T09 · Insecure Skill Coding Practices
- Location
references/webhook-triggers.md:10- Finding
Unauthenticated Webhooks Can Trigger Autonomous Trading Logic
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed crypto-trading automation tool, but it can store signing keys and run autonomous bots, so users should review it carefully before installing.
Install only if you intentionally want an agent to manage TradingFlow strategies and potentially automate crypto trades. Use a dedicated low-balance vault, keep permissions to swap-only at first, set conservative spending limits, avoid storing private keys unless you accept autonomous execution risk, require signed webhooks, pin dependencies, and keep TRADINGCLAW_BASE_URL on the official HTTPS API endpoint.
references/webhook-triggers.md:10Unauthenticated Webhooks Can Trigger Autonomous Trading Logic
scripts/create-strategy.sh:11Configurable API Origin Can Exfiltrate the TradingFlow Bearer Credential
references/strategy-format.md:86Unpinned Dependencies Are Installed as Part of Automatically Started Strategy Deployments
The description is much broader than what this code chunk actually implements. The code only creates a strategy record through a TradingClaw/TradingFlow-style API. While 'create trading strategies' is consistent with part of the declared purpose, the rest of the declared capabilities—automated bot deployment, vault control, DeFi position management, balance checking, and on-chain interactions across multiple chains—are not present in this code. This is a material description-to-behavior mismatch because the actual primary behavior is limited to remote strategy creation.
The skill includes a mechanism for deployed processes to retrieve stored secrets at runtime via a tokenized secret endpoint. In the context of a platform that can generate and run user strategies, this creates a high-value credential-access path: compromised strategy code, prompt-induced code generation, or operator abuse could read sensitive API keys or private keys and use them for unauthorized trading or fund movement.
Categories: `secret` (write-only, encrypted) | `env_var` (readable)
**How TFP processes access secrets at runtime:**
- `env_var` entries are auto-injected as environment variables into the TFP process.
- `secret` entries are NOT injected as env vars. Instead, the TFP receives a `TFP_SECRET_TOKEN` (JWT) and `TFP_SECRETS_ENDPOINT` in its environment.
The documentation first assures users that sensitive fund operations require explicit browser-based approval, but later introduces automated direct signing using a stored Oracle private key. This inconsistency can mislead users about the true trust model and enables unattended fund-moving actions if the TFP process, secret access path, or strategy logic is compromised.
Documenting internal cluster-control and recovery endpoints in a user-facing skill materially widens the perceived operational scope of the agent. Even if some endpoints are unauthenticated or 'internal', exposing them can encourage misuse, infrastructure probing, service disruption, or invocation of operational controls unrelated to trading.
The skill documents extensive shell-based and network-capable operations but does not declare any tool scope restrictions such as allowed-tools or permissions. That increases the blast radius because an agent may enable broader execution than necessary, including arbitrary curl-based API calls and transaction-building flows.
The activation phrases are very broad and include generic terms like 'bot', 'deposit', 'help me trade', and 'show my assets', which can cause the skill to trigger in contexts broader than intended. Overbroad invocation increases the chance that an agent routes unrelated user requests into a high-risk financial automation skill with network access and transaction capabilities.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Create strategy (language: "markdown" for natural-language descriptions, "python"/"javascript"/"typescript" for code)
curl -X POST $TRADINGCLAW_BASE_URL/strategy \
-H "Authorization: Bearer $TRADINGCLAW_API_KEY" \
-d '{"name":"BTC DCA","content":"# BTC DCA\n\nBuy $50 BTC every Monday...","language":"markdown","chain":"bsc"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# The CORRECT way (via Agent tool) — creates + deploys + starts automatically:
curl -X POST $TRADINGCLAW_BASE_URL/claw/execute \
-H "Authorization: Bearer $TRADINGCLAW_API_KEY" \
-d '{"tool":"deploy_process","params":{"strategyId":"...","name":"btc-dca"}}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Check vault status
curl "$TRADINGCLAW_BASE_URL/vault/{chain}/status?address={walletAddr}" \
-H "Authorization: Bearer $TRADINGCLAW_API_KEY"
