Back to skill

Security audit

blave-quant

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a trading and market-data reference skill, but it also tells agents to download and run remote Python strategy code without a clear sandbox or approval boundary.

Install only if you are comfortable with an agent handling financial API credentials. Use least-privilege keys, disable withdrawals unless absolutely needed, prefer read-only keys for research, and keep IP allowlisting enabled. Do not run purchased, shared, or private marketplace strategies through this skill unless you manually review the code and execute it in a sandbox with no inherited exchange credentials or broad filesystem access.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/marketplace.md:29
Finding

Remote Marketplace Strategy Code Is Executed Without an Enforced Security Boundary

Content
View full analysis

Vulnerability Details

File Location: references/marketplace.md:29-39, 90-93, 135-142
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Relevant snippets:

markdown
Fetch strategy code (requires purchase):
GET /openclaw/marketplace/strategies/{id}/code

Response: `{"code": "..."}` — save to `.py` and run with `python3`.

**Flow when user wants to run a purchased strategy:**
1. `GET /openclaw/marketplace/my/purchases` — show the list
2. User picks one → `GET /openclaw/marketplace/strategies/{id}/code`
3. Save to `/tmp/<filename>.py`
4. **Check for multi-strategy bundle** — scan for `# ===== STRATEGY \d+:` markers:
   - If found: split into separate files and deploy each
   - If not found: `python3 filename.py`
markdown
**Deploying** — when downloaded code contains `# ===== STRATEGY N:` markers:
1. Split at each marker into N separate strings
2. Save each to `/tmp/<name_slug>.py`
3. Security scan each file separately; skip any that exit 2 (critical)
4. Move approved files to `strategies/<name_slug>.py` and run each with `python3`
markdown
View strategies shared with you:
GET /openclaw/marketplace/my/shared-with-me

Download code (works for owned, purchased, or shared strategies):
GET /openclaw/marketplace/strategies/{id}/code`
Response: `{"code": "..."}` — save to `.py` and run with `python3`.

Technical Analysis

The Skill instructs the Agent to retrieve Python source from a remote marketplace and execute it with the local Python interpreter. The effective payload is controlled by the marketplace strategy author and can change independently of the reviewed Skill package.

The ordinary purchased/shared strategy path executes a single-file response directly. A security scan is mentioned only for files recognized as multi-strategy bundles, and the document does not identify or implement a scanner, define the checks performed, or ...[truncated 2222 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions that directly execute marketplace-provided source with the host Python interpreter.
  2. Treat purchased, shared, private, bundled, and single-file strategies uniformly as untrusted code.
  3. Require a pinned content digest or signed artifact and verify it before review and execution. Display the strategy identity, publisher, version, and digest to the user.
  4. Implement a real, fail-closed review gate. If scanning fails, is unavailable, or returns an unknown result, execution must stop.
  5. Require explicit user approval after presenting the reviewed source, provenance, requested permissions, and scan result.
  6. Execute approved strategies in an isolated container or equivalent sandbox with:
    • No inherited Blave or exchange credentials.
    • A read-only root filesystem and a dedicated writable working directory.
    • No host filesystem mounts except narrowly selected inputs.
    • Network access denied by default and allowlisted only when required.
    • A non-privileged user, dropped capabilities, resource limits, and execution timeouts.
  7. Do not move remotely supplied files into trusted strategies/ paths until verification succeeds.
  8. Use server-side immutable versions so code cannot change after purchase or approval without generating a new version and requiring renewed review.
  9. Avoid predictable temporary filenames and securely create temporary files, while recognizing that safe temporary-file handling alone does not mitigate arbitrary code execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (144)

YARA rule 'ransomware_behavior': Ransomware-like patterns (mass encryption, ransom notes) [malware]

Critical
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/gateio-api-reference.md (reported line 72)May include surrounding context.

resp.ok: raise RuntimeError(f"{resp.status_code} {resp.text}") return resp.json()

text

**Common mistakes:**
- Signing `/spot/orders` instead of `/api/v4/spot/orders` — the `/api/v4` prefix is part of the signed path
- Using milliseconds for `Timestamp` — Gate.io uses **seconds**
- Hashing a re-serialized body that differs from the bytes actually sent — sign the exact string you send
- Query string must match exactly what is sent (unencoded form, e.g. `currency_pair=BTC_USDT&limit=10`)

## Spot

| Operation | Method | Path | Auth |
|---|---|---|---|
| Ticker | GET | `/spot/tickers?currency_pair=BTC_USDT` | public |
| Order book | GET | `/spot/order_book?currency_pair=BTC_USDT` | public |
| Candlesticks | GET | `/spot/candlesticks?currency_pair=BTC_USDT&interval=1h` | public |
| Balances | GET | `/spot/accounts` | signed |
| Create order | POST | `/spot/orders` | signed |
| Batch orders | POST | `/spot/batch_orders` | signed |
| List orders | GET | `/spot/orders?curren

