Back to skill

Security audit

Okx Strategy Factory

Security checks for vulnerabilities and agentic risk

Overview

The skill broadly matches its stated trading-strategy factory purpose, but it needs Review because it can drive live trading, VPS deployment, and GitHub publishing with sensitive credentials and limited explicit pre-action controls.

Install only in an isolated development workspace, not near production credentials or funded wallets. Pin installer versions, use least-privilege OKX keys and a limited test wallet, require explicit confirmation before any signing, VPS deployment, git push, or GitHub release, and audit generated skills before use, especially any reference files treated as authoritative.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
assets/skill-templates/tool-wrapper.md:54
Finding

Loaded reference files are granted unsafe instruction precedence

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/publish.sh:53
Finding

Unvalidated strategy identifiers permit filesystem path traversal

Content
View full analysis
&2 exit 1 fi shift ``` ```bash SKILL_DIR="$REPO_ROOT/$SKILL_NAME" SKILL_FILE="$SKILL_DIR/SKILL.md" ``` ```bash if [[ -n "$COPY_SCRIPT" ]]; then echo -e "\n${BLUE}[0/4] 复制策略脚本${NC}" if [[ ! -f "$COPY_SCRIPT" ]]; then fail "脚本不存在: $COPY_SCRIPT" exit 1 fi mkdir -p "$SKILL_DIR" cp "$COPY_SCRIPT" "$SKILL_DIR/" pass "已复制 $(basename "$COPY_SCRIPT") -> $SKILL_DIR/" fi ``` ```bash git add "$SKILL_NAME/" ``` The completion hook repeats the same trust problem with an environment-provided identifier: ```bash STRATEGY="${CLAUDE_STRATEGY_NAME:-}" if [[ -z "$STRATEGY" ]]; then STRATEGY=$(ls -dt Strategy/*/ 2>/dev/null | head -1 | xargs basename 2>/dev/null || true) fi ``` ```bash V=$(ls -d "Strategy/$STRATEGY/Script/v"*/ 2>/dev/null | sort -V | tail -1) ``` ### Technical Analysis `SKILL_NAME` and `CLAUDE_STRATEGY_NAME` are used as path components without syntax validation or canonical-path containment checks. Quoting prevents ordinary shell word splitting and metacharacter expansion, but it does not prevent filesystem traversal through values containing `/`, `..`, or absolute-path-like structures. In the publisher, a traversal identifier changes `SKILL_DIR`, after which `mkdir -p` and `cp` can operate outside the intended skill directory. The same identifier is later used as a Git pathspec, potentially staging files outside the intended strategy subtree. In the completion gate, a traversal-capable strategy name can redirect vali ...[truncated 2103 chars]
Remediation
View remediation
&2; exit 1; } [[ "$value" != "." && "$value" != ".." ]] || { echo "Invalid identifier" >&2; exit 1; } } validate_identifier "$SKILL_NAME" ``` 2. Apply the same validation to `CLAUDE_STRATEGY_NAME` before any hook uses it. 3. Enforce canonical containment: ```bash EXPECTED_ROOT="$(realpath "$REPO_ROOT")" SKILL_DIR="$(realpath -m "$EXPECTED_ROOT/$SKILL_NAME")" case "$SKILL_DIR" in "$EXPECTED_ROOT"/*) ;; *) echo "Resolved path escapes repository root" >&2; exit 1 ;; esac ``` 4. Use a dedicated strategies root rather than permitting arbitrary repository-root destinations. 5. Reject: - Values containing `/` or backslashes. - `.` and `..`. - Control characters and newline characters. - Identifiers beginning with `-`. - Symlinked destination directories that resolve outside the approved root. 6. Before copying or staging: - Resolve both source and destination paths. - Verify the destination remains beneath the approved root. - Pass `--` before Git path arguments, such as `git add -- "$relative_path"`. 7. Strengthen completion gates: - Parse JSON with a real JSON parser rather than using `grep`. - Bind the expected strategy and version to trusted pipeline state. - Verify canonical paths before inspecting files. - Ensure gate evidence was generated for the current pipeline execution. ]]>

