Back to skill

Security audit

OKX Trade Kit

Security checks for vulnerabilities and agentic risk

Overview

This OKX trading skill fits its stated purpose, but it asks users to install mutable packages and store exchange credentials for live trading without enough hardening.

Review carefully before installing. Use demo or read-only mode first, verify the package source and version before running npx or npm install, avoid global installation where possible, use a dedicated OKX subaccount with least-privilege API keys and withdrawals disabled, and protect ~/.okx/config.toml with restrictive permissions such as a private directory and 0600 file mode.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20,48
Vulnerability Type: Unpinned npm/npx supply-chain dependency
Risk Level: Medium

Vulnerable Code:

text
1. **Skills(OpenClaw 用戶首選)** — `npx skills add okx/agent-skills`,一行搞掂
text
Run `npx skills add okx/agent-skills`, resolve any issues you encounter, then check the BTC price.

Technical Analysis

The Skill directs the agent to retrieve and execute the current registry-resolved version of okx/agent-skills through npx. It does not pin a reviewed version, verify a package digest or signature, or require inspection of the resolved package. Consequently, the code that executes can differ from the code present when this Skill was audited.

The broad instruction to “resolve any issues you encounter” also gives the agent discretion while installing external code. Although this is not itself evidence of malicious behavior, it increases the consequences of unsafe package output or installation instructions.

Attack Path

  1. An attacker compromises the referenced package, its publisher account, or a transitive dependency.
  2. The attacker publishes a malicious release under the package reference used by the Skill.
  3. A user or agent follows the documented npx skills add okx/agent-skills instruction.
  4. npx resolves and downloads the mutable package content.
  5. Package or lifecycle code executes with the invoking user's privileges.
  6. The malicious code may read local files, modify the agent environment, or target subsequently configured OKX credentials.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the invoking user's account. The accessible scope may include user-readable files, agent configuration, installed skills, and any OKX credentials stored in ~/.okx/config.toml. If exposed credentials have live trading permission, an attacker could submit or manipulate trades within the ...[truncated 161 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specific, reviewed release rather than resolving the latest available version.
  • Verify package provenance, signatures, and integrity hashes before execution.
  • Document the expected publisher, registry, version, and checksum.
  • Review package lifecycle scripts and transitive dependencies before recommending installation.
  • Prefer installation in a restricted or isolated environment without access to trading credentials.
  • Configure credentials only after package validation is complete.
  • Replace the open-ended instruction to resolve arbitrary installation issues with narrowly scoped, documented troubleshooting steps.

T08 · Insecure Dependencies

Warning
Location
references/mcp-setup.md:4
Finding

Unpinned Global Installation of Trading Packages

Content
View full analysis

Vulnerability Details

File Location: references/mcp-setup.md:4-7
Vulnerability Type: Unpinned global npm dependencies
Risk Level: Medium

Vulnerable Code:

bash
npm install -g @okx_ai/okx-trade-mcp @okx_ai/okx-trade-cli

Technical Analysis

The setup guide globally installs two mutable npm packages without exact version constraints, a lockfile, integrity hashes, or signature verification. npm installation can execute package lifecycle scripts, and global installation places commands into shared executable locations associated with the user's npm environment.

The audited project contains no local implementation of these packages, so their effective behavior is outside the reviewed artifact and may change independently after this audit.

Attack Path

  1. An attacker compromises either npm package, a maintainer account, or a transitive dependency.
  2. A malicious version is published to the package registry.
  3. A user follows the documented global installation command.
  4. npm downloads the malicious current release and may execute its lifecycle scripts.
  5. The installed binaries persist in the user's global npm command path.
  6. Malicious code can access files available to the invoking user, including OKX configuration created during later setup.

