Back to skill

Security audit

OKX Trader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent OKX trading bot, but it can automatically place and cancel real orders with unsafe live-trading defaults and weak order-scope controls.

Review this carefully before installing. Use simulation mode first, keep OKX API keys trade-only with withdrawals disabled, avoid enabling the five-minute maintenance schedule for a live account until the live opt-in, order ownership, and exposure-limit issues are fixed, and protect the local okx_data directory because it contains credentials and account snapshots.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/grid-bot.js:73
Finding

Order ownership is inferred only from instrument and size, allowing unrelated orders to be cancelled

Content
View full analysis
Math.abs(parseFloat(o.sz) - CONFIG.sizePerGrid) < 0.000001) .map(o => ({ instId: CONFIG.instId, ordId: o.ordId })); if (toCancel.length > 0) { // Batch cancel await Promise.all(toCancel.map(o => client.request('/trade/cancel-order', 'POST', JSON.stringify(o)))); } ``` ### Technical Analysis During rescaling, the bot identifies its orders solely by comparing each pending order's size with `CONFIG.sizePerGrid`. The instrument has already been selected by the API query, but neither the exchange order ID nor a bot-specific client order identifier is validated against persistent ownership records. Order size is not a unique ownership attribute. Manual orders and orders created by other strategies can legitimately use the same instrument and quantity. Those orders will satisfy the filter and be submitted to the OKX cancellation endpoint. ### Attack Path 1. A manual trader or another automated strategy creates a pending order for the configured instrument. 2. The order quantity equals `CONFIG.sizePerGrid` within the hardcoded tolerance. 3. The market price enters the bot's rescaling trigger zone. 4. The maintenance script retrieves all pending orders for that instrument. 5. The unrelated order passes the size-based filter. 6. The bot sends its `ordId` to `/trade/cancel-order`. 7. OKX cancels the unrelated order using the configured account's trade privileges. ### Impact Assessment The flaw permits cancellation of legitimate orders in the same OKX account and instrument. It can disrupt manual trading, hedging, risk controls, or independent automated strategies. The scope is limited to orders accessible through the configured API credentials, but the resulting loss of protective or strategic orders can creat ...[truncated 32 chars]
Remediation
View remediation
-` prefix. - Persist the exchange order IDs and client order IDs returned after successful placement. - Cancel an order only when its identifier is present in the bot's ownership registry or its validated client ID uses the expected prefix. - Keep ownership namespaces distinct for every bot configuration and instrument. - Do not use order size, price, or instrument as proof of ownership. - Reconcile persisted identifiers against OKX before rescaling and record every cancellation result in the audit log. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
lib/okx-client.js:8
Finding

Simulation mode fails open to live trading

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/grid-bot.js:104
Finding

Position limit ignores pending and newly queued buy exposure

Content
View full analysis
= CONFIG.maxPosition; const minProfitPx = CONFIG.minProfitGap ? (avgPx * (1 + CONFIG.minProfitGap)) : 0; const ordersToPlace = []; let protectedSell = 0; for (const price of grids) { const diff = (price - currentPrice) / currentPrice; let side = ''; if (diff > buffer) side = 'sell'; else if (diff < -buffer) side = 'buy'; else continue; const priceKey = Math.floor(price); if (!activeOrders.has(priceKey)) { if (side === 'buy' && isOverloaded) continue; if (side === 'sell' && currentPos > 0 && price < minProfitPx) { protectedSell++; continue; } ordersToPlace.push({ instId: CONFIG.instId, tdMode: 'cash', side: side, ordType: 'limit', px: price.toFixed(1), sz: CONFIG.sizePerGrid.toString() }); } } // 4. Batch Order Placement (with small delay between chunks to avoid rate limit if needed) let placedBuy = 0, placedSell = 0; if (ordersToPlace.length > 0) { console.log(`[${botType}] Placing ${ordersToPlace.length} orders...`); const results = await Promise.all(ordersToPlace.map(ord => client.request('/trade/order', 'POST', JSON.stringify(ord)) )); ``` ### Technical Analysis The `maxPosition` control checks only the currently filled position at the beginning of the run. It does not include: - Existing pending buy orders. - Buy orders accumulated in `ordersToPlace`. - Partial fills that occur while the script is running. - Concurrent maintenance executions operating on the same account or instrument. If the current position is below the maximum, every missing buy ...[truncated 1192 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/grid-bot.js:66
Finding

Rescaling is triggered inside the configured grid despite documentation claiming an out-of-range trigger

