Back to skill

Security audit

TradingFlow — AI-Powered Intent Trading Across Crypto, Stocks & More

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed crypto-trading automation tool, but it can store signing keys and run autonomous bots, so users should review it carefully before installing.

Install only if you intentionally want an agent to manage TradingFlow strategies and potentially automate crypto trades. Use a dedicated low-balance vault, keep permissions to swap-only at first, set conservative spending limits, avoid storing private keys unless you accept autonomous execution risk, require signed webhooks, pin dependencies, and keep TRADINGCLAW_BASE_URL on the official HTTPS API endpoint.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/webhook-triggers.md:10
Finding

Unauthenticated Webhooks Can Trigger Autonomous Trading Logic

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/create-strategy.sh:11
Finding

Configurable API Origin Can Exfiltrate the TradingFlow Bearer Credential

Content
View full analysis
[language] [chain] "; exit 1; } curl -s -X POST "$TRADINGCLAW_BASE_URL/strategy" \ -H "Authorization: Bearer $TRADINGCLAW_API_KEY" \ -H "Content-Type: application/json" \ -d "$(jq -n \ --arg name "$NAME" \ --arg description "Created via OpenClaw" \ --arg content "$CONTENT" \ --arg language "$LANGUAGE" \ --arg chain "$CHAIN" \ '{name: $name, description: $description, content: $content, language: $language, chain: $chain}' )" | jq . ``` From `scripts/deploy-process.sh`: ```bash : "${TRADINGCLAW_API_KEY:?Must be set}" : "${TRADINGCLAW_BASE_URL:?Must be set}" [ -z "$STRATEGY_ID" ] && { echo "Usage: deploy-process.sh [process-name]"; exit 1; } PARAMS=$(jq -n --arg sid "$STRATEGY_ID" '{strategyId: $sid}') [ -n "$PROCESS_NAME" ] && PARAMS=$(echo "$PARAMS" | jq --arg n "$PROCESS_NAME" '. + {name: $n}') echo "▶ Deploying strategy $STRATEGY_ID via deploy_process tool..." echo " (This creates the TFP, deploys code, and auto-starts)" curl -s -X POST "$TRADINGCLAW_BASE_URL/claw/execute" \ -H "Authorization: Bearer $TRADINGCLAW_API_KEY" \ -H "Content-Type: application/json" \ -d "$(jq -n --arg tool "deploy_process" --argjson params "$PARAMS" '{tool: $tool, params: $params}')" | jq . ``` ### Technical Analysis Both scripts trust `TRADINGCLAW_BASE_URL` without validating its scheme, hostname, port, or path. They then attach `TRADINGCLAW_API_KEY` as a bearer credential to that destination. Consequently, environment-variable poisoning, a malic ...[truncated 2526 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/strategy-format.md:86
Finding

Unpinned Dependencies Are Installed as Part of Automatically Started Strategy Deployments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description is much broader than what this code chunk actually implements. The code only creates a strategy record through a TradingClaw/TradingFlow-style API. While 'create trading strategies' is consistent with part of the declared purpose, the rest of the declared capabilities—automated bot deployment, vault control, DeFi position management, balance checking, and on-chain interactions across multiple chains—are not present in this code. This is a material description-to-behavior mismatch because the actual primary behavior is limited to remote strategy creation.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill includes a mechanism for deployed processes to retrieve stored secrets at runtime via a tokenized secret endpoint. In the context of a platform that can generate and run user strategies, this creates a high-value credential-access path: compromised strategy code, prompt-induced code generation, or operator abuse could read sensitive API keys or private keys and use them for unauthorized trading or fund movement.

Content

Scanner excerpt · SKILL.md (reported line 349)May include surrounding context.

md
Categories: `secret` (write-only, encrypted) | `env_var` (readable)

**How TFP processes access secrets at runtime:**

- `env_var` entries are auto-injected as environment variables into the TFP process.
- `secret` entries are NOT injected as env vars. Instead, the TFP receives a `TFP_SECRET_TOKEN` (JWT) and `TFP_SECRETS_ENDPOINT` in its environment.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation first assures users that sensitive fund operations require explicit browser-based approval, but later introduces automated direct signing using a stored Oracle private key. This inconsistency can mislead users about the true trust model and enables unattended fund-moving actions if the TFP process, secret access path, or strategy logic is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Documenting internal cluster-control and recovery endpoints in a user-facing skill materially widens the perceived operational scope of the agent. Even if some endpoints are unauthenticated or 'internal', exposing them can encourage misuse, infrastructure probing, service disruption, or invocation of operational controls unrelated to trading.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents extensive shell-based and network-capable operations but does not declare any tool scope restrictions such as allowed-tools or permissions. That increases the blast radius because an agent may enable broader execution than necessary, including arbitrary curl-based API calls and transaction-building flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases are very broad and include generic terms like 'bot', 'deposit', 'help me trade', and 'show my assets', which can cause the skill to trigger in contexts broader than intended. Overbroad invocation increases the chance that an agent routes unrelated user requests into a high-risk financial automation skill with network access and transaction capabilities.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

bash
# Create strategy (language: "markdown" for natural-language descriptions, "python"/"javascript"/"typescript" for code)
curl -X POST $TRADINGCLAW_BASE_URL/strategy \
  -H "Authorization: Bearer $TRADINGCLAW_API_KEY" \
  -d '{"name":"BTC DCA","content":"# BTC DCA\n\nBuy $50 BTC every Monday...","language":"markdown","chain":"bsc"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 308)May include surrounding context.

