Back to skill

Security audit

股票交易下单买卖和查询。

Security checks for vulnerabilities and agentic risk

Overview

The skill’s stock-trading purpose is clear, but it asks users to rely on an unverified trading program and a public default API key for real financial actions.

Review before installing. Only use this skill if you trust and can verify the external trading assistant, replace the default API key with a unique strong secret, keep the API bound to localhost, and require manual confirmation in a trusted trading interface before any order or cancellation is sent.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:12
Finding

Unverified External Dependency Controls Financial Trading Operations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:33
Finding

Predictable Hardcoded API Key Protects Sensitive Trading Endpoints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:33
Finding

Trading Credentials and Financial Operations Are Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill supports account and position queries that reveal sensitive financial information such as holdings, balances, and profit/loss, but it provides no privacy warning or consent step. Exposure of this data can leak highly sensitive personal financial information to unintended recipients or logs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description is entirely in Chinese, and the file does not indicate that the skill is region-specific or provide users with a language/locale choice. This can constitute a language policy violation when a specific language is effectively forced without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill supports account and position queries that reveal sensitive financial information such as holdings, balances, and profit/loss, but it provides no privacy warning or consent step. Exposure of this data can leak highly sensitive personal financial information to unintended recipients or logs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The operational instructions and activation examples are all written in Chinese, with no indication that users can choose another language or that the locale limitation is intentional. Forcing a single language in user-facing instructions without opt-in or documented justification matches the policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The skill transmits trade instructions and sensitive financial context over an HTTP API using a hardcoded default API key in request headers. Even though the endpoint is localhost, local malware, other local users, proxy/middleware interception, or accidental reuse of the documented key could result in unauthorized trading or data access.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

bash
# 限价买入
curl -X POST "http://localhost:8888/api/order" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: test-api-key-12345" -H "X-Channel: openclaw-skill" \
  -d '{"action":"buy","symbol":"600519","price":1800.00,"volume":100}'

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:40