEX trading, market research, copy-trading, alpha marketplace). The supplied code instead implements one specific automated strategy: a mean-reversion bot using RSI and Bollinger Bands on Binance price data, then interacting with Maxxit programmatic trading endpoints to check balances/positions and open a trade. There is no evidence of 0G integration, portfolio-aware decisioning, alpha listings/storage, market research, or copy-trading. This is a material description-versus-behavior mismatch, not just an incomplete snippet of the claimed functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a comprehensive trading skill with decentralized AI/storage integration and multiple product workflows. The supplied code chunk instead performs a single technical-analysis-based lazy trading strategy using RSI and Bollinger Bands on one symbol, with signal execution and local state persistence. While it does relate to trading and may fit within a broader trading system, the actual code shown does not substantiate the major declared capabilities such as 0G integrations, market research, copy-trading, alpha marketplace features, or portfolio-aware decision-making. This is a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description is substantially broader and different from the supplied code. This module is clearly focused on programmatic trading execution and indicator utilities for Maxxit lazy-trading strategies. It supports exchange/API interactions for balances, positions, leverage checks, and placing or updating trades on three venues. However, the description prominently claims 0G decentralized AI compute, decentralized storage, censorship-resistant alpha listings, copy-trading, alpha marketplace workflows, and all DEX trading/market research workflows from another package. None of those capabilities appear in this code chunk. While market data retrieval and indicator calculations are present, they are narrow supporting functions for strategy execution, not a full market research or portfolio-aware AI system. Therefore the description does not accurately represent this code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a comprehensive Maxxit skill with decentralized AI/storage integrations and multiple workflows (DEX trading, market research, copy-trading, alpha marketplace, portfolio-aware decisions). The code instead implements a specific automated taker-flow strategy: it reads a symbol/venue from CLI args, pulls Binance order-flow proxy data, generates a threshold-based long/short signal, checks account state through Maxxit lazy-trading programmatic endpoints, and opens or flips a position on OSTIUM or AVANTIS. This is materially narrower and different in purpose from the declared functionality. While it is related to Maxxit trading, the major advertised capabilities are absent, and the actual trigger model (command-line execution) is also undeclared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description claims a comprehensive Maxxit trading skill with decentralized AI/storage backing and multiple workflow categories inherited from maxxit-lazy-trading. The supplied code instead implements a single-purpose automated trading script: it parses CLI arguments, fetches Binance klines, computes VWAP and EMA, checks existing positions and balances via Maxxit APIs, and opens a position on one of two venues when a basic signal appears. There is no sign of 0G integration, portfolio optimization, alpha listing/storage, market research, copy-trading, or marketplace functionality. This is not merely a partial implementation detail; the primary purpose and capabilities are materially narrower and different from the declared description.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill can place leveraged trades, close positions, modify TP/SL, purchase alpha, and interact with brokerage/exchange APIs, yet it lacks a prominent upfront warning about financial risk and irreversible execution. For a high-impact financial skill, insufficient risk disclosure increases the likelihood of unsafe user actions and reduces meaningful informed consent before destructive or costly operations.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill contains a self-modification path instructing the agent to update itself via a forced package installation. Self-updating behavior is dangerous because it changes the trusted code/instruction base at runtime and can be abused to introduce unreviewed or malicious content, especially when combined with @latest and available credentials/tools.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

Skill Maintenance

  • If the user asks OpenClaw to update this skill, run:
bash
npx clawhub@latest install maxxit-0g --force

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill explicitly references access to brokerage credentials and session tokens stored in SSM, including KITE_API_SECRET and KITE_ACCESS_TOKEN. In a skill that also has broad tool capabilities and destructive actions, exposing or normalizing direct credential use increases the risk of credential misuse, leakage through logs/prompts, or unauthorized brokerage actions if the agent is compromised or tricked.

Content

Scanner excerpt · SKILL.md (reported line 1963)May include surrounding context.

md
|----------|-------------|--------|
| `KITE_API_KEY` | Zerodha Kite Connect API key | SSM (set in OpenClaw UI) |
| `KITE_API_SECRET` | Zerodha Kite Connect API secret | SSM (set in OpenClaw UI) |
| `KITE_ACCESS_TOKEN` | Short-lived access token (expires daily) | SSM (auto-stored after OAuth) |
| `KITE_USER_NAME` | Zerodha display name for status/UI | SSM (auto-stored after OAuth) |

### Auth Pre-Flight

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

The skill exposes a destructive session-deletion endpoint (DELETE /zerodha/session) that invalidates the brokerage session and removes the token from SSM. In an agentic environment, destructive account/session operations can be triggered through prompt confusion or misuse, causing denial of service or forcing reauthentication for the user.

Content

Scanner excerpt · SKILL.md (reported line 2030)May include surrounding context.

-H "X-KITE-ACCESS-TOKEN: ${KITE_ACCESS_TOKEN}"

text

#### DELETE /zerodha/session

Invalidate Zerodha session and remove token from SSM.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Canceling brokerage orders is a high-impact state-changing action that can directly alter market exposure or trading outcomes. Because this skill includes broad triggers and extensive action documentation, insufficient safeguards around deletion/cancellation operations increase the risk of accidental or manipulated order cancellation.

Content

Scanner excerpt · SKILL.md (reported line 2149)May include surrounding context.

-d '{"variety": "regular", "price": 2500, "order_type": "LIMIT"}'

text

#### DELETE /zerodha/orders?orderId=<id>

Cancel an order.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

Deleting a GTT trigger removes automated take-profit/stop-loss protections or planned exits, which can materially increase user risk exposure. In a financial context, destructive modification of protective orders is especially sensitive and should not be easy to trigger from general conversation.

Content

Scanner excerpt · SKILL.md (reported line 2249)May include surrounding context.

}'

text

#### DELETE /zerodha/gtt?triggerId=<id>

Delete an existing GTT trigger.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The bot automatically opens leveraged positions once its signal conditions are met, with no explicit user warning, confirmation, or separate execution approval. In the context of a trading skill, this significantly increases harm because a misconfiguration, compromised input source, or logic error can immediately convert into real-money losses.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The execute_signal flow can close existing positions and open new leveraged trades immediately based on a programmatic signal, with no confirmation gate, approval callback, or explicit user acknowledgment at the action point. In a trading skill, this is especially dangerous because mistakes, prompt manipulation in upstream strategy logic, or compromised automation can directly trigger real financial actions and losses across user accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The bot can automatically close and open leveraged positions based solely on external market data and current account state, without any user confirmation, policy gate, dry-run mode, or risk-limit enforcement beyond minimal balance checks. In a trading skill context, this is dangerous because a misconfiguration, bad signal, compromised runtime, or unexpected API response can immediately trigger irreversible financial actions on a live account.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script can automatically open leveraged positions based solely on market signals and available balance, with no interactive confirmation, policy gate, or secondary approval. In a trading-agent context this creates substantial risk of unauthorized or unsafe transactions if inputs, strategy logic, environment, or upstream APIs are manipulated or simply wrong.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:2014