T08 · Insecure Dependencies

Warning
Location
README.md:42
Finding

Installation instructions execute unpinned registry packages through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises a tightly controlled multi-agent trading-strategy lifecycle, but the finding indicates the actual behavior includes repository publishing, file copying, and git push operations that are not clearly declared in the user-facing description. In an agent setting, this kind of capability mismatch is dangerous because users may invoke what they think is a planning or analysis workflow, while the skill performs external side effects such as modifying local files or publishing to remotes, which can lead to unauthorized code release or supply-chain risk.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/SKILL_TEMPLATE.md (reported line 21)May include surrounding context.

md
一句话概述:Skill 做什么、怎么触发、输出到哪里。

<!--
选择你的设计模式,从 Skills/templates/ 目录获取对应模板:

| Pattern        | 适用场景                           | 模板文件                  |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/SKILL_TEMPLATE.md (reported line 21)May include surrounding context.

md
一句话概述:Skill 做什么、怎么触发、输出到哪里。

<!--
选择你的设计模式,从 Skills/templates/ 目录获取对应模板:

| Pattern        | 适用场景                           | 模板文件                  |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/generator.md (reported line 15)May include surrounding context.

md
# <Skill 名称> (Generator)

<!--
Generator 模式:强制一致的输出结构。
用 assets/ 存输出模板,references/ 存风格指南。
指令协调检索并逐步填充。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/generator.md (reported line 15)May include surrounding context.

md
# <Skill 名称> (Generator)

<!--
Generator 模式:强制一致的输出结构。
用 assets/ 存输出模板,references/ 存风格指南。
指令协调检索并逐步填充。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/inversion.md (reported line 14)May include surrounding context.

md
# <Skill 名称> (Inversion)

<!--
Inversion 模式:Agent 先采访用户再行动。
分阶段提问,显式门控("DO NOT start building until all phases are complete")。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/inversion.md (reported line 14)May include surrounding context.

md
# <Skill 名称> (Inversion)

<!--
Inversion 模式:Agent 先采访用户再行动。
分阶段提问,显式门控("DO NOT start building until all phases are complete")。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/pipeline.md (reported line 14)May include surrounding context.

md
# <Skill 名称> (Pipeline)

<!--
Pipeline 模式:严格顺序多步工作流 + 硬检查点。
显式菱形门控条件,需要满足条件才能进入下一步。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/pipeline.md (reported line 14)May include surrounding context.

md
# <Skill 名称> (Pipeline)

<!--
Pipeline 模式:严格顺序多步工作流 + 硬检查点。
显式菱形门控条件,需要满足条件才能进入下一步。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/reviewer.md (reported line 14)May include surrounding context.

md
# <Skill 名称> (Reviewer)

<!--
Reviewer 模式:分离"检查什么"和"如何检查"。
references/review-checklist.md 存放模块化评分标准。
指令定义检查流程和输出格式。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/skill-templates/reviewer.md (reported line 14)May include surrounding context.

md
# <Skill 名称> (Reviewer)

<!--
Reviewer 模式:分离"检查什么"和"如何检查"。
references/review-checklist.md 存放模块化评分标准。
指令定义检查流程和输出格式。

Hidden Instructions

High
Category
Prompt Injection
Confidence
78% confidence
Finding

This duplicate hidden-instruction finding points to the same underlying issue: concealed markdown comments carry behavior-shaping directives that can change agent execution and authority handling without obvious visibility to reviewers. In this skill context, that is more dangerous because the hidden text specifically instructs the system to trust loaded references over its existing safeguards or knowledge.