# Get balances
The skill exposes extra operators for social media access and notifications that are not central to the stated trading/vault-management purpose. Unnecessary operator surface expands opportunities for data exfiltration, spam, social-engineering workflows, or unintended outbound communications from deployed strategies.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 1. Get vault status to find the vault address
curl "$TRADINGCLAW_BASE_URL/vault/bsc/status?address=0xUserWallet" \
-H "Authorization: Bearer $TRADINGCLAW_API_KEY"
# → {"data":{"chain":"bsc","address":"0xVaultAddr","exists":true,"isActive":true}}
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 1. Create strategy
curl -X POST $BASE/claw/execute -H "Authorization: Bearer $KEY" \
-d '{"tool":"create_strategy","params":{"name":"BTC DCA","content":"...","language":"markdown","chain":"bsc"}}'
# 2. Create workflow
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Create workflow linked to a strategy
curl -X POST $TRADINGCLAW_BASE_URL/claw/execute \
-H "Authorization: Bearer $TRADINGCLAW_API_KEY" \
-d '{"tool":"create_workflow","params":{"strategyId":"...","name":"...","nodes":[...],"edges":[...]}}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 1. Create strategy
STRAT_ID=$(curl -sX POST $TRADINGCLAW_BASE_URL/claw/execute \
-H "Authorization: Bearer $KEY" \
-d '{"tool":"create_strategy","params":{"name":"Alpha Signal Monitor","content":"# Alpha Signal Monitor\n\nMonitors three high-impact sources...","language":"markdown"}}' \
| jq -r '.data._id')
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| jq -r '.data._id')
# 2. Create visual workflow
curl -X POST $TRADINGCLAW_BASE_URL/claw/execute \
-H "Authorization: Bearer $KEY" \
-d "{\"tool\":\"create_workflow\",\"params\":{\"strategyId\":\"$STRAT_ID\",\"name\":\"Alpha Signal Monitor\",\"nodes\":[...],\"edges\":[...]}}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# TradingFlow API Reference
Base URL: `$TRADINGCLAW_BASE_URL` (default: `https://api.tradingflow.fun/api/v1`)
Auth header: `Authorization: Bearer $TRADINGCLAW_API_KEY`
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# TradingFlow API Reference
Base URL: `$TRADINGCLAW_BASE_URL` (default: `https://api.tradingflow.fun/api/v1`)
Auth header: `Authorization: Bearer $TRADINGCLAW_API_KEY`
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# TradingFlow API Reference
Base URL: `$TRADINGCLAW_BASE_URL` (default: `https://api.tradingflow.fun/api/v1`)
Auth header: `Authorization: Bearer $TRADINGCLAW_API_KEY`
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# TradingFlow API Reference
Base URL: `$TRADINGCLAW_BASE_URL` (default: `https://api.tradingflow.fun/api/v1`)
Auth header: `Authorization: Bearer $TRADINGCLAW_API_KEY`
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# This is the CORRECT way for agents to create+deploy+start a process:
curl -X POST $TRADINGCLAW_BASE_URL/claw/execute \
-H "Authorization: Bearer $TRADINGCLAW_API_KEY" \
-d '{"tool":"deploy_process","params":{"strategyId":"...","name":"btc-dca-bot"}}'
# → Automatically: creates TFP → deploys code from strategy.generatedCode → starts process
The reference explicitly documents a plaintext retrieval path for env vars via /user-secrets/:name/value and notes env vars are stored readable, but does not prominently warn that agents should never place sensitive credentials there. In this skill context, where bots and strategies commonly need exchange keys and wallet-related settings, that ambiguity can lead to secret material being stored in a retrievable form and later exfiltrated.
The API reference exposes account-management capabilities far beyond the skill's stated purpose of trading strategies, bots, and vault operations, including profile updates, identity binding, invitation handling, and auth flows. In an agent setting, over-broad documented capabilities expand the attack surface and increase the chance the agent is induced to perform unrelated but sensitive account actions.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Build the create-vault transaction
curl -X POST $BASE/vault/bsc/create \
-H "Authorization: Bearer $KEY" \
-d '{"investor":"0xYourWallet","oracle":"0xOracleAddr"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Query
curl "$BASE/vault/bsc/0xVault/agent-permissions/0xAgent" \
-H "Authorization: Bearer $KEY"
# → {"data":{"permissions":3}}
The automated mode instructs users to store a private key and let the TFP process submit transactions autonomously, which removes per-transaction user approval and creates a single high-value secret whose compromise enables direct on-chain actions. Although the document mentions limits and role restrictions, it does not give a prominent warning that enabling ORACLE_ROLE plus stored key material fundamentally shifts trust to the platform/agent runtime and can still permit unauthorized or overly broad trading, borrowing, or withdrawals within configured permissions.
No suspicious patterns detected.