Back to skill

Security audit

Quant Trade

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about enabling OKX analysis and live trading, but it grants broad financial trading authority through globally installed, unpinned dependencies and should be reviewed carefully before use.

Install only in an isolated environment, prefer demo mode first, use OKX API keys with the minimum trading permissions and no withdrawal permission, and review or pin the Python and npm dependencies before connecting live credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Dependencies in a Credentialed Trading Environment

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–18 and 27–35
Vulnerability Type: Unpinned third-party dependencies and unsafe global package installation
Risk Level: Medium

Vulnerable Code

yaml
agent:
  requires:
    python: ">=3.8"
    packages: ["pandas", "requests", "apscheduler"]
    bins: ["okx"]
  install:
    - id: npm
      kind: node
      package: "@okx_ai/okx-trade-cli"
      bins: ["okx"]
      label: "Install okx CLI (npm)"
bash
pip install pandas requests apscheduler
bash
npm install -g @okx_ai/okx-trade-cli

Technical Analysis

The installation instructions do not pin exact dependency versions, provide integrity hashes, or rely on committed lockfiles. Each installation can therefore resolve different package and transitive-dependency versions from external registries.

This is particularly sensitive because @okx_ai/okx-trade-cli is installed globally and is intended to access configured OKX API credentials and execute authenticated financial transactions. Package installation can also execute package lifecycle scripts with the installing user's privileges. If a package release, maintainer account, registry response, or transitive dependency is compromised, malicious code could run during installation or later when the trading CLI is invoked.

The audit did not identify evidence that the named packages are currently malicious. The finding concerns the absence of reproducible, integrity-verified dependency controls in a high-impact trading environment.

Attack Path

  1. An attacker compromises a listed package, one of its transitive dependencies, a package maintainer account, or the associated registry distribution channel.
  2. The attacker publishes a malicious version that remains compatible with the unrestricted installation command.
  3. A user follows the documented pip install or global npm install instruction.
  4. Th ...[truncated 1308 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an exact, reviewed version rather than using unconstrained package names.
  2. Commit package-manager lockfiles that include all transitive dependencies.
  3. For Python dependencies, use a hash-verified requirements file and install with pip install --require-hashes -r requirements.txt.
  4. For Node.js dependencies, install from a reviewed lockfile using npm ci rather than a mutable global installation.
  5. Avoid global package installation. Run the CLI in a dedicated virtual environment, container, or otherwise isolated execution context.
  6. Verify package provenance, signatures, publisher identity, and registry source before installation.
  7. Disable package lifecycle scripts where operationally possible, or review all required lifecycle scripts before allowing them to execute.
  8. Add automated dependency scanning and lockfile review to the release process.
  9. Use dedicated OKX API keys with only the permissions required for the intended workflow. Do not grant withdrawal permission.
  10. Separate demonstration and live credentials, protect credential files with restrictive filesystem permissions, and rotate credentials after any suspected dependency compromise.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description materially overstates the skill's functionality. While the code does support the analysis portion of the declaration—fetching OKX public K-line data and calculating RSI, EMA, Bias, and Bollinger Bands—it contains no trading execution features at all. There are no calls to private OKX endpoints, no authentication/signing logic, no credential handling, no subprocess/CLI invocation for OKX commands, and no order/position management. The actual primary behavior is a read-only indicator calculator, not a combined analysis plus execution trading skill. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a broad OKX trading skill that combines technical analysis with actual trade execution via CLI. In contrast, this code chunk only implements a scheduler that repeatedly calls process_data to fetch/calculate indicators on a timed basis and logs success/failure. Its primary purpose is automated scheduled monitoring, which is not the same as the declared comprehensive analysis-plus-order-execution behavior. While scheduled indicator calculation is related to quantitative analysis, the trading/execution capabilities prominently claimed in the description are not represented here, and the chunk introduces an automation/scheduling capability that is not clearly declared as part of the skill's main behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to use networked components (OKX public API via Python requests and authenticated OKX CLI trading commands) but does not declare any tool scope such as permissions or allowed-tools. In an agent environment, undeclared network capability weakens policy enforcement and can enable unintended outbound requests or live trading actions without clear sandbox constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill title and core operating instructions are presented in Chinese, and the prescribed agent/user prompts later in the file are also Chinese-centric. There is no statement that users may choose their preferred language, so the documentation effectively imposes a specific language/locale by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language strings entirely in Chinese, including the module description and later CLI help/output text, with no option to choose another language. The policy explicitly calls for flagging language or locale constraints when the skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and CLI help/logging strings are written in Chinese throughout the file, which effectively forces a specific language for users of the skill. The policy allows locale constraints only when the skill offers user choice or clearly documents a justified regional restriction, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.