T08 · Insecure Dependencies
- Location
scripts/alpaca_cli.py:32- Finding
Unpinned installation guidance for a security-sensitive trading dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Alpaca trading skill is mostly coherent, but it can place or cancel live financial orders with bypassable or missing confirmations.
Review before installing if you may connect live Alpaca credentials. Prefer paper trading, avoid using --force in live mode, confirm any generated order or cancel command yourself, secure ~/.openclaw/credentials/alpaca.json with restrictive permissions, and install alpaca-py only from a trusted, reviewed version.
scripts/alpaca_cli.py:32Unpinned installation guidance for a security-sensitive trading dependency
scripts/alpaca_cli.py:276Force option bypasses live-trading confirmations and multiple order safeguards
scripts/alpaca_cli.py:75Plaintext trading credential file is used without permission validation
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
### GET /v2/orders/{order_id}
Get order by ID.
### DELETE /v2/orders/{order_id}
Cancel order.
### DELETE /v2/orders
DELETE /v2/orders cancels all orders in an account, making it a highly destructive operation in a live-trading context. In an agent skill that may act on natural-language instructions, exposing bulk cancellation without strong confirmation and environment safeguards materially increases the risk of accidental or prompt-induced financial harm.
### DELETE /v2/orders/{order_id}
Cancel order.
### DELETE /v2/orders
Cancel all orders.
## Order Types
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
### POST /v2/watchlists/{watchlist_id}
Add symbol to watchlist.
### DELETE /v2/watchlists/{watchlist_id}
Delete watchlist.
## Rate Limits
The skill exposes sensitive capabilities including environment access for API keys, file writes for local persistence, and network access for trading/API calls, but it does not declare any explicit tool scope or permission boundaries. In a trading skill, this increases the chance of unintended credential use, unauthorized external requests, or state-changing actions being invoked without clear policy enforcement.
The description says to use the skill when a user asks about stock prices, wants to buy or sell securities, check portfolio, or manage trades, which is broad enough to activate trade-capable functionality from ambiguous financial queries. Because the skill can place real orders, overly permissive routing raises the risk of accidental invocation of high-impact actions in response to loosely related prompts.
The skill documents persistent watchlist and alert management features, and alerts are stored on disk, which introduces session persistence and retained state across runs. In a financial context, persistent state can be abused or become stale, causing unintended notifications, privacy leakage about user interests, or actions based on outdated assumptions if later automation consumes that state.
python3 scripts/alpaca_cli.py watchlist list
python3 scripts/alpaca_cli.py watchlist create "Tech Stocks" AAPL,MSFT,GOOGL
python3 scripts/alpaca_cli.py watchlist add WATCHLIST_ID NVDA
python3 scripts/alpaca_cli.py watchlist delete WATCHLIST_ID
This markdown file describes placing orders and canceling one or all orders, which can directly affect user assets and system state. The section provides endpoint mechanics but does not include any warning or caution about live trading risk, irreversible execution, or the need to verify whether the user is using paper versus live trading.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
if not api_key or not secret_key:
print("Error: Alpaca credentials not found.")
print("Set ALPACA_API_KEY and ALPACA_SECRET_KEY environment variables,")
print("or create ~/.openclaw/credentials/alpaca.json")
sys.exit(1)
return api_key, secret_key, paper
Cancelling all open orders is a destructive trading action that executes immediately when the user passes 'all', with no confirmation prompt or dry-run summary. In a trading skill context, accidental invocation or prompt-manipulated invocation could disrupt intended trades, cause missed executions, and create financial loss.
Deleting a watchlist is a destructive remote account action, but the function performs it immediately without warning or confirmation. While lower impact than order placement or cancellation, it can still remove user-curated data and be abused through accidental or manipulated tool use.
The clear action overwrites the entire local alerts file with an empty set without any confirmation, making accidental data loss easy. Although this affects local state rather than trading positions directly, it can silently remove monitoring important to the user's trading workflow.
The manifest describes using Alpaca for market data, trading, portfolio management, and account info, but the code also creates a separate local alerting subsystem backed by a file in ~/.openclaw/data and a check mode intended for scheduled execution. That is additional behavior not mentioned in the manifest and is not an obvious Alpaca API implementation detail.
The manifest lists market data, orders, positions, portfolio management, and account info, but does not mention creating, modifying, or deleting watchlists. Watchlist administration is a meaningful user-facing capability beyond the stated description.
No suspicious patterns detected.