Impact Assessment

Exploitation could result in arbitrary code execution with the privileges of the account running npm. The attacker could access user files, alter globally installed command-line tools, or steal plaintext OKX API credentials. Compromised trading credentials may permit account inspection and unauthorized trading according to the permissions assigned to the key. System-wide impact would be greater if the command were run with elevated privileges, although the documentation does not instruct users to use sudo or another privilege-escalation mechanism.

Remediation
View remediation

Remediation Suggestions

  • Specify exact reviewed versions for both packages.
  • Publish and verify cryptographic integrity values or trusted signatures.
  • Use a lockfile or equivalent reproducible dependency manifest where possible.
  • Avoid global installation; prefer a project-local or isolated installation with restricted filesystem access.
  • Audit lifecycle scripts and transitive dependencies before deployment.
  • Ensure installation occurs before sensitive credentials are created or made available.
  • Explicitly warn users not to run the installation with elevated privileges.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:64
Finding

Plaintext API Credential File Created Without Enforced Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:64-77
Vulnerability Type: Insecure storage permissions for plaintext secrets
Risk Level: Medium

Vulnerable Code:

bash
mkdir -p ~/.okx && cat > ~/.okx/config.toml << 'EOF'
default_profile = "demo"

[profiles.live]
api_key    = "your-live-api-key"
secret_key = "your-live-secret-key"
passphrase = "your-live-passphrase"

[profiles.demo]
api_key    = "your-demo-api-key"
secret_key = "your-demo-secret-key"
passphrase = "your-demo-passphrase"
demo       = true
EOF

Technical Analysis

The documented command stores live and demo API credentials in a plaintext TOML file. It does not explicitly set the ~/.okx directory to mode 0700 or the credential file to mode 0600. The resulting permissions therefore depend on the user's current umask and any pre-existing directory or file permissions.

On a multi-user host or an environment with permissive defaults, another local account or process may be able to read the file. The command also overwrites an existing file without first validating its ownership, type, or permissions, creating additional risk if the path has been manipulated.

Attack Path

  1. A user runs the documented command under a permissive umask or with an inadequately protected pre-existing ~/.okx directory.
  2. The user replaces the placeholders with real live or demo credentials.
  3. The resulting config.toml is readable by another local user or compromised process.
  4. The attacker copies the API key, secret key, and passphrase.
  5. The attacker authenticates to OKX and performs actions allowed by the key.
  6. If live trading permission is enabled, the attacker can inspect account data or submit unauthorized trades.

Impact Assessment

Exposure grants the attacker the capabilities assigned to the compromised API key. This may include reading balances and positions, viewing account activity, ch ...[truncated 278 chars]

Remediation
View remediation

Remediation Suggestions

  • Create the directory with an explicit restrictive mode:
    bash
    install -d -m 700 "$HOME/.okx"
    
  • Create and maintain the configuration file with mode 0600, and verify that it is a regular file owned by the current user.
  • Set a restrictive umask such as umask 077 before creating the file.
  • Avoid overwriting an existing path until ownership, permissions, and symbolic-link status have been validated.
  • Prefer an operating-system credential manager or secret store when supported.
  • Continue requiring subaccount keys, least-privilege API permissions, demo-first testing, and no withdrawal permission.
  • Add periodic key rotation and immediate revocation procedures for suspected exposure.

T09 · Insecure Skill Coding Practices

Warning
Location
references/mcp-setup.md:23
Finding

Manual MCP Credential Configuration Does Not Enforce File Permissions

Content
View full analysis

Vulnerability Details

File Location: references/mcp-setup.md:23-38
Vulnerability Type: Plaintext secret storage without permission-hardening guidance
Risk Level: Medium

Vulnerable Code:

toml
default_profile = "demo"

[profiles.demo]
api_key    = "your-demo-api-key"
secret_key = "your-demo-secret-key"
passphrase = "your-demo-passphrase"
demo       = true

[profiles.live]
api_key    = "your-live-api-key"
secret_key = "your-live-secret-key"
passphrase = "your-live-passphrase"
# 歐洲用戶加: site = "eea"
# 美國用戶加: site = "us"

Technical Analysis

The MCP setup guide instructs users to place complete API authentication material in ~/.okx/config.toml, but it does not require verification or enforcement of restrictive ownership and permissions. The preceding interactive wizard may create secure permissions, but the audited documentation does not establish that behavior, and the explicitly offered manual method provides no hardening steps.

