Back to skill

Security audit

Crypto Kline BTC加密货币K线数据

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small OKX market-data helper that fetches public candlestick data and does not show hidden persistence, credential use, or destructive behavior.

Install only if you are comfortable with the skill making live requests to OKX for market data. Avoid using it with untrusted http_proxy or https_proxy environment variables, especially for trading decisions, because a proxy could tamper with returned candle data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/okx-kline.js:58
Finding

Unauthenticated plaintext transport between the client and configured proxy

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
node scripts/okx-kline.js BTC-USDT 1d 30 # BTC日线最近30条

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code performs an outbound HTTP(S) request to OKX using user-provided parameters and may also route traffic through a proxy from environment variables. Although the header comment shows usage and proxy support, it does not clearly warn the user that invoking the script sends request metadata to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.