Back to skill

Security audit

LTP RapidX Trading

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RapidX live-trading guide with real financial authority, but its high-impact actions are purpose-aligned and generally gated by preview, consent, and readback instructions.

Install only if you trust the RapidX CLI publisher and are comfortable giving an agent scoped access to live trading credentials. Prefer a pinned, reviewed CLI version where possible, use the host's secret store, start with read-only checks, and enable automation only with narrow symbols, low notional caps, short duration, and clearly limited allowed actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/best-practices.md:138
Finding

Unpinned Global Installation of a Mutable npm Dependency

Content
View full analysis

Vulnerability Details

File Location: references/best-practices.md:138
Vulnerability Type: Insecure third-party dependency installation
Risk Level: Medium

Complete Code Snippet

bash
npm install -g @liquiditytech/rapidx-cli@latest

Technical Analysis

The documented command installs the mutable latest release of @liquiditytech/rapidx-cli globally. Because npm distribution tags can be reassigned, the effective package content may change after this Skill has been audited. The command does not pin an audited version or verify package integrity.

npm installation can also execute package lifecycle scripts. Consequently, compromise of the package publisher, npm account, release process, or package contents could cause attacker-controlled code to execute during installation. Global installation increases exposure because the resulting executable is available across workspaces rather than being isolated to this project.

This finding is limited to supply-chain risk in the documented installation process. The audited project itself contains no embedded executable scripts or confirmed malicious payload.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or another component capable of publishing @liquiditytech/rapidx-cli.
  2. The attacker publishes a malicious release and assigns it the latest distribution tag.
  3. An Agent follows the Skill guidance and runs the documented global installation command.
  4. npm downloads the attacker-controlled release.
  5. Malicious lifecycle scripts, if present, execute with the privileges of the user running npm.
  6. The compromised globally installed rapidx executable remains available to subsequent workspaces and can intercept credentials or alter future RapidX operations.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the installing user. Depending on those privileges and the host configu ...[truncated 471 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable @latest tag with an exact, reviewed version:
    bash
    npm install -g @liquiditytech/rapidx-cli@1.2.3
    
  2. Prefer a project-local dependency recorded in package.json and protected by a committed lockfile instead of a global installation.
  3. Install with npm ci where applicable so dependency resolution follows the reviewed lockfile.
  4. Verify that the package is retrieved from the expected npm registry and validate package provenance, signatures, or published integrity metadata before installation.
  5. Review package contents and lifecycle scripts before approving each upgrade.
  6. Do not upgrade automatically. Audit a new exact version first, then deliberately update the pinned version and lockfile.
  7. Run installation and the CLI as a non-privileged user in an isolated environment with access only to required credentials and files.
  8. Where operationally feasible, disable lifecycle scripts during installation and explicitly enable only reviewed setup steps:
    bash
    npm install --ignore-scripts --save-exact @liquiditytech/rapidx-cli@1.2.3
    
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/capability-overview.md (reported line 70)May include surrounding context.

md
| `rapidx order cancel-preview` | `rapidx/order/cancel-preview` | preview for cancel |
| `rapidx order place` | `rapidx/order/place` | `POST /api/v1/trading/order` |
| `rapidx order replace` | `rapidx/order/replace` | `PUT /api/v1/trading/order` |
| `rapidx order cancel` | `rapidx/order/cancel` | `DELETE /api/v1/trading/order` |
| `rapidx order cancel-all` | `rapidx/order/cancel-all` | `DELETE /api/v1/trading/cancelAll` |
| `rapidx order query` | `rapidx/order/query` | `GET /api/v1/trading/order` |
| `rapidx order open-orders` | `rapidx/order/open-orders` | `GET /api/v1/trading/orders` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

cancel-all is a highly destructive bulk action, and the capability overview presents it as a normal callable operation without any nearby warning, confirmation requirement, or scope limitation. In an agent-planning context, bulk destructive primitives materially raise the risk of accidental or prompt-induced misuse because a single invocation can remove all active orders.

Content

Scanner excerpt · references/capability-overview.md (reported line 71)May include surrounding context.

md
| `rapidx order place` | `rapidx/order/place` | `POST /api/v1/trading/order` |
| `rapidx order replace` | `rapidx/order/replace` | `PUT /api/v1/trading/order` |
| `rapidx order cancel` | `rapidx/order/cancel` | `DELETE /api/v1/trading/order` |
| `rapidx order cancel-all` | `rapidx/order/cancel-all` | `DELETE /api/v1/trading/cancelAll` |
| `rapidx order query` | `rapidx/order/query` | `GET /api/v1/trading/order` |
| `rapidx order open-orders` | `rapidx/order/open-orders` | `GET /api/v1/trading/orders` |
| `rapidx order history` | `rapidx/order/history` | `GET /api/v1/trading/history/orders` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

position.close is a live write operation that can liquidate exposure, and the note that it does not take side or quantity makes misuse more dangerous because an agent may issue a broad close action with limited precision. In this skill context, ambiguous or simplified close semantics increase the blast radius of mistakes or adversarial prompting.