bash
# The CORRECT way (via Agent tool) — creates + deploys + starts automatically:
curl -X POST $TRADINGCLAW_BASE_URL/claw/execute \
  -H "Authorization: Bearer $TRADINGCLAW_API_KEY" \
  -d '{"tool":"deploy_process","params":{"strategyId":"...","name":"btc-dca"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 371)May include surrounding context.

bash
# Check vault status
curl "$TRADINGCLAW_BASE_URL/vault/{chain}/status?address={walletAddr}" \
  -H "Authorization: Bearer $TRADINGCLAW_API_KEY"

# Get balances

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill exposes extra operators for social media access and notifications that are not central to the stated trading/vault-management purpose. Unnecessary operator surface expands opportunities for data exfiltration, spam, social-engineering workflows, or unintended outbound communications from deployed strategies.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 696)May include surrounding context.

bash
# 1. Get vault status to find the vault address
curl "$TRADINGCLAW_BASE_URL/vault/bsc/status?address=0xUserWallet" \
  -H "Authorization: Bearer $TRADINGCLAW_API_KEY"
# → {"data":{"chain":"bsc","address":"0xVaultAddr","exists":true,"isActive":true}}

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 901)May include surrounding context.

bash
# 1. Create strategy
curl -X POST $BASE/claw/execute -H "Authorization: Bearer $KEY" \
  -d '{"tool":"create_strategy","params":{"name":"BTC DCA","content":"...","language":"markdown","chain":"bsc"}}'

# 2. Create workflow

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1030)May include surrounding context.

bash
# Create workflow linked to a strategy
curl -X POST $TRADINGCLAW_BASE_URL/claw/execute \
  -H "Authorization: Bearer $TRADINGCLAW_API_KEY" \
  -d '{"tool":"create_workflow","params":{"strategyId":"...","name":"...","nodes":[...],"edges":[...]}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1432)May include surrounding context.

bash
# 1. Create strategy
STRAT_ID=$(curl -sX POST $TRADINGCLAW_BASE_URL/claw/execute \
  -H "Authorization: Bearer $KEY" \
  -d '{"tool":"create_strategy","params":{"name":"Alpha Signal Monitor","content":"# Alpha Signal Monitor\n\nMonitors three high-impact sources...","language":"markdown"}}' \
  | jq -r '.data._id')

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1438)May include surrounding context.

md
| jq -r '.data._id')

# 2. Create visual workflow
curl -X POST $TRADINGCLAW_BASE_URL/claw/execute \
  -H "Authorization: Bearer $KEY" \
  -d "{\"tool\":\"create_workflow\",\"params\":{\"strategyId\":\"$STRAT_ID\",\"name\":\"Alpha Signal Monitor\",\"nodes\":[...],\"edges\":[...]}}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
# TradingFlow API Reference

Base URL: `$TRADINGCLAW_BASE_URL` (default: `https://api.tradingflow.fun/api/v1`)

Auth header: `Authorization: Bearer $TRADINGCLAW_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
# TradingFlow API Reference

Base URL: `$TRADINGCLAW_BASE_URL` (default: `https://api.tradingflow.fun/api/v1`)

Auth header: `Authorization: Bearer $TRADINGCLAW_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 3)May include surrounding context.

md
# TradingFlow API Reference

Base URL: `$TRADINGCLAW_BASE_URL` (default: `https://api.tradingflow.fun/api/v1`)

Auth header: `Authorization: Bearer $TRADINGCLAW_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/webhook-triggers.md (reported line 31)May include surrounding context.

md
# TradingFlow API Reference

Base URL: `$TRADINGCLAW_BASE_URL` (default: `https://api.tradingflow.fun/api/v1`)

Auth header: `Authorization: Bearer $TRADINGCLAW_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 108)May include surrounding context.

bash
# This is the CORRECT way for agents to create+deploy+start a process:
curl -X POST $TRADINGCLAW_BASE_URL/claw/execute \
  -H "Authorization: Bearer $TRADINGCLAW_API_KEY" \
  -d '{"tool":"deploy_process","params":{"strategyId":"...","name":"btc-dca-bot"}}'
# → Automatically: creates TFP → deploys code from strategy.generatedCode → starts process

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The reference explicitly documents a plaintext retrieval path for env vars via /user-secrets/:name/value and notes env vars are stored readable, but does not prominently warn that agents should never place sensitive credentials there. In this skill context, where bots and strategies commonly need exchange keys and wallet-related settings, that ambiguity can lead to secret material being stored in a retrievable form and later exfiltrated.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API reference exposes account-management capabilities far beyond the skill's stated purpose of trading strategies, bots, and vault operations, including profile updates, identity binding, invitation handling, and auth flows. In an agent setting, over-broad documented capabilities expand the attack surface and increase the chance the agent is induced to perform unrelated but sensitive account actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/vault-operations.md (reported line 33)May include surrounding context.

bash
# Build the create-vault transaction
curl -X POST $BASE/vault/bsc/create \
  -H "Authorization: Bearer $KEY" \
  -d '{"investor":"0xYourWallet","oracle":"0xOracleAddr"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/vault-operations.md (reported line 71)May include surrounding context.

bash
# Query
curl "$BASE/vault/bsc/0xVault/agent-permissions/0xAgent" \
  -H "Authorization: Bearer $KEY"
# → {"data":{"permissions":3}}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The automated mode instructs users to store a private key and let the TFP process submit transactions autonomously, which removes per-transaction user approval and creates a single high-value secret whose compromise enables direct on-chain actions. Although the document mentions limits and role restrictions, it does not give a prominent warning that enabling ORACLE_ROLE plus stored key material fundamentally shifts trust to the platform/agent runtime and can still permit unauthorized or overly broad trading, borrowing, or withdrawals within configured permissions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.