Back to skill

Security audit

Maxxit Lazy Trader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed trading integration, but it can place leveraged trades, spend agent-wallet USDC, and forward financial credentials with too little scoping or transaction-specific confirmation.

Install only if you understand that this skill can act on real trading accounts and delegated wallets. Before use, pin and verify the installer, set MAXXIT_API_URL only to the trusted Maxxit origin, keep trading credentials out of untrusted environments, disable or review the autonomous strategy scripts, and require explicit confirmation for every payment, order, cancellation, close, TP/SL change, and Alpha execution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
strategy_common.py:103
Finding

Financial API credentials can be forwarded to an unrestricted network origin

Content
View full analysis
requests.Session: session = requests.Session() session.headers.update({"X-API-KEY": MAXXIT_API_KEY, "Content-Type": "application/json"}) return session def api_get( session: requests.Session, path: str, params: Optional[Dict[str, Any]] = None, ) -> Optional[Dict[str, Any]]: url = f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/{path}" try: response = session.get(url, params=params, timeout=REQUEST_TIMEOUT) response.raise_for_status() return response.json() except requests.RequestException as exc: log(f"GET {path} failed: {exc}") return None def api_post( session: requests.Session, path: str, payload: Dict[str, Any], ) -> Optional[Dict[str, Any]]: url = f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/{path}" try: response = session.post(url, json=payload, timeout=REQUEST_TIMEOUT) response.raise_for_status() return response.json() except requests.RequestException as exc: log(f"POST {path} failed: {exc}") return None ``` The Skill documentation also instructs authenticated requests to follow redirects: ```bash curl -L -X GET "${MAXXIT_API_URL}/api/lazy-trading/programmatic/zerodha/session" \ -H "X-API-KEY: ${MAXXIT_API_KEY}" \ -H "X-KITE-API-KEY: ${KITE_API_KEY}" \ -H "X-KITE-ACCESS-TOKEN: ${KITE_ACCESS_TOKE ...[truncated 2239 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
strategy_common.py:441
Finding

Strategy scripts execute high-exposure leveraged trades without transaction-specific user confirmation

Content
View full analysis
skipping" ) return False ``` A representative automatic order path is: ```python open_resp = api_post( session, "avantis/open-position", { "agentAddress": agent_address, "userAddress": user_address, "market": market, "side": signal, "collateral": round(collateral, 4), "leverage": leverage, "takeProfitPercent": take_profit, "stopLossPercent": stop_loss, }, ) ``` A representative strategy invokes this path immediately after deriving a signal: ```python session = create_session() success = execute_signal( session=session, config=config, signal=signal, refe ...[truncated 2862 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:2288
Finding

Alpha Marketplace workflow permits payment and trade execution without mandatory exact-amount approval

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:7
Finding

Installation and update commands execute an unpinned mutable package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
breakout-strategy.py:4
Finding

Three advertised strategy scripts fail at module initialization because requests is not imported

Content
View full analysis
Optional[Dict[str, Any]]: url = f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/{path}" try: response = session.post(url, json=payload, timeout=30) response.raise_for_status() return response.json() except requests.RequestException as exc: log(f"POST {path} failed: {exc}") return None ``` Equivalent missing imports exist in `mean-reversion-strategy.py` and `taker-strategy.py`. ### Technical Analysis These modules do not enable postponed annotation evaluation. Consequently, `requests.Session` is resolved while the function is defined. Because `requests` is absent from the module namespace, execution raises `NameError` before the strategy can enter its main trading workflow. Even if annotations were postponed, later calls to `requests.Session`, `requests.get`, and `requests.RequestException` would still fail. The scripts are advertised as operational built-in strategies, so this is a confirmed availability and reliability defect. ### Attack Path No attacker is required: 1. A user invokes one of the affected scripts with the documented arguments. 2. Python loads the module and evaluates the function annotations. 3. Name resolution for `requests.Session` fails. 4. The script terminates ...[truncated 648 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (55)

Tainted flow: 'url' from os.environ.get (line 63, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · breakout-strategy.py (reported line 77)May include surrounding context.

python
url = "https://api.binance.com/api/v3/klines"
    params = {"symbol": symbol, "interval": interval, "limit": limit}
    try:
        resp = requests.get(url, params=params, timeout=10)
        resp.raise_for_status()
        return [
            {"h": float(item[2]), "l": float(item[3]), "c": float(item[4])}

Tainted flow: 'MAXXIT_API_URL' from os.environ.get (line 18, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The script performs an authenticated request to a base URL fully controlled by the MAXXIT_API_URL environment variable, and includes the X-API-KEY header. If that environment variable is misconfigured or maliciously set, the bot can leak API credentials and user trading metadata to an attacker-controlled server, which is especially dangerous in an automated trading agent.

