Back to skill

Security audit

Bybit Exchange AI Trading Skill

Security checks for vulnerabilities and agentic risk

Overview

This Bybit trading skill is mostly aligned with trading, but it grants real-money trading authority while automatically replacing its own files from mutable remote sources and has some under-scoped financial workflows.

Install only if you are comfortable with a trading assistant that can place real orders and persist OAuth/API credentials. Use a dedicated Bybit subaccount with limited balance, Read+Trade only, no Withdraw permission, preferably Testnet first. Review or disable the auto-update/module-fetch behavior before using Mainnet, and require separate confirmations for transfers, bot creation, and any account-admin changes.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
- Save content to temp file, then compute SHA256: shasum -a 256 <temp_file> | awk '{print $1}' - Compare with manifest checksum (strip "sha256:" prefix) - If mismatch: ABORT entire update. - If file extension is `.js` AND the local file already exists at SKILL_DIR/<file>: → Show to user: "⚠️ Code module update: <file> (LOCAL_VERSION → manifest.version). Allow? [Y/n]" → If user declines: skip this file, continue with remaining files - If match: save to SKILL_DIR/.skill ...[truncated 3886 chars]:19
Finding

Automatic Retrieval and Installation of Mutable Remote Skill Payloads

Content
View full analysis
LOCAL_VERSION: a. For each file in manifest.files: - Download: curl -sf -H "User-Agent: bybit-skill/1.5.8" https://raw.githubusercontent.com/bybit-exchange/skills/main/ - Save content to temp file, then compute SHA256: shasum -a 256 | awk '{print $1}' - Compare with manifest checksum (strip "sha256:" prefix) - If mismatch: ABORT entire update. - If file extension is `.js` AND the local file already exists at SKILL_DIR/: → Show to user: "⚠️ Code module update: (LOCAL_VERSION → manifest.version). Allow? [Y/n]" → If user declines: skip this file, continue with remaining files - If match: save to SKILL_DIR/.skill-update-tmp/ b. ALL files verified → move from temp to SKILL_DIR: - For each file: mkdir -p parent dir, then mv .skill-update-tmp/ SKILL_DIR/ - rm -rf SKILL_DIR/.skill-update-tmp/ ``` ```text ### How to load a module 1. Identify which module(s) the user's request needs from the table below 2. If the module has NOT been loaded in this session: a. Ensure manifest is available: - If cached from Auto Update: reuse it - Otherwise: MANIFEST = curl -sf -H "User-Agent: bybit-skill/1.5.8" https://api.bybit.com/skill ...[truncated 3205 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
modules/oauth.md:11
Finding

Contradictory SHA-256 Pins Make OAuth Helper Verification Nondeterministic

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
modules/oauth.md:139
Finding

OAuth Authorization Code Is Passed Through Process Command-Line Arguments

Content
View full analysis
/modules/oauth.js --manual-code "" --init-file "" --env ``` ```javascript function parseArgs() { const args = { port: 9876, output: getDefaultOutputPath(), env: "unify-test-3", exchange: null, subMemberId: null, isCreate: false, headless: false, manualCode: null, initFile: null }; for (let i = 2; i < process.argv.length; i++) { // ... } else if (process.argv[i] === "--manual-code" && process.argv[i + 1]) { args.manualCode = process.argv[++i]; } else if (process.argv[i] === "--init-file" && process.argv[i + 1]) { args.initFile = process.argv[++i]; } } return args; } ``` This behavior conflicts with the module’s own later security instruction: ```text Do NOT write raw token values, `code`, or `code_verifier` inline in shell commands. ``` ### Technical Analysis Command-line arguments are not an appropriate channel for OAuth authorization secrets. Depending on the operating system and execution environment, process arguments may be exposed through: - Process listings and process-monitoring tools. - Agent tool-call logs and execution telemetry. - Debugging or observability systems. - Shell history when a human executes the generated command. - Audit logs or wrapper scripts that record invoked commands. The OAuth code is short-lived and PKCE-protected, which reduces standalone exploitability. However, the same process also receives the path to the mode-0600 initialization file containing the PKCE verifier. An attacker operating with the same local user privileges, or an overprivileged logging system, may obtain both the command-line code and the initialization ...[truncated 1762 chars]
Remediation
View remediation
` argument. 2. Accept authorization codes through standard input, preferably with terminal echo disabled for interactive use. 3. Alternatively, read the code from a mode-0600 temporary file whose path—not content—is supplied to the process. 4. Use a structured process-spawn API without a shell rather than constructing a command string. 5. Never include raw authorization codes in Agent tool-call text, shell history, debug output, or telemetry. 6. Redact OAuth codes, access tokens, refresh tokens, and PKCE verifiers in all logs. 7. Delete the callback file and initialization file immediately after successful exchange or terminal failure. 8. Keep the existing restrictive file modes and verify ownership before reading credential or PKCE files. 9. Add tests confirming that process arguments and standard output never contain authorization codes or token values. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
modules/trading-bot.md:101
Finding

