Back to skill

Security audit

LTP RapidX Config

Security checks for vulnerabilities and agentic risk

Overview

This RapidX setup skill is coherent, but it needs review because it can install a mutable trading CLI and persist production trading credentials for tools that can perform high-impact account actions.

Install only if you trust the RapidX CLI package source and can constrain the API keys. Prefer workspace-local, pinned installs and host-supported secret references or a secret manager. Use read-only or least-privilege credentials for setup when possible, avoid writing production secrets directly into MCP config, and require explicit previews and confirmations before any live trading, cancel-all, leverage, or close-position action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:58
Finding

Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:230
Finding

Production Credentials May Be Persisted in Plaintext MCP Configuration

Content
View full analysis
/config.yaml ``` The resulting `rapidx` block should use materialized values or a secret mechanism that Hermes actually expands at runtime. Do not copy the example placeholders literally: ```yaml mcp_servers: rapidx: command: rapidx args: - mcp - serve env: LTP_ACCESS_KEY: "actual-access-key-or-host-supported-secret-reference" LTP_SECRET_KEY: "actual-secret-key-or-host-supported-secret-reference" LTP_API_HOST: "actual-api-host" ``` ``` ### Technical Analysis The fallback procedure authorizes the agent to read real production credentials from secret-bearing sources and permits those values to be materialized directly into a persistent YAML or JSON MCP configuration file. Although the Skill correctly prohibits displaying full credentials in chat and logs, output masking does not protect secrets written to disk. The instructions do not require restrictive file permissions, encryption at rest, version-con ...[truncated 1779 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (10)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/capability-overview.md (reported line 70)May include surrounding context.

md
| `rapidx order cancel-preview` | `rapidx/order/cancel-preview` | preview for cancel |
| `rapidx order place` | `rapidx/order/place` | `POST /api/v1/trading/order` |
| `rapidx order replace` | `rapidx/order/replace` | `PUT /api/v1/trading/order` |
| `rapidx order cancel` | `rapidx/order/cancel` | `DELETE /api/v1/trading/order` |
| `rapidx order cancel-all` | `rapidx/order/cancel-all` | `DELETE /api/v1/trading/cancelAll` |
| `rapidx order query` | `rapidx/order/query` | `GET /api/v1/trading/order` |
| `rapidx order open-orders` | `rapidx/order/open-orders` | `GET /api/v1/trading/orders` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

cancel-all is a bulk destructive trading operation, and the skill presents it as a straightforward available command without nearby guardrails, confirmation requirements, or strong warnings. In an agent planning context, exposing a bulk action this powerful without safety cues increases the risk of mass order cancellation on production accounts from misunderstanding, prompt confusion, or overly broad tool selection.

Content

Scanner excerpt · references/capability-overview.md (reported line 71)May include surrounding context.

md
| `rapidx order place` | `rapidx/order/place` | `POST /api/v1/trading/order` |
| `rapidx order replace` | `rapidx/order/replace` | `PUT /api/v1/trading/order` |
| `rapidx order cancel` | `rapidx/order/cancel` | `DELETE /api/v1/trading/order` |
| `rapidx order cancel-all` | `rapidx/order/cancel-all` | `DELETE /api/v1/trading/cancelAll` |
| `rapidx order query` | `rapidx/order/query` | `GET /api/v1/trading/order` |
| `rapidx order open-orders` | `rapidx/order/open-orders` | `GET /api/v1/trading/orders` |
| `rapidx order history` | `rapidx/order/history` | `GET /api/v1/trading/history/orders` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
81% confidence
Finding

The position close capability maps directly to a live DELETE operation and is accompanied by parameter guidance, making it operationally actionable. In this skill context, that increases the likelihood an agent may perform an irreversible financial action on a real account without sufficient warnings about liquidation, slippage, or production impact.

