Back to skill

Security audit

Lighter

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed Lighter trading integration, but its live order script can submit mainnet trades without the confirmation boundary the docs say is mandatory.

Review before installing for live trading. Read-only market and account queries are coherent, but do not expose a funded or high-limit Lighter API key until the order script requires an explicit confirmation or dry-run flow, dependencies are pinned and verified, and order sizing/price conversion is fixed. Use isolated credentials with limited trading authority.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:78
Finding

Unpinned and inconsistently named trading dependencies create supply-chain risk

Content
View full analysis
=2.31.0 # Optional: lighter-sdk>=1.0.3 eth-account>=0.12.0 # Only install if you need order placement capabilities ``` ### Technical Analysis The Skill instructs users to install `lighter-python` without pinning an exact version or verifying a package hash. It also directs users to a setup guide on the mutable `main` branch rather than a reviewed commit. Consequently, the code installed or followed later can differ from the version considered during this audit. The dependency documentation is internally inconsistent: `SKILL.md` names `lighter-python`, while `requirements.txt` refers to `lighter-sdk`. This increases the possibility that a user or automated agent installs the wrong package. Broad constraints such as `requests>=2.31.0` also do not provide reproducible dependency resolution. This finding is classified as insecure dependency management rather than remote payload execution. The audited project does not itself download or execute the linked GitHub file; the risk arises when a user follows the mutable installation and setup instructions. ### Attack Path 1. A dependency release, package account, transitive dependency, or mutable setup source is compromised, or a user selects the wrong package because of the inconsistent names. 2. The user or agent runs the documented `pip install` command or follows the changed setup guide. 3. Package installation or setup code executes with the privileges of the user performing the installation. 4. Malicious code can access files and environ ...[truncated 843 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/order.py:47
Finding

Live orders are submitted without the documented confirmation boundary

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/order.py:17
Finding

Binary floating-point conversion and hard-coded precision can alter signed order values

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tainted flow: 'headers' from os.environ.get (line 17, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/account.py (reported line 19)May include surrounding context.

python
headers = {"x-api-key": API_KEY}

response = requests.get(
    f"{API_BASE}/account?by=index&value={ACCOUNT_INDEX}",
    headers=headers
)

Tainted flow: 'ETH_ADDRESS' from os.environ.get (line 11, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/get_account_index.py (reported line 19)May include surrounding context.

python
sys.exit(1)

# Query account
response = requests.get(
    f"{API_BASE}/accountsByL1Address",
    params={"l1_address": ETH_ADDRESS}
)

Tainted flow: 'headers' from os.environ.get (line 21, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/positions.py (reported line 24)May include surrounding context.

python
headers = {"x-api-key": LIGHTER_API_KEY}
    
    try:
        response = requests.get(
            f"{API_BASE}/account?by=index&value={LIGHTER_ACCOUNT_INDEX}",
            headers=headers
        )

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description claims a broad Lighter protocol skill covering trading, prices, positions, and account queries. The actual code only lists markets via a public order books endpoint and prints market identifiers and types. This is materially narrower than the declared purpose. While market discovery is related to the Lighter protocol, the code does not implement the main declared capabilities such as trading, position management, or account data access.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · USAGE.md (reported line 103)May include surrounding context.

md
- Read-only calls first; simulate before any live order.
- Keep `confirm=true` mandatory for execution paths.
- Store keys only in `~/.openclaw/secrets.env`.
- Never echo or log private keys.

---

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill declares required environment variables and instructs the agent to access external network endpoints, but it does not declare any explicit tool scope such as allowed-tools or permissions. In an agent environment, missing capability scoping increases the chance that the skill can access secrets or make network calls without clear policy boundaries, which is risky for a trading-related integration handling API credentials.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · USAGE.md (reported line 24)May include surrounding context.

1) List all order books

bash
curl "https://mainnet.zklighter.elliot.ai/api/v1/orderBooks"

2) Get one market order book (ETH-USD usually market_id=1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script submits live orders immediately once invoked, with no confirmation prompt, dry-run mode, or explicit warning that it will execute a trade on mainnet. In a trading skill, that increases the risk of accidental or manipulated order placement from mistaken parameters, automation bugs, or unsafe agent behavior, potentially causing direct financial loss.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified with a lower-bound range (requests>=2.31.0) rather than an exact pinned version, which makes builds non-reproducible and can cause different environments to install different releases. In a security-sensitive skill that may interact with trading or account data, this increases supply-chain risk and complicates assurance that a known-safe version is being used.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
# Optional: lighter-sdk>=1.0.3 eth-account>=0.12.0
# Only install if you need order placement capabilities

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Because requests is not pinned, there is no way to verify from this manifest whether installation will resolve to a version affected by one of the listed advisories. This uncertainty is a real supply-chain security weakness: a fresh install could pull a vulnerable release, which matters more in a DEX/trading context where HTTP requests may carry API endpoints, credentials, or sensitive account interactions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.