Back to skill

Security audit

CoolTrade 股票行情与分析大师

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated market-data purpose, but it handles API credentials and alert-changing requests in ways users should review before installing.

Install only if you trust CoolTrade with your API key, market queries, crypto interests, and alert settings. Do not hardcode or share the API key; rotate it if it has been placed in URLs or committed anywhere. Treat generated trading signals as informational only, and review alert create/delete actions carefully.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
openclaw.json:17
Finding

API Credential Exposed in HTTP URL Paths

Content
View full analysis

Vulnerability Details

File Location: openclaw.json:17, openclaw.json:31, openclaw.json:45, openclaw.json:59, openclaw.json:73, openclaw.json:87, openclaw.json:101, openclaw.json:110, openclaw.json:123, openclaw.json:143, and openclaw.json:152
Vulnerability Type: Credential exposure through URL paths
Risk Level: High

The following representative configuration demonstrates the issue:

json
{
  "name": "cooltrade_stock_quote",
  "description": "Get deep market quote and financial fundamentals for any A-share stock (China Market). Provide stock name or code.",
  "type": "http",
  "config": {
    "method": "GET",
    "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/ashare/quote/",
    "params": {
      "stock": "{{query}}"
    }
  }
}

The same credential-in-path construction is used by all configured CoolTrade HTTP endpoints, including market-data, report, cryptocurrency, and alert-management operations.

Technical Analysis

The user's COOLTRADE_API_KEY is interpolated directly into the URL path. Although HTTPS protects the request while it is in transit, full URLs are commonly retained outside the encrypted transport layer by origin-server access logs, reverse proxies, application-performance monitoring systems, diagnostic traces, exception reports, and client-side request histories.

Authentication credentials should not be placed in URL paths or query strings. They should be transmitted through an authorization header or another dedicated secret-bearing header and redacted from telemetry. Sending the key to CoolTrade is necessary for the declared functionality, but exposing it through a broadly logged URL field is not necessary and violates least-disclosure principles.

Attack Path

  1. A user installs the Skill and supplies a valid COOLTRADE_API_KEY.
  2. OpenClaw interpolates the key into the URL path whenever a Skill endpoint i ...[truncated 1149 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove {{COOLTRADE_API_KEY}} from every URL path.

  • Send the credential through a standard header, such as:

    http
    Authorization: Bearer {{COOLTRADE_API_KEY}}
    

    Alternatively, use a dedicated header such as X-API-Key if required by the service.

  • Update the CoolTrade server to reject credentials supplied through URLs.

  • Configure clients, reverse proxies, API gateways, and telemetry systems to redact authorization headers and other secret-bearing fields.

  • Search existing access logs, diagnostics, and monitoring records for exposed keys, then securely purge or restrict those records.

  • Rotate all keys that have previously been used with the URL-based authentication scheme.

  • If supported by the platform, use distinct scoped credentials for read-only market data and state-changing alert management.

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:9
Finding

Documentation Encourages Hard-Coding an API Key into URL Configuration

Content
View full analysis

Vulnerability Details

File Location: README.md:9
Vulnerability Type: Unsafe credential-handling guidance
Risk Level: Medium

markdown
## Usage
Simply replace `sk-XXXXX` in the url configs with your actual CoolTrade API Key in OpenClaw ecosystem.

Technical Analysis

The documentation explicitly directs users to replace a placeholder in URL configuration with their real API key. This can persist the secret in plaintext configuration and may result in its inclusion in source control, shared archives, published packages, backups, support bundles, or configuration-management systems.

This guidance is also inconsistent with the credential-template mechanism declared in openclaw.json, which defines COOLTRADE_API_KEY as a separately supplied credential. Users should not be instructed to edit URL configuration with a live secret.

Attack Path

  1. A user follows the README and inserts a live API key directly into URL configuration.
  2. The modified configuration is saved in the project directory.
  3. The user commits the file, shares the package, uploads a support archive, or exposes it through a backup or build artifact.
  4. An attacker obtains the configuration and extracts the plaintext key.
  5. The attacker reuses the key against CoolTrade services.
  6. The attacker gains whatever API capabilities are assigned to that credential, potentially including market-data access and alert management.

Impact Assessment

This issue can expose the CoolTrade API credential to anyone who gains access to the modified configuration or its copies. The resulting privileges are limited to the server-side scope of the compromised key, but may include quota consumption, access to account-associated alerts, and creation or deletion of alerts.

No evidence indicates that the README itself transmits information or executes code. The risk arises because its instructions encourage users to persist sensitive informati ...[truncated 25 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to replace URL placeholders with a real API key.

  • Document use of OpenClaw's credential store or environment-based secret injection.