Content

Scanner excerpt · references/capability-overview.md (reported line 92)May include surrounding context.

md
| `rapidx position history` | `rapidx/position/history` | `GET /api/v1/trading/history/position` |
| `rapidx position get-leverage` | `rapidx/position/get-leverage` | `GET /api/v1/trading/perp/leverage` |
| `rapidx position set-leverage` | `rapidx/position/set-leverage` | `POST /api/v1/trading/position/leverage` |
| `rapidx position close` | `rapidx/position/close` | `DELETE /api/v1/trading/position` |
| `rapidx position close-all` | `rapidx/position/close-all` | `DELETE /api/v1/trading/positions` |

`position.close` does not take `side` or `quantity`. In NET mode, omit `positionSide`; in HEDGE mode, pass the actual `LONG` or `SHORT` side.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

position close-all is an account-wide destructive action that can unwind all open positions, potentially causing immediate realized losses and strategy disruption. Presenting it in a compact capabilities list without conspicuous warnings or confirmation guidance is especially dangerous in an agent skill because the operation is broad, irreversible in effect, and highly sensitive to accidental invocation.

Content

Scanner excerpt · references/capability-overview.md (reported line 93)May include surrounding context.

md
| `rapidx position get-leverage` | `rapidx/position/get-leverage` | `GET /api/v1/trading/perp/leverage` |
| `rapidx position set-leverage` | `rapidx/position/set-leverage` | `POST /api/v1/trading/position/leverage` |
| `rapidx position close` | `rapidx/position/close` | `DELETE /api/v1/trading/position` |
| `rapidx position close-all` | `rapidx/position/close-all` | `DELETE /api/v1/trading/positions` |

`position.close` does not take `side` or `quantity`. In NET mode, omit `positionSide`; in HEDGE mode, pass the actual `LONG` or `SHORT` side.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/capability-overview.md (reported line 103)May include surrounding context.

md
|---|---|---|
| `rapidx algo place` | `rapidx/algo/place` | `POST /api/v1/algo/order` |
| `rapidx algo replace` | `rapidx/algo/replace` | `PUT /api/v1/algo/order` |
| `rapidx algo cancel` | `rapidx/algo/cancel` | `DELETE /api/v1/algo/order` |
| `rapidx algo query` | `rapidx/algo/query` | `GET /api/v1/algo/order` |
| `rapidx algo open-orders` | `rapidx/algo/open-orders` | `GET /api/v1/algo/openOrders` |
| `rapidx algo history` | `rapidx/algo/history` | `GET /api/v1/algo/history/orders` |

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The skill encourages collecting production credentials through agent-host chat-secret mechanisms and, if unavailable, writing placeholders or references into MCP config. Even though it warns about retention risk and says not to print full keys, this workflow increases the chance that sensitive secrets are persisted in host-managed stores or configuration files that may be accessible to other tools, users, backups, or collaboration features.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
Ask whether the user wants to provide credentials as a user-provided chat secret. This is the default path for non-programmers, but state the risk first: even protected chat-secret flows are controlled by the agent host and may be subject to that host's retention, access, or collaboration settings.

If the agent host has a dedicated chat-secret UI, ask the user to create three secrets with the exact names `LTP_ACCESS_KEY`, `LTP_SECRET_KEY`, and `LTP_API_HOST`. If the host has no chat-secret UI, ask whether the user wants the agent to write masked-reference placeholders into MCP config or whether they prefer to set local environment variables manually.

Offer alternatives when the user wants stronger isolation:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance explicitly introduces a Chinese-language example symbol component (币安人生USDT -> BINANCE_PERP_币安人生_USDT) as part of required normalization behavior. This suggests locale-specific handling in the skill instructions without offering user choice or explaining a region-specific requirement, which can conflict with organizational language/locale policy.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/best-practices.md (reported line 116)May include surrounding context.

md
1. Prefer the Agent host's user-provided chat secret mechanism.
2. Ask the user to create secrets named exactly `LTP_ACCESS_KEY`, `LTP_SECRET_KEY`, and `LTP_API_HOST`.
3. Do not ask the user to paste full keys into public chats, screenshots, logs, or repositories.

Fallbacks:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/best-practices.md (reported line 399)May include surrounding context.

md
## 12. Automation

Automation is a bounded local authorization session. It lets the Agent submit matching previews without asking for another per-order chat confirmation.

Automation still requires preview.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This overview documents live trading, cancellation, leverage, and position-closing capabilities in a planning reference without prominent warnings that these actions are financially destructive and may execute against production accounts. In an agent skill context, enumerating powerful write operations without explicit safety framing can normalize unsafe use and increase the chance an agent or operator invokes a live endpoint when they intended read-only discovery or preview.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:253