Back to skill

Security audit

claw-future

Security checks for vulnerabilities and agentic risk

Overview

This is a real futures-trading skill, but it needs review because its background daemon accepts unauthenticated local commands that can place, cancel, or schedule trades.

Install only in a trusted, isolated environment and test with a simulation account first. Do not run it on a shared machine until the daemon protocol requires authentication and mandatory account identity, and keep config.json, .management_secret, runtime files, and idempotency journals private. Treat condition orders and scheduled orders as real unattended trading automation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/daemon.py:777
Finding

Unauthenticated Loopback Interface Allows Unauthorized Trading Operations

Content
View full analysis
None: srv = socket.socket(socket.AF_INET, socket.SOCK_STREAM) srv.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1) srv.bind(("127.0.0.1", port)) srv.listen(5) srv.settimeout(1.0) logger.info("命令监听端口: %d", port) while self._running: try: conn, _ = srv.accept() except socket.timeout: continue threading.Thread(target=self._handle_conn, args=(conn,), daemon=True).start() srv.close() def _handle_conn(self, conn: socket.socket) -> None: try: data = b"" while True: chunk = conn.recv(4096) if not chunk: break data += chunk if b"\n" in data: break cmd = json.loads(data.decode()) resp = self._handle_cmd(cmd) conn.sendall((json.dumps(resp, ensure_ascii=False) + "\n").encode()) except Exception as e: try: conn.sendall((json.dumps({"ok": False, "error": str(e)}) + "\n").encode()) except Exception: pass finally: conn.close() ``` The account check is optional because it only rejects a request when an `account_id` is supplied and does not match: ```python def _handle_cmd(self, cmd: dict) -> dict: """Dispatch a command, journaling every state-changing request.""" target_account = str(cmd.get("account_id") or "").strip() if target_account and target_account != self.account_id: return { ...[truncated 4963 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (89)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

该代码块的主要功能是账户与运行环境管理,而不是面向用户的期货交易助理能力。虽然其中出现了“期货账户”“交易实例”等术语,说明它可能属于同一项目的底层组件,但此片段本身仅处理本地 JSON 配置、账户目录隔离、运行时文件路径、daemon 端口校验,以及防止重复启动同一真实账户实例的锁机制。它没有执行任何 CTP 交易、行情查询、报表生成或定时任务相关操作。因此,代码实际行为与声明描述的核心用途存在明显不一致,应判定为 mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是期货交易与行情/账户相关助手,而实际代码仅是一个通用审计日志模块。它创建本地 SQLite 数据库表,记录操作事件并做有限脱敏,主要用途是管理面审计与幂等去重。这与所宣称的交易执行、查询、预埋单、定时任务和日报生成功能在主目的和能力上都明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents an end-user trading skill that can monitor markets, place futures orders, manage conditional/scheduled orders, query account and market data, and generate reports. However, the supplied code chunk does not implement any of those trading, querying, scheduling, or reporting behaviors. Instead, it is purely an infrastructure/build script for compiling and packaging a native bridge library against the CTP SDK on Linux. While such a build script may support the overall project, the actual behavior of this chunk is materially different from the declared purpose of the skill itself. Therefore this code chunk does not accurately represent the declared trading-assistant functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description describes an end-user futures trading assistant skill with operational capabilities like placing orders, querying positions/funds/quotes, setting alerts and scheduled tasks, and generating reports. The supplied code chunk does none of that. It is purely a development/build script for macOS that compiles and packages a native CTP bridge library and related dylibs. This is a materially different primary purpose, not just a supporting implementation detail exposed to the user. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents an end-user trading assistant skill that should handle trading actions, position/fund/market queries, alerts, scheduled orders, and reporting. The supplied code chunk does none of those runtime trading-assistant behaviors. Instead, it is purely a development/build utility for Windows that prepares a CTP bridge DLL by invoking the Visual Studio compiler and managing SDK files. While the build script is related to CTP infrastructure, its primary purpose is materially different from the declared user-facing trading functionality, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a full-featured CTP futures trading assistant with order placement, position/funds/market queries, alerts, scheduled tasks, and daily reports. However, the supplied code chunk contains only a minimal package initializer comment and no executable logic. This is a material mismatch because the actual code does not implement the declared primary purpose or any of the listed capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad CTP futures trading assistant capable of real market monitoring, order handling, conditional orders, timed operations, and daily reporting. The supplied code is explicitly labeled as an in-memory demo data source for UI development only. Its behavior is limited to returning fabricated account/trade/quote data and simulating simple order submission and cancellation in local memory. While some surface functions overlap with the description (querying funds/positions/orders/trades/quotes and placing/canceling demo orders), key declared capabilities are absent: no real CTP connectivity, no conditional orders, no timed jobs, no login automation, and no settlement/report generation. This is a material description-behavior mismatch because the implementation is a mock/demo backend with narrower and different purpose than the declared production trading assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