Content

Scanner excerpt · breakout-strategy.py (reported line 120)May include surrounding context.

python
log(f"Starting Volatility Breakout Bot | Market: {MARKET} | Venue: {VENUE}")
    
    # 1. Get Club Details
    club = requests.get(f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/user-details", headers=session.headers).json()
    user_address = club.get("user_wallet")
    agent_address = club.get("ostium_agent_address")

Tainted flow: 'url' from os.environ.get (line 65, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · mean-reversion-strategy.py (reported line 79)May include surrounding context.

python
url = "https://api.binance.com/api/v3/klines"
    params = {"symbol": symbol, "interval": interval, "limit": limit}
    try:
        resp = requests.get(url, params=params, timeout=10)
        resp.raise_for_status()
        return [float(item[4]) for item in resp.json()] # Just close prices
    except Exception as exc:

Tainted flow: 'MAXXIT_API_URL' from os.environ.get (line 18, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The code builds a request URL from MAXXIT_API_URL taken directly from the environment and sends the API key in headers to that destination. If the environment variable is misconfigured or maliciously controlled, the bot can exfiltrate credentials and wallet metadata to an attacker-controlled server, which is especially dangerous in an automated trading skill with authority to place trades.

Content

Scanner excerpt · mean-reversion-strategy.py (reported line 125)May include surrounding context.

python
log(f"Starting Mean Reversion Bot | Market: {MARKET} | Venue: {VENUE}")
    
    # 1. Get Club Details
    club = requests.get(f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/user-details", headers=session.headers).json()
    user_address = club.get("user_wallet")
    agent_address = club.get("ostium_agent_address")

Tainted flow: 'url' from os.environ.get (line 83, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · taker-strategy.py (reported line 98)May include surrounding context.

python
url = "https://api.binance.com/api/v3/klines"
    params = {"symbol": symbol, "interval": interval, "limit": limit}
    try:
        resp = requests.get(url, params=params, timeout=10)
        resp.raise_for_status()
        data = resp.json()
        # [OpenTime, Open, High, Low, Close, Vol, CloseTime, QuoteVol, Trades, TakerBuyBase, TakerBuyQuote, Ignore]

Tainted flow: 'url' from os.environ.get (line 62, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · vwap-strategy.py (reported line 76)May include surrounding context.

python
url = "https://api.binance.com/api/v3/klines"
    params = {"symbol": symbol, "interval": interval, "limit": limit}
    try:
        resp = requests.get(url, params=params, timeout=10)
        resp.raise_for_status()
        # [OpenTime, Open, High, Low, Close, Vol, CloseTime, QuoteVol, Trades, TakerBuyBase, TakerBuyQuote, Ignore]
        return [

Tainted flow: 'MAXXIT_API_URL' from os.environ.get (line 19, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The code performs an authenticated request to a URL taken directly from MAXXIT_API_URL, sending the X-API-KEY header to whatever host is configured. If that environment variable is misconfigured or maliciously set, the bot can leak credentials to an attacker-controlled endpoint and trust forged account data, which is especially dangerous in a live trading skill.

Content

Scanner excerpt · vwap-strategy.py (reported line 119)May include surrounding context.

python
log(f"Starting VWAP Bot | Market: {MARKET} | Venue: {VENUE}")
    
    # 1. Get Club Details
    club = requests.get(f"{MAXXIT_API_URL}/api/lazy-trading/programmatic/user-details", headers=session.headers).json()
    user_address = club.get("user_wallet")
    agent_address = club.get("ostium_agent_address")

