Back to skill

Security audit

三立智期 抢先版

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real futures-trading skill, but it handles trading credentials and live order authority with endpoint and persistence risks that users should review before installing.

Install only if you trust this publisher and understand it can access trading account data and submit or cancel orders when configured. Keep the environment on sim unless you intentionally use live, avoid configuring any non-HTTPS or non-official API domain, review live order details before approval, and treat the stored API key files as sensitive secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
runtime/mcp/src/index.ts:81
Finding

Configurable API endpoint permits credential transmission to arbitrary or plaintext destinations

Content
View full analysis
{ const rawDomain = (process.env[DOMAIN_ENV] ?? "").trim(); const domainSource: RuntimeConfig["domainSource"] = rawDomain ? "env" : "default"; const domain = normalizeDomain(rawDomain || DEFAULT_DOMAIN); const rawEnv = (process.env[TRADING_ENV] ?? "sim").trim().toLowerCase(); let tradingEnv: RuntimeConfig["tradingEnv"] = "sim"; if (rawEnv === "live") { tradingEnv = "live"; } else if (rawEnv !== "sim") { console.error(`WARN: ${TRADING_ENV}=${rawEnv} 非法,已按 sim 处理(合法值:sim 或 live)`); } const { apiKey, source } = await resolveApiKey(domain); if (!apiKey) { console.error(`WARN: 未配置 ${API_KEY_ENV},交易类工具将返回登录指引;可用 slzq_open_v1_auth_login 完成登录。`); } return { domain, domainSource, apiBase: `${domain}/mobile-api`, apiKey, apiKeySource: source, tradingEnv }; } ``` ```typescript async function openApiFetch( path: string, options: { method?: string; auth: boolean; searchParams?: Record; body?: unknown; } ): Promise<{ ok: boolean; status: number; body: unknown }> { const url = new URL(`${config.apiBase}/open/v1${path.startsWith("/") ? path : `/${path}`}`); if (options.searchParams) { for (const [k, v] of Object.entries(options.searchParams)) { ...[truncated 3893 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
install/setup-clawhub.mjs:52
Finding

Recommended setup automatically downloads dependencies from a non-canonical registry mirror

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (81)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是面向用户的期货交易与行情查询能力,但实际代码片段只是一个开发/测试用 shell 脚本,用于检查并运行 MCP tools 的自检脚本,必要时安装 Node.js 依赖。该代码没有体现任何与期货交易、模拟盘密钥发放、行情查询、持仓查询、委托/撤单、开户咨询相关的业务逻辑或资源访问。因此这不是对已声明能力的支持性实现细节,而是一个 materially different primary purpose(安装与测试基础设施),与声明用途明显不符。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims a full-featured futures trading skill with simulation and quote/position/order capabilities. The actual code chunk contains no implementation beyond an empty module stub. Therefore the code does not substantiate the declared purpose at all, indicating a clear description-behavior mismatch. There is no evidence of undeclared harmful behavior; the mismatch is that the advertised capabilities are absent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
node install/setup-clawhub.mjs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
MCP 入口是本包里的 `runtime/mcp/dist/index.js`。脚本会尝试写入 OpenClaw;成功后请 **完全退出并重启客户端**,再新开对话。也可以在对话里直接说「帮我注册三立智期 MCP」,智能体会协助。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install/doctor.sh (reported line 31)May include surrounding context.

sh
pass "Node.js $(node -v)"

DEFAULT_DOMAIN="https://slzqapi.sxslqhsh.com"
CREDENTIALS_FILE="${HOME}/.slzq-trading/credentials.json"

DOMAIN="${!DOMAIN_ENV:-}"
API_KEY="${!API_KEY_ENV:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install/test_connection.sh (reported line 39)May include surrounding context.

sh
pass "Node.js $(node -v)"

DEFAULT_DOMAIN="https://slzqapi.sxslqhsh.com"
CREDENTIALS_FILE="${HOME}/.slzq-trading/credentials.json"

DOMAIN="${!DOMAIN_ENV:-}"
API_KEY="${!API_KEY_ENV:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mcp/README.md (reported line 35)May include surrounding context.

md
pass "Node.js $(node -v)"

DEFAULT_DOMAIN="https://slzqapi.sxslqhsh.com"
CREDENTIALS_FILE="${HOME}/.slzq-trading/credentials.json"

