T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unverified External Dependency Controls Financial Trading Operations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s stock-trading purpose is clear, but it asks users to rely on an unverified trading program and a public default API key for real financial actions.
Review before installing. Only use this skill if you trust and can verify the external trading assistant, replace the default API key with a unique strong secret, keep the API bound to localhost, and require manual confirmation in a trusted trading interface before any order or cancellation is sent.
SKILL.md:12Unverified External Dependency Controls Financial Trading Operations
SKILL.md:33Predictable Hardcoded API Key Protects Sensitive Trading Endpoints
SKILL.md:33Trading Credentials and Financial Operations Are Transmitted over Plaintext HTTP
The skill supports account and position queries that reveal sensitive financial information such as holdings, balances, and profit/loss, but it provides no privacy warning or consent step. Exposure of this data can leak highly sensitive personal financial information to unintended recipients or logs.
The manifest description is entirely in Chinese, and the file does not indicate that the skill is region-specific or provide users with a language/locale choice. This can constitute a language policy violation when a specific language is effectively forced without opt-in or justification.
The skill supports account and position queries that reveal sensitive financial information such as holdings, balances, and profit/loss, but it provides no privacy warning or consent step. Exposure of this data can leak highly sensitive personal financial information to unintended recipients or logs.
The operational instructions and activation examples are all written in Chinese, with no indication that users can choose another language or that the locale limitation is intentional. Forcing a single language in user-facing instructions without opt-in or documented justification matches the policy violation criteria.
The skill transmits trade instructions and sensitive financial context over an HTTP API using a hardcoded default API key in request headers. Even though the endpoint is localhost, local malware, other local users, proxy/middleware interception, or accidental reuse of the documented key could result in unauthorized trading or data access.
# 限价买入
curl -X POST "http://localhost:8888/api/order" \
-H "Content-Type: application/json" \
-H "X-API-Key: test-api-key-12345" -H "X-Channel: openclaw-skill" \
-d '{"action":"buy","symbol":"600519","price":1800.00,"volume":100}'
Detected: suspicious.exposed_secret_literal