T09 · Insecure Skill Coding Practices
- Location
scripts/rapidapi_fetch.py:23- Finding
RapidAPI Key Exposed Through Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is transparent about building automated crypto trading, but it asks for high-impact exchange credentials and scheduled trading execution without enough containment or secure secret handling.
Install only if you are comfortable reviewing and constraining an automated trading workflow yourself. Use testnet or dry-run first, avoid passing secrets on the command line, lock down any env file before adding credentials, and require explicit human approval before any live dYdX order execution or cron enablement.
scripts/rapidapi_fetch.py:23RapidAPI Key Exposed Through Command-Line Arguments
scripts/bootstrap_env.py:28Sensitive Environment File Created Without Enforced Restrictive Permissions
The skill advertises end-to-end automated trading, credential bootstrap, cron execution, TP/SL, cleanup, and notifications, but the analyzed content does not implement those controls and instead appears limited to signal retrieval guidance. This mismatch is dangerous because operators may rely on non-existent safeguards or execution logic, leading to unsafe deployment decisions, mishandled credentials, or unmonitored trading behavior in a high-risk financial context.
The skill describes operations that inherently require sensitive capabilities—network access, file writes, and likely shell/cron orchestration—but it declares no explicit tool scope or permission boundaries. In an agent setting, this creates an overbroad and ambiguous execution surface where a caller or runtime may grant more access than necessary, which is especially risky because the workflow handles API keys, trading credentials, and automated order execution.
The checklist explicitly asks operators to collect highly sensitive secrets, including a RapidAPI key, dYdX mnemonic path, and Telegram bot token, but provides no guidance on secure storage, masking, least-privilege handling, or avoiding disclosure in logs and chat. In a trading automation skill, these credentials can enable account takeover, unauthorized trading, data exposure, or abuse of notification infrastructure if mishandled.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
return
out.write_text(TEMPLATE)
print(f"Wrote {out}")
print("Run: chmod 600 .env.crypto-signals")
if __name__ == "__main__":
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
return
out.write_text(TEMPLATE)
print(f"Wrote {out}")
print("Run: chmod 600 .env.crypto-signals")
if __name__ == "__main__":
This code performs an outbound HTTP request to a third-party RapidAPI host and transmits the provided API key in request headers, but there is no docstring, comment, or other in-code disclosure explaining that behavior. For code files, network calls that transmit user or system data should have some visible warning or explanation unless clearly documented elsewhere.
No suspicious patterns detected.