Back to skill

Security audit

VibeTrader

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent trading skill, but it gives a remote service natural-language authority over real-money trading without documented confirmation or scope controls.

Install only if you trust VibeTrader with access to your trading account and understand that live mode can affect real funds. Prefer paper trading or read-only credentials if available, verify the API key scope, and require your own explicit confirmation before any live order, position closure, live-mode switch, or bot deletion.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
openclaw.plugin.json:8
Finding

Remote MCP Service Receives Broad Financial Account Authority

Content
View full analysis

Vulnerability Details

File Location: openclaw.plugin.json:8-12; SKILL.md:105-121; SKILL.md:149-153
Vulnerability Type: Excessive remote-service privileges and insufficient privilege separation
Risk Level: High

Evidence

openclaw.plugin.json:8-12:

json
"mcp": {
  "server": {
    "type": "sse",
    "url": "https://vibetrader-mcp-289016366682.us-central1.run.app/mcp"
  }
},

SKILL.md:105-121:

markdown
| Tool | Description |
|------|-------------|
| `authenticate` | Connect with your API key (auto-uses env var if set) |
| `create_bot` | Create a trading bot from natural language (use `prompt` param) |
| `list_bots` | List all your bots with status |
| `get_bot` | Get detailed bot info and strategy |
| `start_bot` | Start a paused bot |
| `pause_bot` | Pause a running bot |
| `delete_bot` | Delete a bot |
| `get_portfolio` | View positions and balance |
| `get_positions` | View current open positions |
| `get_account_summary` | Get account balance and buying power |
| `place_order` | Place a buy/sell order |
| `close_position` | Close an existing position |
| `get_quote` | Get stock/ETF/crypto quotes |
| `get_trade_history` | See recent trades |
| `run_backtest` | Backtest a bot's strategy |
| `get_market_status` | Check if markets are open |

SKILL.md:149-153:

markdown
## Trading Modes

- **Paper Trading** (default): Practice with virtual money, no risk
- **Live Trading**: Real money trades via Alpaca brokerage

Technical Analysis

The plugin sends MCP requests to an externally operated Cloud Run service and allows that service to authenticate using the VIBETRADER_API_KEY environment variable. The same integration exposes read operations, bot administration, position closure, order placement, and live-trading functionality.

The reviewed package does not define separate read-only, paper-trading, and live-trading credenti ...[truncated 1797 chars]

Remediation
View remediation

Remediation Suggestions

  1. Issue separate credentials for read-only access, paper trading, and live trading.
  2. Apply least-privilege scopes to each credential and reject tools outside the credential's approved scope.
  3. Disable live-trading tools by default and require a separate, explicit authorization process to enable them.
  4. Enforce server-side per-order, daily-loss, position-size, symbol, and notional-value limits.
  5. Require short-lived credentials rather than a broadly privileged long-lived API key.
  6. Add tool-level authorization checks independent of MCP session authentication.
  7. Provide an authenticated endpoint under the declared application domain or publish verifiable endpoint ownership and deployment attestations.
  8. Maintain immutable audit logs and send immediate notifications for authentication events, mode changes, bot changes, orders, and position closures.
  9. Support rapid credential revocation and brokerage-side restrictions that remain effective if the MCP service is compromised.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:109
Finding

Financially Consequential Operations Lack Documented Confirmation Safeguards

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:109-121; SKILL.md:132-135; SKILL.md:149-153; README.md:51-61
Vulnerability Type: Missing confirmation and transaction-integrity controls for destructive and live-trading actions
Risk Level: High

Evidence

SKILL.md:109-121:

markdown
| `start_bot` | Start a paused bot |
| `pause_bot` | Pause a running bot |
| `delete_bot` | Delete a bot |
| `get_portfolio` | View positions and balance |
| `get_positions` | View current open positions |
| `get_account_summary` | Get account balance and buying power |
| `place_order` | Place a buy/sell order |
| `close_position` | Close an existing position |
| `get_quote` | Get stock/ETF/crypto quotes |
| `get_trade_history` | See recent trades |
| `run_backtest` | Backtest a bot's strategy |
| `get_market_status` | Check if markets are open |