Content
View full analysis
CONFIG.maxPrice - threshold || currentPrice < CONFIG.minPrice + threshold) { ``` ### Technical Analysis The documented behavior states that rescaling occurs when the market price moves outside the active grid range. The implemented condition instead defines inner boundaries: - Upper trigger: `maxPrice - threshold` - Lower trigger: `minPrice + threshold` Consequently, the bot begins rescaling while the price remains inside the configured range. With the fallback threshold of ten percent of the range, either outer ten-percent zone triggers cancellation and recentering. Because rescaling also cancels matching pending orders and rewrites `grid_settings.json`, this discrepancy can produce significantly more account mutations than an operator would expect from the documentation. The expression `CONFIG.trailingPercent || 0.1` also prevents an explicit numeric value of `0` from disabling the inner threshold, because zero is replaced with `0.1`. ### Attack Path 1. An operator configures a grid based on the documented expectation that rescaling occurs only after the price leaves the range. 2. The market price moves into the upper or lower inner threshold zone but remains within `minPrice` and `maxPrice`. 3. The condition evaluates to `true`. 4. The bot cancels orders it identifies as grid orders. 5. It recalculates the range around the current price and overwrites `grid_settings.json`. 6. Repeated boundary movement can cause unexpected cancellation and replacement cycles. ### Impact Assessment The flaw can cause premature order cancellation, unexpected strategy recentering, increased API activity, missed fills, additional fees, and divergence ...[truncated 191 chars]
Remediation
View remediation
CONFIG.maxPrice || currentPrice < CONFIG.minPrice) { // Rescale } ``` - If an inner trailing zone is intentional, update the documentation and rename the setting to describe that behavior accurately. - Validate `trailingPercent` as a finite number within a documented safe range. - Use nullish handling rather than logical OR so an explicit zero remains valid: ```js const trailingPercent = CONFIG.trailingPercent ?? 0.1; ``` - Add tests for prices below, at, inside, and outside both boundaries. - Require cancellation success before persisting a newly rescaled configuration. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (13)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script programmatically cancels pending orders and places new live orders against a real exchange account with no interactive confirmation, dry-run safeguard, or explicit execution mode separation. In the context of an agent skill, this is dangerous because invoking the skill can directly and irreversibly alter account state and market exposure, especially if configuration is wrong or the skill is run unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The okx_grid_maintain tool is explicitly described as maintaining grid orders and performing auto-rescale, which implies order creation, cancellation, or modification on an exchange account. Because the manifest lacks a prominent warning that this tool can execute live account actions, a user or orchestrator could invoke it without understanding that it may directly affect positions and funds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly describes an automated system that places and cancels exchange orders on a schedule and recenters grids automatically, but it does not prominently warn that these actions can affect a live brokerage account and create real financial loss. In an agent-skill context, operational descriptions may be treated as approval to run the strategy, so missing safety warnings materially increases the risk of unintended live trading or destructive order management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to provide exchange API credentials and states that account snapshots containing balances, prices, and trading summaries are recorded, but it does not clearly warn about the sensitivity of this financial data or the risks of insecure storage and exposure. In a trading-agent context, these details can enable account compromise, privacy loss, or leakage of strategy and holdings information if mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The client reads API key, secret, and passphrase from configuration or environment variables, then uses them to authenticate outbound HTTPS requests. There is no confirmation prompt, logging, comment, or docstring in this file warning that sensitive credentials will be accessed and sent to the external OKX service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script loads config.json into authData and passes it to the OKX client, which implies access to sensitive authentication material. While the file header mentions optimization changes, there is no user-facing warning, prompt, or explanatory comment disclosing that credential-bearing configuration is read from disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script makes network requests to exchange endpoints for ticker, positions, and pending orders, transmitting instrument/account context to an external API. There is logging for rescaling and order placement, but no disclosure that external network calls involving trading/account data occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script reads OKX API credentials and passphrase from environment variables to initialize an exchange client, but there is no confirmation prompt, user-facing log message, or explanatory comment/docstring warning that sensitive credentials will be accessed. In this file, the behavior is silent aside from later report output, so users reviewing only execution behavior would not be alerted to credential use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated report strings are hard-coded in Chinese, including headings, labels, and notes, with no option for users to choose another language. This creates a natural-language locale policy concern because the skill imposes a specific language without opt-in or explanation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script prints all user-facing status and summary messages in Chinese, which imposes a specific language on users without opt-in. Under the policy, locale or language restrictions should either be user-selectable or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes live trading automation, reporting, and account snapshots against OKX, but it does not clearly warn users that the skill can transmit account data to a third-party exchange and may affect a real trading account. In a financial context, missing consent and safety warnings increase the chance of unintended live execution, privacy exposure, and monetary loss, especially because simulation mode defaults to false.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
## ⚠️ RISK WARNING
Trading cryptocurrencies involves significant risk. This skill is provided "as is" without warranties.
- **Simulation First:** Always test with `OKX_IS_SIMULATION=true` before using real funds.
- **Permissions:** Use API keys with "Trade" permissions only. **Disable "Withdrawal" permissions.**

---

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

When rescaling triggers, the script updates grid_settings.json in place, changing persistent bot configuration on disk. There is no comment, warning, or disclosure that execution will rewrite local settings, which may surprise users or affect later runs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.