Security audit
btc-strategy-v40
Security checks for vulnerabilities and agentic risk
Overview
The skill mostly matches a BTC trading-monitoring purpose but it reads undeclared local credential files, writes persistent state/logs in the user home, and posts notifications to a hard-coded Telegram chat ID — these behaviors are not declared in the metadata and could leak data or be surprising.
Before installing or running this skill: 1) Review and understand the two included scripts — they are not merely examples but will be executed. 2) The monitor script will read a Telegram token from ~/.config/trading_bot/telegram_token (if present) and send messages to a hard-coded chat_id (5876347015). If you keep a token file there your bot credentials may be used to post to that chat; replace or remove the file or change the script to use your own token/chat_id. 3) The scripts will create persistent files under $HOME/.okx_data and write state/log files — back up or inspect these before running. 4) The code calls external services (OKX API, Binance API, Telegram) and may invoke an 'okx' CLI if present; ensure you trust those binaries and that no automatic trade-execution component exists in your environment. 5) Best practice: run the scripts in an isolated/sandbox environment (or inspect/modify them so they prompt you for the Telegram token/chat_id and confirm any trade-execution actions) and verify exactly what /tmp/btc_signal.txt and other output files contain before connecting them to any live trading infrastructure.
Static analysis
No suspicious patterns detected.
