T05 · Unauthorized Access and Privilege Escalation
- Location
openclaw.plugin.json:8- Finding
Remote MCP Service Receives Broad Financial Account Authority
- Content
View full analysis
Vulnerability Details
File Location:
openclaw.plugin.json:8-12;SKILL.md:105-121;SKILL.md:149-153
Vulnerability Type: Excessive remote-service privileges and insufficient privilege separation
Risk Level: HighEvidence
openclaw.plugin.json:8-12:json "mcp": { "server": { "type": "sse", "url": "https://vibetrader-mcp-289016366682.us-central1.run.app/mcp" } },SKILL.md:105-121:markdown | Tool | Description | |------|-------------| | `authenticate` | Connect with your API key (auto-uses env var if set) | | `create_bot` | Create a trading bot from natural language (use `prompt` param) | | `list_bots` | List all your bots with status | | `get_bot` | Get detailed bot info and strategy | | `start_bot` | Start a paused bot | | `pause_bot` | Pause a running bot | | `delete_bot` | Delete a bot | | `get_portfolio` | View positions and balance | | `get_positions` | View current open positions | | `get_account_summary` | Get account balance and buying power | | `place_order` | Place a buy/sell order | | `close_position` | Close an existing position | | `get_quote` | Get stock/ETF/crypto quotes | | `get_trade_history` | See recent trades | | `run_backtest` | Backtest a bot's strategy | | `get_market_status` | Check if markets are open |SKILL.md:149-153:markdown ## Trading Modes - **Paper Trading** (default): Practice with virtual money, no risk - **Live Trading**: Real money trades via Alpaca brokerageTechnical Analysis
The plugin sends MCP requests to an externally operated Cloud Run service and allows that service to authenticate using the
VIBETRADER_API_KEYenvironment variable. The same integration exposes read operations, bot administration, position closure, order placement, and live-trading functionality.The reviewed package does not define separate read-only, paper-trading, and live-trading credenti ...[truncated 1797 chars]
- Remediation
View remediation
Remediation Suggestions
- Issue separate credentials for read-only access, paper trading, and live trading.
- Apply least-privilege scopes to each credential and reject tools outside the credential's approved scope.
- Disable live-trading tools by default and require a separate, explicit authorization process to enable them.
- Enforce server-side per-order, daily-loss, position-size, symbol, and notional-value limits.
- Require short-lived credentials rather than a broadly privileged long-lived API key.
- Add tool-level authorization checks independent of MCP session authentication.
- Provide an authenticated endpoint under the declared application domain or publish verifiable endpoint ownership and deployment attestations.
- Maintain immutable audit logs and send immediate notifications for authentication events, mode changes, bot changes, orders, and position closures.
- Support rapid credential revocation and brokerage-side restrictions that remain effective if the MCP service is compromised.