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The documentation explicitly instructs the agent to fetch remote Python code, save it to disk, and run it with python3. This is direct arbitrary code execution from a remote service and creates an immediate path to credential theft, host compromise, lateral movement, destructive actions, or covert trading/account abuse if a purchased or shared strategy is malicious or tampered with.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
When the user wants to trade, **ask which exchange** if not specified, then **read the corresponding reference file** for full auth, endpoints, and operation flow.

| Exchange | .env keys | Reference |
|---|---|---|
| BitMart (Futures) | `BITMART_API_KEY`, `BITMART_API_SECRET`, `BITMART_API_MEMO` | `references/bitmart-futures-skill.md` |
| BitMart (Spot) | same as above | `references/bitmart-spot-skill.md` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/binance-api-reference.md (reported line 218)May include surrounding context.

md
`quantity` or `closePosition=true`/`workingType`
- Response: `algoId` (int, keep as string) + `algoStatus` (NEW/TRIGGERED/CANCELED/EXPIRED)
- Conditional orders do NOT appear in `GET /fapi/v1/openOrders` — query
  `GET /fapi/v1/openAlgoOrders`; cancel one via `DELETE /fapi/v1/algoOrder`
  (`algoId` or `clientAlgoId`); cancel all via `DELETE /fapi/v1/algoOpenOrders?symbol=`
  (`DELETE /fapi/v1/allOpenOrders` only clears regular orders)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
83% confidence
Finding

The reference advertises a bulk-cancel endpoint keyed by symbol and describes it without any warning about high-blast-radius misuse. In an agentic trading context, a malformed, overbroad, or manipulated symbol parameter could wipe protective algo orders for a market, exposing positions to large losses.

Content

Scanner excerpt · references/binance-api-reference.md (reported line 219)May include surrounding context.

md
- Response: `algoId` (int, keep as string) + `algoStatus` (NEW/TRIGGERED/CANCELED/EXPIRED)
- Conditional orders do NOT appear in `GET /fapi/v1/openOrders` — query
  `GET /fapi/v1/openAlgoOrders`; cancel one via `DELETE /fapi/v1/algoOrder`
  (`algoId` or `clientAlgoId`); cancel all via `DELETE /fapi/v1/algoOpenOrders?symbol=`
  (`DELETE /fapi/v1/allOpenOrders` only clears regular orders)

**Futures order params:** `symbol`, `side` (BUY/SELL), `positionSide` (BOTH/LONG/SHORT), `type` (LIMIT/MARKET/STOP/STOP_MARKET/TAKE_PROFIT/TAKE_PROFIT_MARKET/TRAILING_STOP_MARKET), `quantity`, `price`, `stopPrice`, `timeInForce`, `reduceOnly`, **`newClientOrderId` (REQUIRED: must start with `x-52DDFAFN`, ≤36 chars)**

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The all-open-orders cancellation endpoint is a high-impact administrative action, and the reference presents it as a normal operation without emphasizing the danger of mass order removal. In this skill's trading context, misuse could instantly remove all standing futures protection and execution logic, leading to uncontrolled exposure or losses.

Content

Scanner excerpt · references/binance-api-reference.md (reported line 220)May include surrounding context.

md
- Conditional orders do NOT appear in `GET /fapi/v1/openOrders` — query
  `GET /fapi/v1/openAlgoOrders`; cancel one via `DELETE /fapi/v1/algoOrder`
  (`algoId` or `clientAlgoId`); cancel all via `DELETE /fapi/v1/algoOpenOrders?symbol=`
  (`DELETE /fapi/v1/allOpenOrders` only clears regular orders)

**Futures order params:** `symbol`, `side` (BUY/SELL), `positionSide` (BOTH/LONG/SHORT), `type` (LIMIT/MARKET/STOP/STOP_MARKET/TAKE_PROFIT/TAKE_PROFIT_MARKET/TRAILING_STOP_MARKET), `quantity`, `price`, `stopPrice`, `timeInForce`, `reduceOnly`, **`newClientOrderId` (REQUIRED: must start with `x-52DDFAFN`, ≤36 chars)**

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

These sections enumerate endpoints for placing orders, canceling orders, closing positions, changing leverage/margin mode, and using kill switches, yet they do not clearly warn that these operations can execute or unwind real positions on live accounts. Because the skill metadata explicitly includes exchange trading functions and the document says to default to live unless paper trading is explicitly requested, this omission makes accidental destructive trading significantly more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section provides ready-to-run examples for live order placement, cancellation, leverage changes, position-mode changes, and funds transfers without a strong top-level warning about real financial consequences. In a skill that can be consumed by an autonomous agent, such examples materially increase the chance of unintended live trading or asset movement from copied workflows.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/bitmart-spot-authentication.md (reported line 111)May include surrounding context.

