T09 · Insecure Skill Coding Practices
- Location
scripts/okx-kline.js:58- Finding
Unauthenticated plaintext transport between the client and configured proxy
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a small OKX market-data helper that fetches public candlestick data and does not show hidden persistence, credential use, or destructive behavior.
Install only if you are comfortable with the skill making live requests to OKX for market data. Avoid using it with untrusted http_proxy or https_proxy environment variables, especially for trading decisions, because a proxy could tamper with returned candle data.
scripts/okx-kline.js:58Unauthenticated plaintext transport between the client and configured proxy
Referenced artifact was not completely inspected
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条
Referenced artifact was not completely inspected
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条
Referenced artifact was not completely inspected
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条
Referenced artifact was not completely inspected
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条
Referenced artifact was not completely inspected
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条
Referenced artifact was not completely inspected
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条
This code performs an outbound HTTP(S) request to OKX using user-provided parameters and may also route traffic through a proxy from environment variables. Although the header comment shows usage and proxy support, it does not clearly warn the user that invoking the script sends request metadata to an external service.
No suspicious patterns detected.