Content

Scanner excerpt · assets/skill-templates/tool-wrapper.md (reported line 13)May include surrounding context.

md
# <Skill 名称> (Tool Wrapper)

<!--
Tool Wrapper 模式:按需加载特定库/API 的上下文。
SKILL.md 监听关键词,从 references/ 目录动态加载文档,作为绝对真理应用。

Hidden Instructions

High
Category
Prompt Injection
Confidence
78% confidence
Finding

This duplicate hidden-instruction finding points to the same underlying issue: concealed markdown comments carry behavior-shaping directives that can change agent execution and authority handling without obvious visibility to reviewers. In this skill context, that is more dangerous because the hidden text specifically instructs the system to trust loaded references over its existing safeguards or knowledge.

Content

Scanner excerpt · assets/skill-templates/tool-wrapper.md (reported line 13)May include surrounding context.

md
# <Skill 名称> (Tool Wrapper)

<!--
Tool Wrapper 模式:按需加载特定库/API 的上下文。
SKILL.md 监听关键词,从 references/ 目录动态加载文档,作为绝对真理应用。

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · references/api-interfaces.md (reported line 23)May include surrounding context.

md
def onchainos_cmd(args: list[str], timeout: int = 30) -> dict | None:
    """Run onchainos CLI command, return parsed JSON."""
    env = os.environ.copy()
    env.setdefault("OKX_API_KEY", os.environ.get("OKX_API_KEY", ""))
    env.setdefault("OKX_SECRET_KEY", os.environ.get("OKX_SECRET_KEY", ""))
    env.setdefault("OKX_PASSPHRASE", os.environ.get("OKX_PASSPHRASE", ""))

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file appears to be the primary introduction for the skill, but all user-facing content is presented only in Chinese. That forces a specific language on users without opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The README instructs users to execute npx clawhub install okx-strategy-factory without pinning an exact package version. This creates a supply-chain risk because a future compromised or malicious release could be fetched and run implicitly at install time, which is especially sensitive for a skill that later handles deployment, trading workflows, and credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README describes deployment to a VPS and GitHub publication but does not prominently warn users that these actions can modify remote systems and publish artifacts publicly. In this skill's context, that omission is more dangerous because the pipeline coordinates autonomous agents across deployment and release stages, making accidental destructive changes or unintended public release more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

The prerequisite npx skills add okx/onchainos-skills references a remotely fetched package/toolchain without version pinning. Because npx can download and execute code, users may unknowingly run a changed or compromised version, increasing supply-chain exposure in a workflow tied to wallets, API keys, and live trading.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README lists OKX API keys, an agentic wallet with signing capability, and optional 1Password usage without an explicit warning about the sensitivity of these credentials or the financial authority they grant. In a live-trading skill, this materially increases risk because users may provide high-privilege secrets to an automation pipeline that can deploy, trade, and publish, amplifying the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to run npx clawhub install okx-strategy-factory without pinning a package version or integrity source. That can cause users to execute whatever version is current at install time, increasing supply-chain risk if the package is compromised, typo-squatted, or updated maliciously.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README describes an Infra agent that deploys to a VPS over SSH, manages pm2, performs health checks, and automatically rolls back, but it does not prominently warn that using the skill may modify remote systems and running services. Because this is a multi-agent automation workflow, users may underestimate that the agent can make live infrastructure changes, increasing the risk of unintended or over-broad actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The prerequisite npx skills add okx/onchainos-skills references a remotely resolved package/toolchain without version pinning. In a skill that later handles API keys, wallets, deployment, and publishing, unpinned bootstrap dependencies meaningfully expand supply-chain exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match common requests like strategy development, backtesting, deployment, or iteration, which increases the chance the skill activates in contexts where the user did not intend a high-impact trading or publishing workflow. Because this skill coordinates deployment and release-related actions, accidental invocation can escalate into unintended file modification, deployment, or live-trading preparation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description promotes deployment and live trading lifecycle support without an upfront warning that the skill may affect production systems, financial positions, wallets, VPS environments, or public releases. In the context of on-chain trading and deployment, omission of prominent warnings materially increases the risk that a user triggers actions with financial or operational consequences without appreciating the blast radius.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script's descriptive comments, usage text, examples, and later user-facing messages are written in Chinese, which imposes a specific language on users. The file does not offer an opt-in language choice or explain that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.