DOMAIN="${!DOMAIN_ENV:-}"
API_KEY="${!API_KEY_ENV:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · runtime/mcp/README.md (reported line 144)May include surrounding context.

md
pass "Node.js $(node -v)"

DEFAULT_DOMAIN="https://slzqapi.sxslqhsh.com"
CREDENTIALS_FILE="${HOME}/.slzq-trading/credentials.json"

DOMAIN="${!DOMAIN_ENV:-}"
API_KEY="${!API_KEY_ENV:-}"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This documentation explicitly supports live order placement and cancellation for real-money futures trading but does not present any explicit user-facing warning, confirmation requirement, or risk disclosure in the described flow. In an agent skill context, that omission increases the chance that a user or downstream agent triggers irreversible financial actions without fully understanding that 'live' affects real funds and positions.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill instructs the agent to receive an API key from a login flow and write it into environment/config files such as ~/.slzq-trading/credentials.json and ~/.openclaw/openclaw.json for future reuse. This is credential handling and persistence of a trading key on disk, which materially increases the blast radius if the host, logs, or config files are later exposed; in this trading context, compromise could enable account access, market data access, and potentially order placement depending on key scope.

Content

Scanner excerpt · references/usage-notes.md (reported line 180)May include surrounding context.

md
**走 HTTP 路径时第 5 步之后**:响应 `data.apiKey` 就是完整密钥。**禁止回显给用户**;把它写入 `SLZQ_OPENCLAW_API_KEY` 后继续调用,并提示用户在客户端配置里持久化该变量(否则下次会话还要重领)。MCP 路径无需这一步,工具已自动落盘。

登录成功后:未注册的手机号自动注册;**模拟盘账户自动开通并在响应里回报状态**(`simAccountReady` / `simAccountBalance`,无需回 App 操作);密钥自动落盘(`~/.slzq-trading/credentials.json`,权限 `0600`;本机装了 OpenClaw 时并入 `~/.openclaw/openclaw.json`),**当前会话立即生效,无需重启**。拿到密钥后**直接继续用户原本的任务**,不要停下来汇报流程。

响应里的 `keyCreated` 告诉你这把钥匙的来历:`true`=本次新签发;`false`=**返回的是该账号原有的模拟盘密钥**,和用户在 App 里看到的是同一把,可以据此安抚"没有生成新密钥、旧配置不受影响"。

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill persists API credentials to a predictable file under the user's home directory and also attempts to merge the key into another local config file. Although it uses restrictive file permissions and masks keys in responses, local plaintext storage increases the blast radius of host compromise, backup leakage, or accidental exposure through other tools that can read user files.

Content

Scanner excerpt · runtime/mcp/dist/index.js (reported line 22)May include surrounding context.

js
const TRADING_ENV = "SLZQ_OPENCLAW_ENV";
/** 登录后落盘的凭据文件:宿主不是 OpenClaw 时也能让密钥跨重启生效 */
const CREDENTIALS_DIR = join(homedir(), `.${SKILL_NAME}`);
const CREDENTIALS_FILE = join(CREDENTIALS_DIR, "credentials.json");
/** OpenClaw 网关自身的配置;仅在用户确实装了 OpenClaw(目录已存在)时才合并写入 */
const OPENCLAW_CONFIG_FILE = join(homedir(), ".openclaw", "openclaw.json");
const NO_API_KEY_HINT = `尚未配置 ${API_KEY_ENV}。有两种取钥方式,先把两种都告诉用户让其选择,不要替他决定:` +

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
84% confidence
Finding

fast-uri 3.1.0 has multiple high-severity URI parsing issues, including host confusion and malformed IPv6 handling that can enable SSRF or security boundary bypass in software that trusts parsed URLs. In a trading skill that may call upstream market, account, or simulation APIs, incorrect URL parsing is particularly risky because it can redirect internal requests or defeat allowlists.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: hono==4.12.11 — 16 advisory(ies): CVE-2026-56762 (Hono missing validation of cookie name on write path in setCookie()); CVE-2026-47676 (Hono: app.mount() strips mount prefix using undecoded path, causing incorrect ro); CVE-2026-47675 (Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie) +13 more

