Back to skill

Security audit

Okx Pro

Security checks for vulnerabilities and agentic risk

Overview

This OKX trading skill is purpose-aligned but asks users to handle live trading credentials and execute financial actions with insufficient safeguards.

Review this carefully before installing. Use a dedicated OKX API key with the minimum permissions needed, no withdrawal permission, IP allowlisting where possible, and demo trading first. Avoid storing the secret and passphrase in plaintext unless you lock down file permissions, and require explicit confirmation before any order, cancellation, leverage change, margin change, or position closure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:13
Finding

Plaintext Storage of High-Impact OKX Trading Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13–22
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: High

Vulnerable Code

markdown
### Setup Credentials

Save to `~/.openclaw/credentials/okx.json`:
```json
{
  "apiKey": "YOUR_API_KEY",
  "secretKey": "YOUR_SECRET_KEY",
  "passphrase": "YOUR_PASSPHRASE"
}
text

### Technical Analysis

The setup instructions direct users to persist an OKX API key, signing secret, and passphrase in a plaintext JSON file. They do not require restrictive file permissions, verify file ownership, recommend encryption or a secret manager, or warn users against backups and accidental disclosure.

These are high-impact credentials because the documented integration supports authenticated balance and position queries, spot and futures orders, leveraged trading, order cancellation, position closure, and leverage changes. The actual request helper consumes environment variables rather than the documented JSON file, so retaining a second plaintext credential copy is not required by the demonstrated implementation and exceeds minimum privilege and data-retention needs.

This does not establish intentional credential theft: the reviewed content sends authentication values only to the declared OKX endpoint. Nevertheless, insecure local storage creates an avoidable credential-disclosure path.

### Attack Path

1. A user follows the setup instructions and writes valid OKX credentials to `~/.openclaw/credentials/okx.json`.
2. The file is created using default filesystem permissions, with no mandatory `0600` protection or ownership validation.
3. Another local user, compromised process, malicious Skill, backup service, or overly broad synchronization tool obtains read access to the file.
4. The attacker extracts the API key, signing secret, and passphrase.
5. The attacker uses those values to sign direct OKX V5 API requests.
6. Subject to th
...[truncated 936 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the plaintext JSON credential-storage instruction because the documented request helper already uses environment variables.
  2. Prefer an operating-system keychain, dedicated secret manager, or runtime secret injection mechanism.
  3. If file-based storage is unavoidable:
    • Create ~/.openclaw/credentials with mode 0700.
    • Create okx.json with mode 0600.
    • Verify that the current user owns both the directory and file.
    • Refuse to use credentials when permissions or ownership are unsafe.
    • Exclude the file from source control, cloud synchronization, diagnostics, logs, and unencrypted backups.
  4. Use a dedicated OKX API key with only the permissions required by this Skill.
  5. Disable withdrawal permissions and unrelated account-management permissions.
  6. Configure an exchange-side IP allowlist where operationally possible.
  7. Use separate demo and production credentials, defaulting to demo trading.
  8. Document credential rotation and immediate revocation procedures.
  9. Avoid printing secrets, authentication headers, signed requests, or the credential file contents during debugging and error handling.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description and top-level introduction are presented in Chinese, which can impose a language preference before the later bilingual sections are reached. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented signature helper does not implement OKX V5 signing correctly because it emits a hex HMAC digest instead of the Base64-encoded HMAC required by the API. In a trading skill, incorrect auth logic can cause failed requests, encourage unsafe troubleshooting, and lead users to paste secrets into ad hoc debug commands or modified scripts to make trading work.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This skill transmits highly sensitive API credentials and authenticated trade requests to an external exchange. External transmission is expected for an exchange integration, but the context is high risk because the transmitted secrets authorize real financial actions, and any misuse, endpoint manipulation, or accidental execution can directly place trades, alter leverage, or expose account data.

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

md
local timestamp=$(date -u +"%Y-%m-%dT%H:%M:%S.000Z")
  local signature=$(okx_sign "$method" "$endpoint" "$body")
  
  curl -s -X "$method" "https://www.okx.com$endpoint" \
    -H "Content-Type: application/json" \
    -H "OKX-ACCESS-KEY: $OKX_API_KEY" \
    -H "OKX-ACCESS-SIGN: $signature" \

Static analysis

No suspicious patterns detected.