KEYED Verification (simplest)

bash
curl -s -H "X-BM-KEY: $BITMART_API_KEY" \
  -H "User-Agent: bitmart-skills/spot/v2026.3.23" \
  -H "X-BM-BROKER-ID: BlaveData666666" \
  'https://api-cloud.bitmart.com/account/v1/wallet' | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/bitmart-spot-authentication.md (reported line 136)May include surrounding context.

md
TIMESTAMP=$(date +%s000)
BODY='{}'
SIGN=$(echo -n "${TIMESTAMP}#${BITMART_API_MEMO}#${BODY}" | openssl dgst -sha256 -hmac "$BITMART_API_SECRET" | awk '{print $NF}')
curl -s -X POST 'https://api-cloud.bitmart.com/spot/v4/query/open-orders' \
  -H "User-Agent: bitmart-skills/spot/v2026.3.23" \
  -H "X-BM-BROKER-ID: BlaveData666666" \
  -H "Content-Type: application/json" \

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The margin scenario allows borrowing and placing a leveraged market order before presenting prominent upfront risk disclosures about debt, interest accrual, liquidation, and loss amplification. Because this skill can trigger real trading actions, omitting pre-trade warnings and acknowledgment makes accidental high-risk financial harm substantially more likely.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/kucoin-api-reference.md (reported line 64)May include surrounding context.

md
import requests
from dotenv import dotenv_values

env = dotenv_values(".env")
API_KEY        = env["KUCOIN_API_KEY"]
API_SECRET     = env["KUCOIN_API_SECRET"]
API_PASSPHRASE = env["KUCOIN_API_PASSPHRASE"]

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file materially expands the skill from market data and trading API usage into a remote code marketplace that supports uploading, downloading, sharing, and executing Python source. That is a significant capability jump because it introduces arbitrary code handling and execution paths unrelated to normal trading functions, increasing the attack surface for supply-chain compromise and agent misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions normalize downloading untrusted code and executing it without any warning, verification, or trust boundary discussion. Even if execution were intended elsewhere, omitting risk disclosure and safety requirements makes unsafe automation more likely and increases the chance that users or agents will run hostile code with valuable API keys present.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The marketplace submission, private upload, sharing, and code download features enable arbitrary source-code publication and distribution through the skill. In the context of an agent that also has trading credentials and operational capabilities, this creates a software supply-chain channel that can be used to propagate malicious strategies to other users or to trick the agent into handling attacker-controlled code.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The multi-strategy bundle flow instructs splitting attacker-controlled content into multiple files, moving approved files into a strategies directory, and executing each with python3. This scales the arbitrary code execution risk across several payloads and could help attackers smuggle malicious components inside bundles, while the mention of a security scan is insufficient without defined isolation and trust controls.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/marketplace.md (reported line 121)May include surrounding context.

Remove a user's access:

text
DELETE /openclaw/marketplace/strategies/{id}/share
Content-Type: application/json

{"user_id": 456}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly supports authenticated order placement and position management across many exchanges, but the overview does not prominently warn that these actions can execute real trades or move funds. In an agent setting, missing user-facing risk and confirmation guidance materially increases the chance of unintended financial transactions, especially because the file normalizes direct API use and lists many trading capabilities together.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file enumerates numerous API keys, secrets, passphrases, and memos without any accompanying warning that these credentials are highly sensitive and must never be logged, echoed, committed, or exposed to users. In a multi-exchange trading skill, such omissions raise the risk of credential leakage and full account compromise across several venues if the agent or operator handles them unsafely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx -y skills add ... without pinning the skills package to a specific version or integrity hash. That creates a supply-chain risk: a future compromised or malicious package version could be fetched and executed automatically during install or update, and the -y flag further reduces user friction before execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The update path repeats the same unpinned npx -y skills add ... pattern, which means every update reintroduces the same remote code execution and supply-chain exposure. Because this command overwrites the existing skill in place, a compromised upstream package or dependency could silently replace trusted content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description heavily mixes English with Traditional Chinese and includes substantial Chinese-only capability text, implying the skill is oriented toward a specific locale/language without stating that users may choose their preferred language. This can violate language/locale policy when the skill does not explicitly offer opt-in or language choice.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
READ operations (quotes, balances, positions, order history, klines, alpha data) do **not** require CONFIRM.

If the user requests a mode like "auto-trade without prompts" / "run this loop without asking": refuse and explain the safety rule. To operate autonomously, the user must run their own script — this skill will not bypass CONFIRM.

Not financial advice. Trading carries significant risk of loss.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The reference includes concrete instructions for loading API credentials from .env, generating signed requests, and issuing authenticated network calls, but it does not warn that these operations use live trading credentials or that requests can move funds and place orders. In an agent skill that can trade across multiple exchanges, this omission materially increases the risk of unsafe automation, accidental live execution, and credential misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document enumerates live asset-transfer, order-placement, leverage, margin, and cancel-all endpoints without prominent warnings that they are destructive and affect real accounts. Because this skill explicitly supports trading and wallet transfers, the missing guardrails make accidental liquidation, unintended order placement, or irreversible fund movement much more likely in agent-driven workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.