T08 · Insecure Dependencies
- Location
SKILL.md:58- Finding
Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This RapidX setup skill is coherent, but it needs review because it can install a mutable trading CLI and persist production trading credentials for tools that can perform high-impact account actions.
Install only if you trust the RapidX CLI package source and can constrain the API keys. Prefer workspace-local, pinned installs and host-supported secret references or a secret manager. Use read-only or least-privilege credentials for setup when possible, avoid writing production secrets directly into MCP config, and require explicit previews and confirmations before any live trading, cancel-all, leverage, or close-position action.
SKILL.md:58Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
SKILL.md:230Production Credentials May Be Persisted in Plaintext MCP Configuration
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `rapidx order cancel-preview` | `rapidx/order/cancel-preview` | preview for cancel |
| `rapidx order place` | `rapidx/order/place` | `POST /api/v1/trading/order` |
| `rapidx order replace` | `rapidx/order/replace` | `PUT /api/v1/trading/order` |
| `rapidx order cancel` | `rapidx/order/cancel` | `DELETE /api/v1/trading/order` |
| `rapidx order cancel-all` | `rapidx/order/cancel-all` | `DELETE /api/v1/trading/cancelAll` |
| `rapidx order query` | `rapidx/order/query` | `GET /api/v1/trading/order` |
| `rapidx order open-orders` | `rapidx/order/open-orders` | `GET /api/v1/trading/orders` |
cancel-all is a bulk destructive trading operation, and the skill presents it as a straightforward available command without nearby guardrails, confirmation requirements, or strong warnings. In an agent planning context, exposing a bulk action this powerful without safety cues increases the risk of mass order cancellation on production accounts from misunderstanding, prompt confusion, or overly broad tool selection.
| `rapidx order place` | `rapidx/order/place` | `POST /api/v1/trading/order` |
| `rapidx order replace` | `rapidx/order/replace` | `PUT /api/v1/trading/order` |
| `rapidx order cancel` | `rapidx/order/cancel` | `DELETE /api/v1/trading/order` |
| `rapidx order cancel-all` | `rapidx/order/cancel-all` | `DELETE /api/v1/trading/cancelAll` |
| `rapidx order query` | `rapidx/order/query` | `GET /api/v1/trading/order` |
| `rapidx order open-orders` | `rapidx/order/open-orders` | `GET /api/v1/trading/orders` |
| `rapidx order history` | `rapidx/order/history` | `GET /api/v1/trading/history/orders` |
The position close capability maps directly to a live DELETE operation and is accompanied by parameter guidance, making it operationally actionable. In this skill context, that increases the likelihood an agent may perform an irreversible financial action on a real account without sufficient warnings about liquidation, slippage, or production impact.
| `rapidx position history` | `rapidx/position/history` | `GET /api/v1/trading/history/position` |
| `rapidx position get-leverage` | `rapidx/position/get-leverage` | `GET /api/v1/trading/perp/leverage` |
| `rapidx position set-leverage` | `rapidx/position/set-leverage` | `POST /api/v1/trading/position/leverage` |
| `rapidx position close` | `rapidx/position/close` | `DELETE /api/v1/trading/position` |
| `rapidx position close-all` | `rapidx/position/close-all` | `DELETE /api/v1/trading/positions` |
`position.close` does not take `side` or `quantity`. In NET mode, omit `positionSide`; in HEDGE mode, pass the actual `LONG` or `SHORT` side.
position close-all is an account-wide destructive action that can unwind all open positions, potentially causing immediate realized losses and strategy disruption. Presenting it in a compact capabilities list without conspicuous warnings or confirmation guidance is especially dangerous in an agent skill because the operation is broad, irreversible in effect, and highly sensitive to accidental invocation.
| `rapidx position get-leverage` | `rapidx/position/get-leverage` | `GET /api/v1/trading/perp/leverage` |
| `rapidx position set-leverage` | `rapidx/position/set-leverage` | `POST /api/v1/trading/position/leverage` |
| `rapidx position close` | `rapidx/position/close` | `DELETE /api/v1/trading/position` |
| `rapidx position close-all` | `rapidx/position/close-all` | `DELETE /api/v1/trading/positions` |
`position.close` does not take `side` or `quantity`. In NET mode, omit `positionSide`; in HEDGE mode, pass the actual `LONG` or `SHORT` side.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
|---|---|---|
| `rapidx algo place` | `rapidx/algo/place` | `POST /api/v1/algo/order` |
| `rapidx algo replace` | `rapidx/algo/replace` | `PUT /api/v1/algo/order` |
| `rapidx algo cancel` | `rapidx/algo/cancel` | `DELETE /api/v1/algo/order` |
| `rapidx algo query` | `rapidx/algo/query` | `GET /api/v1/algo/order` |
| `rapidx algo open-orders` | `rapidx/algo/open-orders` | `GET /api/v1/algo/openOrders` |
| `rapidx algo history` | `rapidx/algo/history` | `GET /api/v1/algo/history/orders` |
The skill encourages collecting production credentials through agent-host chat-secret mechanisms and, if unavailable, writing placeholders or references into MCP config. Even though it warns about retention risk and says not to print full keys, this workflow increases the chance that sensitive secrets are persisted in host-managed stores or configuration files that may be accessible to other tools, users, backups, or collaboration features.
Ask whether the user wants to provide credentials as a user-provided chat secret. This is the default path for non-programmers, but state the risk first: even protected chat-secret flows are controlled by the agent host and may be subject to that host's retention, access, or collaboration settings.
If the agent host has a dedicated chat-secret UI, ask the user to create three secrets with the exact names `LTP_ACCESS_KEY`, `LTP_SECRET_KEY`, and `LTP_API_HOST`. If the host has no chat-secret UI, ask whether the user wants the agent to write masked-reference placeholders into MCP config or whether they prefer to set local environment variables manually.
Offer alternatives when the user wants stronger isolation:
The guidance explicitly introduces a Chinese-language example symbol component (币安人生USDT -> BINANCE_PERP_币安人生_USDT) as part of required normalization behavior. This suggests locale-specific handling in the skill instructions without offering user choice or explaining a region-specific requirement, which can conflict with organizational language/locale policy.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
1. Prefer the Agent host's user-provided chat secret mechanism.
2. Ask the user to create secrets named exactly `LTP_ACCESS_KEY`, `LTP_SECRET_KEY`, and `LTP_API_HOST`.
3. Do not ask the user to paste full keys into public chats, screenshots, logs, or repositories.
Fallbacks:
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## 12. Automation
Automation is a bounded local authorization session. It lets the Agent submit matching previews without asking for another per-order chat confirmation.
Automation still requires preview.
This overview documents live trading, cancellation, leverage, and position-closing capabilities in a planning reference without prominent warnings that these actions are financially destructive and may execute against production accounts. In an agent skill context, enumerating powerful write operations without explicit safety framing can normalize unsafe use and increase the chance an agent or operator invokes a live endpoint when they intended read-only discovery or preview.
Detected: suspicious.exposed_secret_literal