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad multi-platform trading skill with numerous capabilities: multiple venues (Ostium, Aster, Avantis), Zerodha-based Indian stock trading, market data and research, copy-trading, and a blockchain alpha marketplace. The supplied code does not implement that general platform behavior. Instead, it is narrowly a specific breakout strategy bot that: parses CLI args for symbol/venue, fetches OHLC data from Binance, calculates ATR and Bollinger Bands, checks Maxxit user/balance/position data, and opens a long or short perpetual trade on OSTIUM or AVANTIS when breakout conditions are met. This is a materially narrower and different actual behavior than the declared all-in-one trading integration. While it does relate to Maxxit perpetual trading, the missing major declared capabilities and the undeclared reliance on Binance market data make the description inaccurate for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a large multi-capability trading skill spanning several exchanges, Indian equity brokerage integration, research endpoints, copy-trading, and a blockchain marketplace. The supplied code chunk instead implements a narrow automated Donchian/ADX breakout strategy: it parses CLI arguments, fetches Binance klines, computes indicators, decides long/short/no-trade, and submits a trade via shared helper functions to a configured venue. While the venue parameter may align partially with Maxxit-related perpetual trading, the vast majority of the declared functionality is absent from this code. This is a material description-to-behavior mismatch, not just an incomplete snippet of a matching interface, because the primary behavior shown is a specific strategy executor rather than the claimed broad API/platform feature set.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description presents a large multi-feature trading skill spanning multiple broker/API integrations and marketplace features. The actual code chunk only implements a single EMA-based automated trading strategy that consumes Binance candles and places venue trades through helper functions. While trading on Ostium/Aster/Avantis is consistent with part of the description, most of the declared functionality is absent from this code, and the code’s primary purpose is much narrower than advertised. This is therefore a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declaration describes a comprehensive multi-platform trading skill with numerous programmatic capabilities across crypto perpetuals, Indian equities, copy-trading, and an on-chain signal marketplace. The supplied code is much narrower: it is a standalone mean-reversion strategy script that only opens positions on Maxxit Lazy Trading for OSTIUM or AVANTIS based on Binance-derived indicators. Its primary purpose is automated signal generation and order entry for one strategy, not the broad API surface and cross-platform functionality claimed in the description. This is a material description-behavior mismatch, not merely an incomplete snippet, because several major declared capabilities are entirely absent and one declared venue (Aster) is unsupported in the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a large multi-feature trading integration platform, but the supplied code chunk is only a specific algorithmic strategy script. Its primary behavior is to fetch Binance candle data, calculate RSI and Bollinger bands, detect re-entry signals, and call a generic execute_signal helper to place a trade on a venue. While trading on Avantis may be compatible with part of the description, the code does not implement most of the declared capabilities: no Indian equities via Zerodha, no research endpoints, no copy-trading, no marketplace, and no explicit Ostium/Aster integrations in this chunk. This is therefore a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code does support a substantial subset of the declared purpose: programmatic perpetual trading on Ostium, Aster, and Avantis via Maxxit Lazy Trading API, including balance checks, position management, leverage/notional handling, and TP/SL updates. However, the description claims several additional major capabilities that are not present anywhere in this code chunk. There is no Zerodha Kite integration, no Indian stock handling, no equity research functionality, no copy-trading logic, and no blockchain marketplace or Arbitrum Sepolia interactions. The code instead focuses narrowly on shared strategy utilities and perp trade execution using Maxxit plus Binance market data. Because the declared description materially overstates the implemented capabilities, this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a wide multi-feature trading skill spanning multiple venues and capabilities, including Ostium, Aster, Avantis, Zerodha Kite, research, copy-trading, and an Alpha Marketplace. The supplied code does not implement that broad functionality. Instead, it implements one narrow automated strategy: it pulls Binance klines, computes a taker-buy ratio signal, and uses Maxxit programmatic endpoints to manage perpetual positions on only OSTIUM or AVANTIS. This is a materially different primary purpose from the declared broad platform/API capability set. The Binance dependency is also an undeclared external resource in the description. While some overlap exists with Maxxit perpetual trading and position management, the chunk substantially underdelivers on the declared scope and adds a specific autonomous trading behavior not reflected in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description advertises a large multi-capability trading skill spanning multiple venues and features, but the supplied code chunk implements only a narrow automated strategy: a VWAP crossover bot for Maxxit Lazy Trading. It supports only OSTIUM and AVANTIS as CLI venue choices, not Aster. It fetches candlestick data from Binance, computes VWAP and EMA, checks existing positions and balances through Maxxit programmatic APIs, and opens a long or short position with preset take-profit/stop-loss values. There is no implementation of Zerodha Kite, Indian stock research, copy-trading, marketplace behavior, or trustless/ZK/Arbitrum functionality. This is a material description-to-behavior mismatch in scope and capabilities, even though the code does fit one subset of the declared Maxxit perpetual trading theme.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill prominently enables automated trading and strategy execution but lacks an equally prominent user warning that actions may be high-risk and financially irreversible. In a tool that can place leveraged perpetual trades and brokerage orders, insufficient warning and consent language increases the chance of harmful or unintended financial loss.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
97% confidence
Finding