Content

Scanner excerpt · references/capability-overview.md (reported line 92)May include surrounding context.

md
| `rapidx position history` | `rapidx/position/history` | `GET /api/v1/trading/history/position` |
| `rapidx position get-leverage` | `rapidx/position/get-leverage` | `GET /api/v1/trading/perp/leverage` |
| `rapidx position set-leverage` | `rapidx/position/set-leverage` | `POST /api/v1/trading/position/leverage` |
| `rapidx position close` | `rapidx/position/close` | `DELETE /api/v1/trading/position` |
| `rapidx position close-all` | `rapidx/position/close-all` | `DELETE /api/v1/trading/positions` |

`position.close` does not take `side` or `quantity`. In NET mode, omit `positionSide`; in HEDGE mode, pass the actual `LONG` or `SHORT` side.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

position.close-all is an extremely destructive bulk trading action that can flatten all open positions, potentially causing immediate realized losses, strategy failure, or forced portfolio changes. In an autonomous-agent setting, exposing this operation in a compact planning reference without hard warnings or confirmation expectations materially increases the chance of catastrophic accidental execution.

Content

Scanner excerpt · references/capability-overview.md (reported line 93)May include surrounding context.

md
| `rapidx position get-leverage` | `rapidx/position/get-leverage` | `GET /api/v1/trading/perp/leverage` |
| `rapidx position set-leverage` | `rapidx/position/set-leverage` | `POST /api/v1/trading/position/leverage` |
| `rapidx position close` | `rapidx/position/close` | `DELETE /api/v1/trading/position` |
| `rapidx position close-all` | `rapidx/position/close-all` | `DELETE /api/v1/trading/positions` |

`position.close` does not take `side` or `quantity`. In NET mode, omit `positionSide`; in HEDGE mode, pass the actual `LONG` or `SHORT` side.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/capability-overview.md (reported line 103)May include surrounding context.

md
|---|---|---|
| `rapidx algo place` | `rapidx/algo/place` | `POST /api/v1/algo/order` |
| `rapidx algo replace` | `rapidx/algo/replace` | `PUT /api/v1/algo/order` |
| `rapidx algo cancel` | `rapidx/algo/cancel` | `DELETE /api/v1/algo/order` |
| `rapidx algo query` | `rapidx/algo/query` | `GET /api/v1/algo/order` |
| `rapidx algo open-orders` | `rapidx/algo/open-orders` | `GET /api/v1/algo/openOrders` |
| `rapidx algo history` | `rapidx/algo/history` | `GET /api/v1/algo/history/orders` |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
Preview ids are runtime-local. Use MCP preview ids only with the same MCP server runtime. Use CLI preview ids only with the same CLI preview store. Do not cross-submit MCP preview ids through CLI, or CLI preview ids through MCP.

Automation session still requires preview. Use it only when the user explicitly enables RapidX automation in chat and authorizes symbol, per-order max notional, total max notional, duration, allowed actions, and allowed order types. For normal order lifecycle automation, use `allowedActions=["order.place","order.replace","order.cancel"]`. First create a session with `rapidx/automation/start`; the input must include `explicitUserConsent=true` and `acceptedRiskText` copied from the user's authorization. Then add `automationSessionId` to order place/replace/cancel preview input. If the preview returns `automationSession.confirmationMode="automation-session"` and `confirmation.submitToken`, submit that preview without asking for another per-order chat confirmation. Do not invent automation scope. If no matching session exists, create one only after user authorization. If multiple sessions match, ask which session to use or pass the intended `automationSessionId`.

Automation session flow:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/best-practices.md (reported line 116)May include surrounding context.

md
1. Prefer the Agent host's user-provided chat secret mechanism.
2. Ask the user to create secrets named exactly `LTP_ACCESS_KEY`, `LTP_SECRET_KEY`, and `LTP_API_HOST`.
3. Do not ask the user to paste full keys into public chats, screenshots, logs, or repositories.

Fallbacks:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
96% confidence
Finding

This section explicitly allows the agent to submit future matching orders without an additional per-order chat confirmation once an automation session is established. In a live trading skill, that meaningfully increases autonomous execution risk: if the session scope is overly broad, misconfigured, or the agent misinterprets user intent, orders can be placed without contemporaneous human approval, leading to financial loss.

Content

Scanner excerpt · references/best-practices.md (reported line 399)May include surrounding context.

md
## 12. Automation

Automation is a bounded local authorization session. It lets the Agent submit matching previews without asking for another per-order chat confirmation.

Automation still requires preview.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description says the skill is for portfolio reads, market reads, order preview/submit/replace/cancel, position management, algo orders, and live trading verification. This reference additionally documents portfolio set-position-mode, which changes account configuration rather than reading portfolio state or directly managing a position, expanding the advertised behavior beyond the stated description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The overview prominently lists state-changing trading operations such as order placement, cancellation, leverage changes, position closure, and algo actions without an explicit warning that these can modify a live account and cause financial loss. In an agent skill, omission of prominent safety framing increases the chance that an agent or operator treats destructive operations as routine, especially because the file is presented as planning guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.