Bot Launch Workflow Can Automatically Transfer Funds Without Specific Transaction Confirmation

Content
View full analysis
", "coin": "USDT", "amount": "", "fromAccountType": "UNIFIED", "toAccountType": "FUND" } If UNIFIED is also insufficient → inform user to deposit and stop. ``` The automatic transfer conflicts with the global authorization boundary: ```text One CONFIRM = one operation: Each CONFIRM authorizes only the single operation (or single batch) shown in the immediately preceding confirmation card. A new operation requires a new card and a new CONFIRM. ``` It also conflicts with the module’s own safety rule: ```text Any create / close / transfer operation must first present the plan or describe the action, then wait for the user to explicitly reply "confirm" before executing. Until the user says "confirm", absolutely no write API calls. ``` ### Technical Analysis The sample confirmation describes launching a bot and the proposed investment, but it does not disclose that a separate internal transfer may occur from the Unified account to the Funding account. Afte ...[truncated 2056 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (71)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 66)May include surrounding context.

OpenClaw — use .env file:

bash
# ~/.openclaw/.env
BYBIT_API_KEY=your_api_key
BYBIT_API_SECRET=your_secret_key
BYBIT_ENV=mainnet

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README tells users that cloud AI platforms may collect API credentials interactively and retain them in session memory, while later claiming secrets never leave the user's device. This contradiction can mislead users into disclosing sensitive trading credentials to hosted assistants or providers under a false assumption of local-only handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README advises users of cloud AI platforms to provide API credentials interactively, but does not include a clear privacy and custody warning about sharing secrets with hosted third-party assistants. In this context, those credentials can authorize real trades, so disclosure to a cloud model or platform materially increases account compromise and unauthorized trading risk.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

A self-update mechanism that changes skill files at session start is a form of externally driven self-modification. In a trading skill, this is particularly dangerous because updated logic may change execution behavior, bypass confirmations, or exfiltrate credentials/accounts if the update source is compromised.

Content

Scanner excerpt · README.md (reported line 93)May include surrounding context.

md
## Auto Update

The skill includes a self-update mechanism. At session start, it checks the `VERSION` file on GitHub. If a newer version is available, it downloads updated files listed in `MANIFEST` — keeping users on the latest version automatically.

## License

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The manifest describes a trading skill, but the body also implements OAuth bootstrap, local callback handling, credential-file persistence, account-selection flows, and self-updating code/module retrieval. This description-behavior gap can mislead users and host agents about the real trust boundary, especially since the extra behaviors involve secrets and local system state.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: bybit-trading
description: Bybit AI Trading Skill — Trade on Bybit using natural language. Covers spot, derivatives, earn, and more. Works with Claude, ChatGPT, OpenClaw, and any AI assistant.
metadata:
  version: 1.5.8  # Modular Architecture + Security Baseline
  author: Bybit
  updated: 2026-08-07
license: MIT
---

# Bybit Trading Skill

Trade on Bybit using natural language. Supports spot, linear perpetuals (USDT/USDC), inverse contracts, options, and earn products.