High
Category
Supply Chain
Confidence
88% confidence
Finding

hono 4.12.11 is flagged with numerous advisories affecting cookie handling, routing, and related framework behaviors, indicating an elevated risk in the web framework layer. Because this skill is for trading operations and may handle authentication, API keys, or order-related traffic, weaknesses in cookie sanitization or route matching can materially increase the chance of session abuse, misrouting, or bypass of intended controls.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.1.0 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
80% confidence
Finding

ip-address 10.1.0 includes advisories for address parsing ambiguities and XSS in HTML-emitting methods. In services that rely on IP parsing for rate limiting, allowlists, audit logging, or admin restrictions, inconsistent interpretation of leading-zero octets can weaken network-based controls; the XSS aspect matters if any rendered diagnostics are exposed in a UI.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The skill persists API credentials to a predictable file under the user's home directory and also attempts to merge them into another local config file. Although the code sets restrictive permissions and masks keys in output, storing long-lived trading credentials on disk increases the blast radius of local compromise, accidental backup/sync leakage, or other processes reading the file if host isolation is weak.

Content

Scanner excerpt · runtime/mcp/src/index.ts (reported line 25)May include surrounding context.

ts
/** 登录后落盘的凭据文件:宿主不是 OpenClaw 时也能让密钥跨重启生效 */
const CREDENTIALS_DIR = join(homedir(), `.${SKILL_NAME}`);
const CREDENTIALS_FILE = join(CREDENTIALS_DIR, "credentials.json");
/** OpenClaw 网关自身的配置;仅在用户确实装了 OpenClaw(目录已存在)时才合并写入 */
const OPENCLAW_CONFIG_FILE = join(homedir(), ".openclaw", "openclaw.json");

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises access to API keys, networked trading endpoints, and an installation/setup script, but it does not declare an explicit tool/permission scope. In a trading context, undeclared access to env/network/shell increases the risk of secret exposure, unauthorized requests, or local command execution without clear user/admin review boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger set contains broad, common finance terms that can cause the skill to activate in unrelated conversations. In a skill capable of handling API keys and trading actions, accidental invocation raises the chance of exposing account context, prompting for sensitive data, or steering users into transactional flows they did not intend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L16 requires that all three display methods include a specific Chinese sentence, which imposes a language choice on the user interaction. The file does not mention user opt-in, multilingual support, or a documented region-specific justification for forcing Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script emits user-facing status and remediation text in Chinese, for example in the fail helper and many subsequent echo statements. The file does not offer an opt-in language choice or explain that the skill is intentionally limited to Chinese-speaking users, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's echo statements are hardcoded in Chinese, which imposes a specific language on users. This matches the language/locale policy violation category because there is no opt-in, fallback language, or documented justification for restricting output to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file appears to require Chinese for all user-facing documentation, beginning with the title and continuing throughout the API descriptions. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-examples-errors.md (reported line 18)May include surrounding context.

md
# 首次安装:登录领取模拟盘密钥(三步均无需鉴权)
curl -s "$API_BASE/open/v1/auth/agreement" | jq .

curl -s -X POST "$API_BASE/open/v1/auth/sms/send" \
  -H "Content-Type: application/json" \
  -d '{"mobileNum":"13800000000"}' | jq .

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-examples-errors.md (reported line 24)May include surrounding context.

md
# verifyCode 位数以上一步响应的 codeLength 为准(当前 4 位纯数字),字符串原样传、保留前导零
# codeKey 不用传:服务端按手机号暂存并自动取回
curl -s -X POST "$API_BASE/open/v1/auth/login" \
  -H "Content-Type: application/json" \
  -d '{
        "mobileNum": "13800000000",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-examples-errors.md (reported line 73)May include surrounding context.

md
-H "X-Trading-Env: ${ENV}" | jq .

# 下单(限价买入开仓,sim)
curl -s -X POST "$API_BASE/open/v1/orders" \
  -H "Authorization: Bearer ${API_KEY}" \
  -H "X-Trading-Env: sim" \
  -H "Content-Type: application/json" \

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.potential_exfiltration

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
install/setup-clawhub.mjs:34

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
install/test_mcp_tools.mjs:18

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
install/test_connection.sh:20

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
runtime/mcp/dist/index.js:60

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
runtime/mcp/src/index.ts:78

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
runtime/mcp/dist/index.js:65

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
runtime/mcp/src/index.ts:83