SKILL.md:132-135:

markdown
### Portfolio Management
- "What's my current portfolio value?"
- "Show my open positions with P&L"
- "Buy $500 worth of NVDA"

SKILL.md:149-153:

markdown
## Trading Modes

- **Paper Trading** (default): Practice with virtual money, no risk
- **Live Trading**: Real money trades via Alpaca brokerage

README.md:51-61:

markdown
### Manage Portfolio
> "What's my portfolio value?"

> "Show my open positions"

> "Buy $500 of TSLA"

### Monitor Bots
> "Show me all my bots"

> "Pause my AAPL bot"

Technical Analysis

The skill promotes natural-language execution of operations that can delete bots, change automation state, close positions, or place orders. The reviewed documentation and configuration do not specify a mandatory preview, explicit user confirmation, fresh authorization check, idempotency key, order-value ceiling, or distinction between conversational intent and final transaction approval.

Natural-language instructions can be ambiguous, ...[truncated 1624 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit confirmation immediately before every live order, position closure, bot deletion, and transition to live mode.
  2. Present a normalized transaction preview containing account mode, symbol, side, quantity, order type, limit or stop price, time in force, and estimated notional value.
  3. Require the confirmation message to repeat or cryptographically bind the critical transaction details.
  4. Use short-lived, single-use approval tokens so stale or replayed confirmations cannot authorize later operations.
  5. Add idempotency keys to prevent duplicate orders caused by retries or repeated channel messages.
  6. Keep every new session in paper or read-only mode unless live mode is separately authorized.
  7. Require step-up authentication for live-mode activation and high-value transactions.
  8. Enforce server-side order limits, allowed-symbol lists, trading-hour policies, and daily loss controls.
  9. Verify channel-user identity and authorization before accepting financially consequential requests.
  10. Provide a cancellation window where operationally possible and send an immediate execution receipt through a trusted channel.
  11. Require stronger confirmation for irreversible actions such as deleting bots or closing an entire position.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly promotes switching to live trading mode and placing real-money orders without any adjacent risk warning, suitability notice, or confirmation guidance. In a finance skill, encouraging irreversible financial actions through natural language materially increases the chance of accidental or impulsive loss, especially if an agent executes user intents directly.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The plugin description states only that it provides AI-powered trading, portfolio monitoring, and backtesting, but it does not clearly disclose that the skill can perform live trading actions affecting real funds. In a financial-trading context, omission of this warning can mislead users or downstream agents into invoking actions with real monetary consequences without informed consent, increasing the risk of unintended purchases, sales, or losses.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 3)May include surrounding context.

md
# VibeTrader Skill for OpenClaw

Create and manage AI-powered trading bots directly from WhatsApp, Telegram, Slack, Discord, or any other OpenClaw channel.

## Installation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly encourages real trading actions such as buying securities and running live bots, but it does not warn users about financial loss, irreversible orders, market risk, or the need to verify actions before execution. In a chat-driven multi-channel skill, natural-language ambiguity and accidental triggering make this more dangerous because users may treat the assistant like a safe conversational interface while issuing commands that can cause real monetary harm.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: vibetrader
description: Create and manage AI-powered trading bots via natural language. Paper & live trading, portfolio monitoring, backtesting, stock quotes, and options chains.
homepage: https://vibetrader.markets
metadata: {"openclaw":{"homepage":"https://vibetrader.markets","category":"finance","requires":{"env":["VIBETRADER_API_KEY"]}}}
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill describes deleting bots and bulk deletion prompts without warning that deletion is destructive or suggesting confirmation steps. In this context, bot deletion can remove strategies, configuration, and possibly historical context, making accidental destruction more likely when driven by natural-language commands.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.