### Rule Priority

When rules in this skill conflict, follow this order: **Safety > User Responsiveness > Convenience**. For example, never skip confirmation to be faster; never block the user's first request to run an auto-update check.

### Auto Update (MUST follow at session start)

This skill supports

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

Self-modification is one of the clearest risks in this file: the agent is instructed to alter its own local skill files based on remote content. This undermines static review, allows post-deployment behavior drift, and creates a strong avenue for supply-chain compromise.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

Auto Update (MUST follow at session start)

This skill supports self-update with integrity verification. At the start of each new session, launch the update check as a background sub-agent so it never blocks the user's first request:

text
FOREGROUND (main agent — immediate):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
(returns JSON: {"version":"x.y.z", "files":{"SKILL.md":"sha256:...","modules/market.md":"sha256:...",...}})

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
(returns JSON: {"version":"x.y.z", "files":{"SKILL.md":"sha256:...","modules/market.md":"sha256:...",...}})

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The skill instructs use of filesystem-mutating shell commands, including rm -rf, during the self-update process. Although aimed at a temp directory, destructive shell patterns inside agent instructions raise the risk of tool misuse, path handling errors, or exploitation if directory resolution is flawed elsewhere in the flow.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
- If match: save to SKILL_DIR/.skill-update-tmp/<file>
   b. ALL files verified → move from temp to SKILL_DIR:
      - For each file: mkdir -p parent dir, then mv .skill-update-tmp/<file> SKILL_DIR/<file>
      - rm -rf SKILL_DIR/.skill-update-tmp/
   c. return {status: "updated", from: LOCAL_VERSION, to: manifest.version}
   If manifest.version == LOCAL_VERSION:
   d. return {status: "current"}

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
modules/oauth.md` and execute its **Bootstrap** section. The OAuth executable (`modules/oauth.js`) is NOT delivered by auto-update — it is lazy-fetched from raw

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 752)May include surrounding context.

md
modules/oauth.md` and execute its **Bootstrap** section. The OAuth executable (`modules/oauth.js`) is NOT delivered by auto-update — it is lazy-fetched from raw

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

md
, private wealth, investment plan, fund management, asset manager | **earn** | `modules/earn.md` | account |

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The skill is designed to access credentials from env vars, .env files, OAuth credential files, and local key paths. Even though it discusses safety practices, it normalizes direct agent interaction with high-value trading secrets, which can lead to credential disclosure, misuse, or unintended persistence if the host environment is weak.

Content

Scanner excerpt · SKILL.md (reported line 630)May include surrounding context.

md
| AI Tool Type | Key Location | Risk Level | Recommendation |
|-------------|-------------|------------|----------------|
| **Local CLI** (Claude Code, Cursor) | Key stays on your machine (env vars) | Low | Safe for trading |
| **Self-hosted OpenClaw** | Key stays on your machine (.env file) | Low | Safe for trading |
| **Cloud AI** (hosted OpenClaw, Claude.ai, ChatGPT, Gemini) | Key is sent to AI provider's servers | **Medium** | Use sub-account + Read+Trade only, no Withdraw |
| **Unknown AI tools** | Key destination unclear | **High** | Use Testnet only, or avoid providing Key |

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented ability to enumerate sub-account API keys is highly sensitive and not justified by a normal trading skill. Exposure of key inventory and related metadata can materially aid privilege mapping, account reconnaissance, and downstream compromise, especially if an agent can retrieve or reason over multi-account administrative information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The institutional loan UID association endpoint allows binding or unbinding UIDs, which changes account relationships rather than executing trades. That capability is highly sensitive and unjustified in a trading assistant, so if the agent is induced to call it, it could alter account linkage or control boundaries with significant account-management consequences.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Broker rate-limit query and set endpoints provide administrative control over API throughput, which is not necessary for ordinary user trading flows. In an agent context, exposing these controls could let prompts trigger operational changes that disrupt safeguards, enable abuse, or interfere with other broker-managed accounts.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · modules/card.md (reported line 49)May include surrounding context.

