Back to skill

Security audit

OKX交易执行器

Security checks for vulnerabilities and agentic risk

Overview

This OKX trading skill is mostly coherent, but it can place live financial orders with weak safeguards and directs users to keep exchange credentials in a local plaintext file.

Review before installing. Use demo mode unless you have explicitly decided to allow live OKX trading, restrict OKX API keys to the minimum permissions needed, disable withdrawals, use IP allowlisting if available, and avoid storing real credentials in the packaged .env file. Treat any live order invocation as financially binding and add your own confirmation and order-size limits before delegating this skill to an agent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
providers/okx_provider.py:102
Finding

Invalid order amounts are silently converted into positive live orders

Content
View full analysis
Dict[str, Any]: """ OKX 市价单: - side = 'buy' 时,如果 ccy='USDT',sz 代表购买用的 USDT 金额 - side = 'sell' 时,sz 代表卖出的基础货币数量 """ inst_id = self._normalize_symbol(symbol) side = side.lower() body = { 'instId': inst_id, 'tdMode': 'cash', 'side': side, 'ordType': 'market', } if side == 'buy': body['ccy'] = 'USDT' body['sz'] = f"{size:.2f}" if float(body['sz']) < 10: body['sz'] = "10.00" else: body['sz'] = f"{size:.8f}".rstrip('0').rstrip('.') if not body['sz'] or float(body['sz']) < 0.00001: body['sz'] = "0.00001" ``` ```python # providers/okx_provider.py ...[truncated 2673 chars]
Remediation
View remediation
float: if value is None or not math.isfinite(value) or value <= 0: raise ValueError(f"{name} must be a finite number greater than zero") return value ``` 2. Apply validation before creating the provider request: ```python size = require_positive_finite(args.size, "size") price = require_positive_finite(args.price, "price") ``` 3. Replace truthiness-based checks with explicit checks: ```python if args.symbol is None or args.side is None or args.size is None: ... ``` 4. Never increase an order to an exchange minimum automatically. If an amount is below the supported minimum, reject it with a clear error that includes the applicable constraint. 5. Validate symbols against the intended instrument format and validate order parameters against OKX instrument metadata, including minimum order size, lot size, tick size, and quote-currency rules. 6. Add automated tests covering zero, negative values, `NaN`, positive and negative infinity, values below the exchange minimum, and unusually large values. Verify that none of these invalid inputs reaches `OKXClient.request()`. 7. Consider requiring an explicit confirmation or configurable notional limit for `okx_live` orders to reduce the impact of compromised or malformed upstream requests. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
.env:1
Finding

Live trading credentials are directed into a repository-local plaintext file

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose understates the skill's operational scope: it is not just a narrow buy/sell adapter, but can read balances, positions, trades, and place limit orders, with language suggesting a more generic provider abstraction. This mismatch can mislead users or higher-level agents about what actions are possible, causing unsafe delegation or use in contexts where broader trading/account access was not intended.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/execute.py (reported line 33)May include surrounding context.

python
args = parser.parse_args()
    
    # 尝试加载环境所在目录的 .env 文件 (优先向上层找)
    env_path = os.path.join(skill_dir, '.env')
    if not os.path.exists(env_path):
        env_path = os.path.join(os.path.dirname(os.path.dirname(skill_dir)), '.env')

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/execute.py (reported line 34)May include surrounding context.

python
args = parser.parse_args()
    
    # 尝试加载环境所在目录的 .env 文件 (优先向上层找)
    env_path = os.path.join(skill_dir, '.env')
    if not os.path.exists(env_path):
        env_path = os.path.join(os.path.dirname(os.path.dirname(skill_dir)), '.env')
    load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/execute.py (reported line 36)May include surrounding context.

python
args = parser.parse_args()
    
    # 尝试加载环境所在目录的 .env 文件 (优先向上层找)
    env_path = os.path.join(skill_dir, '.env')
    if not os.path.exists(env_path):
        env_path = os.path.join(os.path.dirname(os.path.dirname(skill_dir)), '.env')
    load_dotenv(env_path)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though it is designed to access environment secrets and perform networked trading actions. In an agent setting, missing scope declarations can let orchestrators invoke a credential-reading, external-action skill without clear guardrails, increasing the chance of unintended secret access or real-money trades.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document presents core operating instructions entirely in Chinese, including a mandatory agent behavior section for authentication handling. This imposes a language requirement on users or agents without documenting any language choice, opt-in, or justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains user-facing/docstring natural language that mandates a specific language context by presenting all descriptive guidance only in Chinese. Under the policy, a forced language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

These methods can submit real exchange orders directly, including in non-demo mode, without any built-in confirmation, policy gate, or explicit safeguard in this file. In an agentic context, that increases the risk of unintended or unauthorized trades from prompt injection, task confusion, or upstream validation failure, leading to financial loss.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames the skill as an adapter for executing trading actions (buy/sell) and querying capabilities, which most directly implies basic order execution. This file additionally exposes a dedicated limit-order capability, expanding behavior beyond the described market-style buy/sell execution scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This script can place live market and limit orders when --provider okx_live is selected, but it performs no user-facing confirmation, no environment-specific safeguard, and no additional verification before executing irreversible trading actions. In an agent-skill context, that makes accidental or prompt-induced real-money trades significantly more dangerous because a caller can route directly to live execution with only CLI parameters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The class docstring and additional comments/docstrings throughout the file are written in Chinese, which imposes a specific language choice in natural-language content. The file does not indicate that the skill is region-specific or provide an opt-in or alternative language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code reads OKX_API_KEY, OKX_API_SECRET, and OKX_PASSPHRASE from a .env file and environment variables, which is access to sensitive credentials. The file contains no user-facing notice, docstring, or explanatory comment warning that exchange credentials are required and will be accessed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.