  • State explicitly that users must never commit, publish, or share API keys.

  • Provide an example that uses a secret reference in an authorization header rather than a literal credential:

    text
    Authorization: Bearer {{COOLTRADE_API_KEY}}
    
  • Add secret-bearing local configuration files to .gitignore where applicable.

  • Recommend immediate credential rotation if a key is accidentally committed or distributed.

  • Add automated secret scanning to the release and repository workflow.

T09 · Insecure Skill Coding Practices

Warning
Location
openclaw.json:121
Finding

State-Changing Alert Operations Use Unsafe GET Requests

Content
View full analysis

Vulnerability Details

File Location: openclaw.json:121-134 and openclaw.json:150-155
Vulnerability Type: Unsafe HTTP method usage for state-changing operations
Risk Level: Medium

Alert creation is configured as follows:

json
{
  "name": "cooltrade_alert_create",
  "description": "Create a stock price alert for any A-share stock. Call this when the user says things like 'notify me when X drops below Y', 'alert me if stock breaks MA60', 'tell me when price rises above Z'. Supported conditions: price_below, price_above, pct_down (daily drop %), pct_up (daily rise %), ma_break_below (breaks below N-day MA), ma_break_above (breaks above N-day MA). Channels: weixin, telegram, both.",
  "type": "http",
  "config": {
    "method": "GET",
    "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/alert/create/",
    "params": {
      "stock": "{{stock}}",
      "condition": "{{condition}}",
      "threshold": "{{threshold}}",
      "channel": "{{channel}}",
      "repeat": "{{repeat}}",
      "note": "{{note}}"
    }
  }
}

Alert deletion is configured as follows:

json
{
  "name": "cooltrade_alert_delete",
  "description": "Disable or delete a stock price alert by its ID. Call this when the user says 'cancel alert', 'remove my alert', 'stop monitoring'. First use cooltrade_alert_list to get the alert ID.",
  "type": "http",
  "config": {
    "method": "GET",
    "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/alert/delete/",
    "params": {
      "id": "{{alert_id}}"
    }
  }
}

Technical Analysis

HTTP GET is defined as a safe method and should not modify server state. Infrastructure and clients may cache, retry, prefetch, inspect, or replay GET requests under the assumption that they are read-only. Using GET to create or delete alerts therefore makes state changes vulnerable to unintended repet ...[truncated 1620 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace alert creation with an authenticated POST endpoint.
  • Replace alert deletion with an authenticated DELETE endpoint, such as DELETE /alert/{id}, or a documented authenticated POST action if platform constraints require it.
  • Move alert parameters into a JSON request body rather than the URL.
  • Move the API credential into an authorization header.
  • Reject state-changing GET requests on the server.
  • Add idempotency keys for alert creation to prevent duplicate mutations during retries.
  • Apply replay protection and verify that authorization is checked for every alert operation.
  • Ensure logs redact credentials, alert notes, and other sensitive request fields.
  • Require explicit user confirmation before destructive deletion where supported by the agent platform.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a broad set of financial data, analysis, reporting, and notification capabilities. The supplied code does none of these things. Its sole behavior is checking for a local configuration file, parsing it, and returning a skills list. This is a materially different primary purpose from the declared description, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly instructs users to substitute their real API key directly into URL configuration values. Putting secrets in URLs is unsafe because URLs are commonly logged by clients, proxies, servers, browser history, and observability tooling, which can expose the credential and enable unauthorized API access. In this skill context, the issue is more dangerous because the package is intended for agent integrations and automation, where configs, logs, and shared deployment artifacts are often widely distributed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly advertises automated alert delivery to WeChat and Telegram but does not prominently warn users that stock symbols, thresholds, schedules, and related monitoring metadata may be transmitted to external services. This can expose sensitive investment interests or behavioral patterns to third-party platforms without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill presents AI-generated crypto buy/sell signals, entry zones, targets, and stop-loss levels in a way that can be interpreted as actionable financial advice, yet no prominent disclaimer states that the output may be inaccurate or unsuitable for investment decisions. In a trading context, users may rely on these recommendations and suffer financial loss, especially given the volatility of crypto markets.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This request sends user input to an external third-party service and embeds the API key directly in the URL path. Putting secrets in URLs is dangerous because URLs are commonly logged by clients, proxies, gateways, and server access logs, which can expose the credential beyond its intended scope.

Content

Scanner excerpt · openclaw.json (reported line 17)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/ashare/quote/",
        "params": {
          "stock": "{{query}}"
        }

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This request transmits user-supplied stock queries to an external service while placing the API key in the URL path. URL-based secret handling increases exposure through logs, monitoring systems, browser history equivalents, and intermediary infrastructure, making credential leakage more likely.