Because both demo and live credentials are held in one plaintext file, compromise of that file exposes every configured profile simultaneously.

Attack Path

  1. A user manually creates ~/.okx/config.toml with editor defaults or a permissive umask.
  2. The user enters valid API credentials for demo and live profiles.
  3. Another local user or compromised application reads the insufficiently protected file.
  4. The attacker extracts all configured credentials.
  5. The attacker invokes account or trading APIs within each key's granted permissions.

Impact Assessment

The attacker may gain read access to account balances, positions, bills, and fees, as well as trading functions if those permissions are enabled. Live keys may enable unauthorized orders, leverage changes, position closure, or automated trading strategies. The maximum scope remains bounded by the API permissions and account isolation selected by the user.

Remediation
View remediation

Remediation Suggestions

  • Add mandatory instructions to set ~/.okx to 0700 and config.toml to 0600.
  • Require the setup wizard to enforce and validate ownership and permissions.
  • Warn users when the configuration file is a symbolic link, is owned by another account, or is readable by group/other users.
  • Store secrets in a platform credential manager where integration permits.
  • Separate live and demo credentials if operationally practical to reduce the blast radius of one file disclosure.
  • Use dedicated subaccount keys with only necessary read/trade permissions and no withdrawal permission.
  • Document credential rotation, revocation, and local compromise response procedures.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill body is written almost entirely in Cantonese/Traditional Chinese and does not indicate that users may request another language. This can violate a language/locale policy when the skill imposes a specific language without opt-in or an explicit justified regional constraint.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

The skill tells users to run npx skills add okx/agent-skills without pinning a specific package version or integrity-verified source. Because npx resolves and executes the latest package at install time, a compromised upstream package or breaking update could cause users to run unexpected code in a high-trust installation flow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This instruction directly tells the user to execute npx skills add okx/agent-skills in chat, again without pinning a version. That creates a real supply-chain risk because the command fetches and runs remote code dynamically, and the conversational setting may reduce scrutiny before execution.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill instructs users to create a persistent plaintext config file in ~/.okx/config.toml containing live and demo API credentials. Storing exchange secrets unencrypted on disk increases the chance of credential theft through local compromise, backups, shell-history leakage during setup, or accidental file exposure, and these credentials can enable trading actions on a financial account.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

打開 Terminal,執行:

bash
mkdir -p ~/.okx && cat > ~/.okx/config.toml << 'EOF'
default_profile = "demo"

[profiles.live]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup instructs users to store live and demo API credentials in ~/.okx/config.toml without warning that the file contains highly sensitive trading secrets in local plaintext. In this skill's context, exposed credentials can enable unauthorized account access, data theft, or real-money trading, making the omission materially dangerous.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document claims a safety layer where money-related tools are labeled and the AI will confirm first, but it also provides live trading launch commands that do not visibly enforce confirmation or read-only restrictions. In an AI-driven trading context, this mismatch can create dangerous overtrust and may lead users to enable live trading under the false assumption that destructive actions are always gated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document enumerates numerous account- and market-affecting tools such as order placement, leverage changes, position closing, and bot creation without any adjacent warning about real-money consequences, liquidation risk, or the need for explicit user confirmation before execution. In the context of an AI trading skill, this omission increases the chance that an agent or user treats these tools as routine informational functions and triggers irreversible financial actions without sufficient caution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The setup guide is written entirely in Cantonese/Traditional Chinese, with no indication that other language options are available. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file is written entirely in Traditional Chinese/Cantonese phrasing and does not indicate any language choice or opt-in. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.