Back to skill

Security audit

snaptrade-API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a clearly disclosed SnapTrade brokerage/trading helper, but installing it gives an agent access to sensitive account data and live trading actions if the user provides credentials.

Install only if you intentionally want OpenClaw to interact with a SnapTrade-connected brokerage. Use paper trading or a low-limit account first, keep SnapTrade secrets in a secret manager or uncommitted .env file, require explicit confirmation for every live order or cancellation, and enable automated trading only with strict allowlists and loss/notional limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:15
Finding

Third-Party Dependencies Installed Without Cryptographic Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: scripts/setup.sh:15-17
Vulnerability Type: Supply-chain exposure through dependency installation without hash verification
Risk Level: Medium

Vulnerable Code

bash
"$VENV_DIR/bin/pip" install --quiet \
  "snaptrade-python-sdk==11.0.187" \
  "python-dotenv==1.2.2"

Technical Analysis

The setup script installs two packages from pip using exact version constraints, but it does not verify the cryptographic hashes of downloaded artifacts. Version pinning helps prevent unexpected upgrades, but it does not authenticate package contents or constrain unpinned transitive dependencies.

The subsequent version check only reads installed package metadata:

bash
SNAPTRADE_VER=$("$VENV_DIR/bin/pip" show snaptrade-python-sdk | grep "^Version:" | awk '{print $2}')
DOTENV_VER=$("$VENV_DIR/bin/pip" show python-dotenv | grep "^Version:" | awk '{print $2}')

A compromised artifact can report the expected version, so this check cannot establish integrity. Installation may also execute package-controlled build logic. This is especially consequential because the installed SnapTrade SDK later receives brokerage credentials and can perform account-data retrieval, order placement, and cancellation.

No evidence was found that the named packages or specified versions are malicious. The vulnerability is the absence of artifact and transitive-dependency integrity controls.

Attack Path

  1. An attacker compromises a package release artifact, package-index delivery path, or transitive dependency used by one of the declared packages.
  2. A user runs bash scripts/setup.sh.
  3. pip downloads the affected artifact without comparing it against a trusted hash.
  4. Malicious code executes during package installation, SDK import, or a subsequent API operation.
  5. Once the Skill is used, the malicious dependency may access the process environment containing SnapTrade credentials.
  6. The dependency could disclose those c ...[truncated 866 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a fully resolved dependency lock file covering both direct and transitive dependencies.
  2. Record reviewed SHA-256 hashes for every permitted distribution artifact.
  3. Install dependencies with hash enforcement, for example:
bash
"$VENV_DIR/bin/pip" install \
  --require-hashes \
  --only-binary=:all: \
  -r requirements.lock
  1. Prefer wheel-only installation where practical to reduce execution of source-build logic.
  2. Download and review artifacts through a controlled dependency-update process rather than resolving dependencies during ordinary setup.
  3. Consider using an authenticated internal package mirror populated only with approved artifacts.
  4. Run vulnerability and provenance checks before approving SDK upgrades.
  5. Execute setup and runtime under a dedicated, minimally privileged operating-system account.
  6. Limit brokerage permissions and use paper-trading or low-limit accounts during testing.
  7. Keep secrets in a dedicated secret manager and expose them only to the runtime process that requires them.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says this skill should handle live brokerage/account interactions via SnapTrade whenever trading or account data is needed. However, the supplied code chunk does not perform any SnapTrade API operations at all. It only prepares a local Python environment and instructs the operator to set credentials. That setup behavior may support the declared purpose, but it is not the declared operational functionality itself. Therefore the code chunk does not accurately represent the stated skill behavior and is a material mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger language is extremely broad, effectively routing any brokerage-related request to a skill that can place real trades and access sensitive account data. Overbroad activation increases the risk of accidental invocation, action on ambiguous user intent, and unauthorized high-impact financial operations in contexts where only informational help was expected.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- This skill can place real trades and cancel orders on connected brokerage accounts.
  - Default to requiring user confirmation per trade. Automated mode is supported if explicitly configured — enforce symbol allowlists, notional caps, position limits, and daily loss limits before enabling.
  - Use paper trading or a low-limit account during testing.
  - Store credentials in a .env file or secret manager — never hardcode, log, or pass them through untrusted channels.
  - Rotate SNAPTRADE_USER_SECRET immediately via the SnapTrade dashboard if there is any chance it was exposed.
  - Prefer a dedicated SnapTrade user with limited brokerage permissions for automated trading rather than using your primary account credentials.
compatibility:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 37)May include surrounding context.

sh
- This skill can place real trades and cancel orders on connected brokerage accounts.
  - Default to requiring user confirmation per trade. Automated mode is supported if explicitly configured — enforce symbol allowlists, notional caps, position limits, and daily loss limits before enabling.
  - Use paper trading or a low-limit account during testing.
  - Store credentials in a .env file or secret manager — never hardcode, log, or pass them through untrusted channels.
  - Rotate SNAPTRADE_USER_SECRET immediately via the SnapTrade dashboard if there is any chance it was exposed.
  - Prefer a dedicated SnapTrade user with limited brokerage permissions for automated trading rather than using your primary account credentials.
compatibility:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares access to sensitive environment-based credentials and trading capability but does not define any explicit tool scope or permission boundaries. In an agentic environment, missing scope constraints can let the skill be invoked too broadly and increase the chance of unintended credential exposure or unauthorized brokerage actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This documentation guides an agent to retrieve highly sensitive brokerage data including account numbers, balances, positions, holdings, and order history, but it provides no privacy boundaries, data-minimization guidance, or warnings about exposing this information to users, logs, or downstream tools. In a trading skill, that omission is materially risky because agents may over-fetch or disclose full financial data when only a narrow answer was needed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation instructs the agent to place live crypto orders directly and emphasizes broad triggering for trading actions, but it does not clearly require explicit user confirmation that real funds will be committed. In an agentic trading context, that omission increases the risk of unintended or misinterpreted instructions resulting in irreversible financial transactions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file documents options trading, including multi-leg orders and short option actions, while the manifest describes the skill more generically as buy/sell orders and account data operations through SnapTrade. This creates a scope expansion risk: an agent may invoke higher-risk derivatives functionality without explicit declaration, review, or policy gating, increasing the chance of unauthorized or unsafe trading behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Canceling an order changes live brokerage state and can materially affect execution outcomes, yet the instructions present cancellation as a simple endpoint call without requiring explicit acknowledgment. In a trading skill, this can lead to unintended disruption of active strategies or failure of protective orders if an agent acts on an ambiguous command.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The notes instruct readers to use get_crypto_pairs to find the correct symbol, but no such function appears in this file. Earlier code examples instead use snaptrade.trading.search_cryptocurrency_pair_instruments, so the documentation contradicts the demonstrated API usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.