Content

Scanner excerpt · openclaw.json (reported line 29)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/ashare/news/",
        "params": {
          "stock": "{{query}}"
        }

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The skill forwards financial lookup requests to a third-party endpoint and includes the secret in the request URL. In this context the main security issue is not merely external transmission, but transmission with poor secret hygiene that can leak the API key via standard HTTP logging and observability tooling.

Content

Scanner excerpt · openclaw.json (reported line 41)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/ashare/financials/",
        "params": {
          "stock": "{{query}}"
        }

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The index lookup calls a third-party API and exposes the credential in the URL path. Because URLs are routinely captured in infrastructure logs and telemetry, compromise of those systems could reveal the key and enable unauthorized API usage.

Content

Scanner excerpt · openclaw.json (reported line 53)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/global/index/",
        "params": {
          "index": "{{query}}"
        }

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This US stock quote endpoint transmits user queries to a third party and carries the API key in the URL. That combination creates a realistic credential exposure risk and may also leak user interest data to the external provider without an explicit warning in the manifest.

Content

Scanner excerpt · openclaw.json (reported line 65)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/us_stock/quote/",
        "params": {
          "stock": "{{query}}"
        }

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The futures quote request sends user parameters off-platform and embeds the authentication secret in the URL. URL-carried secrets are particularly problematic because they persist in logs and tracing systems, increasing the blast radius if any supporting system is compromised.

Content

Scanner excerpt · openclaw.json (reported line 77)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/futures/quote/",
        "params": {
          "symbol": "{{query}}"
        }

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

Even without additional query parameters, this daily report endpoint still places the API key in the URL for an external request. The vulnerability remains because the secret itself is exposed to logging and intermediary systems, independent of the sensitivity of the request body.

Content

Scanner excerpt · openclaw.json (reported line 89)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/daily-report/"
      }
    },
    {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest explicitly advertises AI-generated buy/sell signals and coin recommendations but does not include any warning that the output may be inaccurate, unsuitable, or not financial advice. In this context, the missing warning increases the chance that users rely on speculative automated recommendations as actionable trading guidance, especially for volatile crypto assets.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

This crypto quote endpoint both transmits user interest in specific crypto assets to a third party and embeds the API key in the URL. In the context of speculative trading signals, leakage of both user query patterns and credentials increases privacy and account-abuse risk.

Content

Scanner excerpt · openclaw.json (reported line 98)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/crypto/quote/",
        "params": {
          "symbol": "{{symbol}}"
        }

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The crypto screener is described as responding to broad requests such as 'which crypto should I buy' and returning ranked buy candidates, which can cause the agent to provide personalized-looking investment recommendations without meaningful scope limits or suitability checks. In this skill context, that is risky because it operationalizes financial advice through an API workflow and may trigger on ordinary conversation rather than an explicit request for informational market data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

The crypto screener endpoint sends external requests with the API key in the URL, creating a strong likelihood of credential exposure through routine infrastructure logging. Because this tool may be invoked for broad investment-style prompts, it also increases the volume and ambiguity of externally transmitted user intent data.

Content

Scanner excerpt · openclaw.json (reported line 110)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/crypto/screener/",
        "params": {
          "top": "{{top_n}}"
        }

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

This alert-creation endpoint is especially sensitive because it transmits not only the secret in the URL but also user-configured monitoring preferences, thresholds, notification channels, and notes to a third party. If the key leaks, an attacker may be able to create or manipulate alerts; meanwhile the transmitted alert metadata can expose user behavior and potentially personal information.

Content

Scanner excerpt · openclaw.json (reported line 122)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/alert/create/",
        "params": {
          "stock": "{{stock}}",
          "condition": "{{condition}}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

Listing alerts reveals user monitoring configuration to a third party while the credential is embedded in the URL. Exposure of the URL can allow unauthorized parties to enumerate alert data or abuse the API key, and the returned data may reveal portfolio interests or behavioral patterns.

Content

Scanner excerpt · openclaw.json (reported line 139)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/alert/list/"
      }
    },
    {

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

This delete operation uses GET to perform a state-changing action and also includes the API key in the URL, compounding the risk. GET-based destructive actions can be triggered unintentionally by prefetching, link following, or caching behaviors, while URL-based secret exposure can enable unauthorized deletions if the key leaks.

Content

Scanner excerpt · openclaw.json (reported line 148)May include surrounding context.

json
"type": "http",
      "config": {
        "method": "GET",
        "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/alert/delete/",
        "params": {
          "id": "{{alert_id}}"
        }

Static analysis

No suspicious patterns detected.