md
> `statusCode` 用于请求过滤,`tradeStatus` 反映交易在卡网络中的进度,`status` 反映 Bybit 系统内部的订单处理状态。两个响应字段可能同时出现在同一条记录中。

**Response display rules:**
- `uid`: **隐藏,不展示给用户** — 内部标识,存在身份关联风险
- `pan6`: **隐藏,不展示给用户** — 卡 BIN 号段暴露发卡行信息,用户辨认卡片仅需 `pan4`(尾号)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

md
| Hold-to-Earn | `/v5/earn/hold-to-earn/product` | GET | status (`Online` only earns yield) |
| PWM | `/v5/earn/pwm/investment-plan/all` | GET | planId, planName, status, currentAssetUsd, accumulateYieldUsd |

> **Display rules**: Skip categories that return empty lists. For OnChain `Processing` entries on testnet, note they are demo data. Convert all `E8` fields before displaying. Group results by category with a summary header per section.

---

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · modules/earn.md (reported line 63)May include surrounding context.

md
| Hold-to-Earn | `/v5/earn/hold-to-earn/product` | GET | status (`Online` only earns yield) |
| PWM | `/v5/earn/pwm/investment-plan/all` | GET | planId, planName, status, currentAssetUsd, accumulateYieldUsd |

> **Display rules**: Skip categories that return empty lists. For OnChain `Processing` entries on testnet, note they are demo data. Convert all `E8` fields before displaying. Group results by category with a summary header per section.

---

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · modules/oauth.md (reported line 347)May include surrounding context.

md
| Hold-to-Earn | `/v5/earn/hold-to-earn/product` | GET | status (`Online` only earns yield) |
| PWM | `/v5/earn/pwm/investment-plan/all` | GET | planId, planName, status, currentAssetUsd, accumulateYieldUsd |

> **Display rules**: Skip categories that return empty lists. For OnChain `Processing` entries on testnet, note they are demo data. Convert all `E8` fields before displaying. Group results by category with a summary header per section.

---

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · modules/fiat.md (reported line 93)May include surrounding context.

md
| Endpoint | Path | Method | Required Params | Optional Params |
|----------|------|--------|----------------|-----------------|
| Send Chat Message | `/v5/p2p/order/message/send` | POST | message, contentType, orderId, msgUuid | — |
| Upload Chat File | `/v5/p2p/oss/upload_file` | POST | upload_file (multipart/form-data) | — |
| Get Chat Messages | `/v5/p2p/order/message/listpage` | POST | orderId | size, lastMsgId |

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · modules/fiat.md (reported line 94)May include surrounding context.

md
| Endpoint | Path | Method | Required Params | Optional Params |
|----------|------|--------|----------------|-----------------|
| Send Chat Message | `/v5/p2p/order/message/send` | POST | message, contentType, orderId, msgUuid | — |
| Upload Chat File | `/v5/p2p/oss/upload_file` | POST | upload_file (multipart/form-data) | — |
| Get Chat Messages | `/v5/p2p/order/message/listpage` | POST | orderId | size, lastMsgId |

#### Key Notes

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · modules/oauth.md (reported line 179)May include surrounding context.

This handles token exchange + saves credentials atomically. If it outputs needs_sub_account_selection: true, proceed to Step 6.

Alternative — manual curl (if module unavailable):

bash
export CRED_PATH=$(node -e "console.log(require('<skill_dir>/modules/oauth.js').getCredentialPath())")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · modules/oauth.md (reported line 362)May include surrounding context.

bash
REFRESH_TOKEN=$(node -e "const f=require('fs');const d=JSON.parse(f.readFileSync(process.env.CRED_PATH,'utf8'));process.stdout.write(d.refresh_token)")
curl -s -X POST '<base_url>/oauth/v1/public/refresh_token' \
  -d 'client_id=ai-agent' \
  -d "refresh_token=$REFRESH_TOKEN" \
  | node -e "

Static analysis

No suspicious patterns detected.