The skill includes self-modification instructions that fetch and reinstall the skill via a remote package manager command. Self-update behavior is especially dangerous in an agent context because it can replace trusted behavior with unreviewed code and bypass normal change-control expectations.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

Skill Maintenance

  • If the user asks OpenClaw to update this skill, run:
bash
npx clawhub@latest install maxxit-lazy-trading --force

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The skill references high-value Zerodha credentials and access tokens stored in environment/SSM for brokerage actions. In a powerful trading skill with broad tool access and destructive endpoints, exposing or mishandling these credentials could enable unauthorized account access, portfolio disclosure, and live order placement or cancellation.

Content

Scanner excerpt · SKILL.md (reported line 1912)May include surrounding context.

md
|----------|-------------|--------|
| `KITE_API_KEY` | Zerodha Kite Connect API key | SSM (set in OpenClaw UI) |
| `KITE_API_SECRET` | Zerodha Kite Connect API secret | SSM (set in OpenClaw UI) |
| `KITE_ACCESS_TOKEN` | Short-lived access token (expires daily) | SSM (auto-stored after OAuth) |
| `KITE_USER_NAME` | Zerodha display name for status/UI | SSM (auto-stored after OAuth) |

### Auth Pre-Flight

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The skill exposes a session-deletion endpoint that invalidates Zerodha authentication and removes the token from SSM. This is a destructive action against account access state, and if triggered accidentally or through prompt confusion it can deny service and interrupt brokerage operations.

Content

Scanner excerpt · SKILL.md (reported line 1979)May include surrounding context.

-H "X-KITE-ACCESS-TOKEN: ${KITE_ACCESS_TOKEN}"

text

#### DELETE /zerodha/session

Invalidate Zerodha session and remove token from SSM.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Order cancellation is a legitimate feature, but it is a high-impact state-changing action in a live brokerage environment. If the agent routes a request incorrectly or acts on ambiguous instructions, it can cancel protective, entry, or exit orders and materially affect financial outcomes.

Content

Scanner excerpt · SKILL.md (reported line 2098)May include surrounding context.

-d '{"variety": "regular", "price": 2500, "order_type": "LIMIT"}'

text

#### DELETE /zerodha/orders?orderId=<id>

Cancel an order.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Deleting a GTT trigger removes automated target/stop-loss protection, which can expose a user to unmanaged downside or missed exits. In this financial context, destructive trigger deletion is inherently high risk and should not be callable from loosely interpreted user intent.

Content

Scanner excerpt · SKILL.md (reported line 2198)May include surrounding context.

}'

text

#### DELETE /zerodha/gtt?triggerId=<id>

Delete an existing GTT trigger.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The bot can automatically open leveraged positions based solely on market signals, with no user confirmation, dry-run default, or explicit safety interlock. In a live-trading skill, this materially increases the risk of unauthorized or accidental financial loss from bad signals, misconfiguration, or manipulated inputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code automatically opens a leveraged trading position via the open-position API when a signal is detected, which is a safety-critical and financially irreversible operation. Although there is logging after execution, there is no prior confirmation prompt, cautionary disclosure, or explicit user-facing warning before submitting the trade.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script can automatically close and open live leveraged positions without interactive confirmation, simulation, or hard safety interlocks. In the context of an agent skill that may be invoked programmatically, this is dangerous because bad inputs, misconfiguration, or faulty signals can immediately trigger irreversible financial actions and amplified losses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file instructs users to execute perpetual futures trades, send trading signals, and run predefined trading strategies, which can directly affect user funds. The description does not include any caution about financial loss, automated execution risk, or the possibility of placing real trades on supported venues.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:1963