Back to skill

Security audit

Okx Trading Analyst

Security checks for vulnerabilities and agentic risk

Overview

The skill does perform OKX market analysis, but it also has under-disclosed command execution paths and unnecessarily handles exchange secrets, so it belongs in Review before installation.

Install only after reviewing or fixing the command-injection bug, removing default execution of other local skill scripts, and avoiding broad OKX secrets unless they are truly needed. If used as-is, create only read-only OKX credentials and avoid passing untrusted symbols or timeframes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/analyze.js:40
Finding

Shell Command Injection Through Unsanitized CLI Arguments

Content
View full analysis
/tmp/skill-command-output # ``` 3. `parseArgs()` stores this text in `options.symbol`. 4. `runAnalysis()` concatenates the value into the shell command. 5. `execSync()` invokes the shell, which runs the intended Python process and then the injected command. 6. The injected command executes with the same operating-system privileges, environment variables, filesystem access, and network access as the Skill process. ### Impact Assessment Successful exploitation provides arbitrary command execution under the account running the Agent. An attacker could: ...[truncated 483 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/okx_analyst.py:832
Finding

Execution of Unverified Scripts Outside the Audited Skill Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/okx_analyst.py:18
Finding

Unnecessary Collection and Retention of an Exchange API Secret

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose is limited to OKX market-data technical analysis, but the finding indicates the code also fetches external news, aggregates other sources, and invokes local scripts via subprocess. This mismatch is dangerous because it hides materially broader behavior from reviewers and users, creating opportunities for unexpected network exfiltration, unreviewed data ingestion, and command execution beyond the declared trust boundary.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/analyze.js (reported line 13)May include surrounding context.

js
if (!API_KEY || !API_SECRET) {
    console.error("⚠️  错误: OKX_API_KEY 和 OKX_API_SECRET 未设置");
    console.error("   请在项目根目录创建 .env 文件:");
    console.error("   OKX_API_KEY=your-api-key");
    console.error("   OKX_API_SECRET=your-api-secret");
    process.exit(1);

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/okx_analyst.py (reported line 20)May include surrounding context.

python
if (!API_KEY || !API_SECRET) {
    console.error("⚠️  错误: OKX_API_KEY 和 OKX_API_SECRET 未设置");
    console.error("   请在项目根目录创建 .env 文件:");
    console.error("   OKX_API_KEY=your-api-key");
    console.error("   OKX_API_SECRET=your-api-secret");
    process.exit(1);

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/okx_analyst.py (reported line 36)May include surrounding context.

python
if (!API_KEY || !API_SECRET) {
    console.error("⚠️  错误: OKX_API_KEY 和 OKX_API_SECRET 未设置");
    console.error("   请在项目根目录创建 .env 文件:");
    console.error("   OKX_API_KEY=your-api-key");
    console.error("   OKX_API_SECRET=your-api-secret");
    process.exit(1);

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script builds a shell command string from user-controlled arguments such as symbol and timeframe, then executes it with execSync. Because values are concatenated without escaping or validation, an attacker could inject shell metacharacters and execute arbitrary commands on the host running the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Executing an external script to gather news is unrelated to the core technical-indicator calculation advertised by the skill and introduces an unnecessary code-execution primitive. In a skill ecosystem, this materially increases risk because a seemingly low-risk analysis tool can become a launcher for other code and side effects not obvious to users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code invokes a separate Python news-aggregator script from another skill, creating hidden coupling and a broader execution surface than the skill description suggests. This is especially risky because cross-skill execution can bypass expected isolation and lets changes in another component silently alter this skill's behavior or security posture.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though its documented and detected capabilities include environment access, file operations, network access, and shell execution. In an agent setting, missing scope declarations can let the skill run with broader privileges than users expect, increasing the chance of unintended data access, command execution, or lateral behavior if the implementation is modified or abused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation description is broad enough to trigger on many general crypto-analysis requests without clear boundaries. Over-broad triggering can cause the skill to run in situations the user did not intend, unnecessarily exposing credentials, network access, or other privileged operations tied to the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes a technical analysis tool that fetches market data and generates signals. While network access to OKX is expected, this wrapper script additionally depends on sensitive API credentials from environment variables, a capability not clearly justified for read-only market analysis and broader than necessary if public market data endpoints are sufficient.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code presents error and status messages in Chinese, and later output is also hard-coded in Chinese. That creates a natural-language locale constraint without user opt-in or documented justification, which falls under the language/locale policy violations category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill continues to use Chinese-only messaging for execution failure and analysis status output. Because the file provides no alternative language option or explicit locale scope, it enforces a specific language in a way that violates the stated natural-language policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language description and many user-facing strings are in Chinese, and the news-fetch path explicitly prefers zh-CN before falling back to English. This imposes a locale/language choice by default rather than offering the user an explicit language option, which conflicts with the language-choice policy.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/okx_analyst.py (reported line 29)May include surrounding context.

python
BASE_URL = "https://www.okx.com"

# NS3 新闻API
NS3_BASE = "https://api.ns3.ai/feed"


class OKXAnalyzer:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description promises OKX market-data technical analysis, but the implementation also aggregates external news from separate services and helper skills. This scope expansion is security-relevant because users and calling systems may not expect additional external data flows and execution paths, reducing transparency and increasing attack surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill runs an external helper process without clear user-facing disclosure that another local script will be executed. While lack of disclosure alone is not code execution, it is a meaningful security issue in agent settings because it obscures capability expansion and prevents informed consent about additional execution and data handling.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

The code executes an external Node.js script from an absolute path to fetch news, creating a cross-skill execution boundary that is outside the stated OKX analysis purpose. Even though shell injection is mitigated by passing an argument list, this still allows execution of untrusted or modified local code with the current process privileges and can be abused for arbitrary code execution if that external script or path is compromised.

Content

Scanner excerpt · scripts/okx_analyst.py (reported line 840)May include surrounding context.

python
script_path = '/Users/yirongcao/.openclaw/skills/crypto-monitor/scripts/news.js'
        cmd = ['node', script_path, f'--coin={base_symbol}', f'--lang={lang}', f'--limit={max(20, limit * 4)}']
        
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=30)
        
        if result.returncode != 0:
            return []

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Python subprocess call to a separate news-aggregator script is not clearly disclosed to users, masking a significant expansion in behavior beyond OKX analysis. In agent ecosystems, undisclosed cross-component execution undermines trust and can conceal unexpected data access, network calls, or side effects.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
94% confidence
Finding

The skill invokes another Python script from a separate skill directory, which expands its trust boundary and effectively delegates execution to unrelated code. This is dangerous because compromise, replacement, or unexpected behavior in that external script can lead to arbitrary code execution, data access, or network activity under this skill's permissions.

Content

Scanner excerpt · scripts/okx_analyst.py (reported line 910)May include surrounding context.

python
script_path = '/Users/yirongcao/.openclaw/skills/wire-news-aggregator/scripts/wire_news.py'
        cmd = ['python3', script_path, '--limit', str(max(20, limit * 4)), '--json']
        
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=60)
        
        if result.returncode != 0:
            return []

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python file contains user-facing natural-language text entirely in Chinese in the module docstring and notification output, indicating the skill is designed to communicate in a single language. The provided policy says locale/language constraints should be flagged unless the skill offers a language choice or clearly documents a justified region-specific constraint, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill behavior in that language without indicating that the user may choose another language. Under the policy, language constraints should be opt-in or clearly justified; no such choice or justification appears here.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/analyze.js:51