整体上,代码确实覆盖了声明中的一部分核心交易能力:期货账户查询、行情获取、下单与撤单,且明确面向 CTP/ClawTrader 账户场景,因此并非完全无关。但声明强调的几个重要能力——预埋条件单、价格预警、定时任务/定时委托/定时登录、收盘日报——在该代码片段中都没有对应实现。相反,代码的主要内容是搭建一个单账户 MCP 服务接口,并提供基础交易查询与执行工具。虽然代码多出的认证和服务端封装可视为支撑性实现细节,不一定单独构成问题,但缺失了声明中多项关键功能,说明描述比实际能力更宽,存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a user-facing futures trading assistant for CTP operations such as placing trades, monitoring markets, setting conditional/scheduled orders, querying positions/funds/quotes, and generating daily reports. The supplied code chunk instead contains only tests for an idempotency subsystem. While idempotency could be a supporting implementation detail in a trading system, this chunk’s actual purpose is materially different from the declared skill behavior and does not implement the advertised trading capabilities. Therefore this code chunk does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a user-facing futures trading skill that can monitor markets, place and manage orders, schedule tasks, and produce reports. The supplied code does not implement those trading assistant functions. Instead, it is a test file focused on validating internal account-management and demo-order idempotency behavior. While these tests may support a broader trading system, this chunk’s actual purpose is materially different from the declared purpose, so it is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该代码与“期货交易助理”大方向一致,确实覆盖了 CTP 交易场景中的部分核心能力:账户状态、资金、持仓、委托、成交、行情、下单和撤单。但声明描述明显比实际代码更宽:代码中没有看到任何价格预警、条件单/预埋单、定时委托、定时任务、定时登录、收盘报告或日报相关实现。相反,实际实现更像一个基础 Web 前端交易面板,而不是完整的多功能交易助理。虽然存在登录、查询和下单等匹配项,但缺失的多个已声明核心能力属于实质性描述不符,因此应判定为 mismatch。

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
| IF / IH / IC / IM / TF / T / TS / SF / SM | CFFEX |
| rb / hc / cu / au / ag / al / zn / ni / sn / pb / ss / ao / br / bc | SHFE |
| c / cs / a / b / m / y / p / j / jm / l / v / pp / eg / pg / eb / rr / lh | DCE |
| CF / SR / TA / MA / OI / RM / ZC / FG / SA / PF / PX / UR / CJ / AP / RS | CZCE |
| sc / lu / nr | INE |
| si / lc | GFEX |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes unattended condition-triggered order placement that will automatically send real trades when a price threshold is met, even when the user is offline, but it does not present a prominent upfront risk warning. In a live futures-trading context, hidden autonomous execution can create substantial financial loss, unintended positions, and compliance problems if users do not fully understand the automation model.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The scheduled-order section instructs the agent to create future autonomous trades, but it lacks a conspicuous warning that orders may execute later without further review and can have real financial impact. In a high-risk trading environment, delayed unattended execution is especially dangerous because market conditions may change materially between setup time and execution time.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'uvicorn' resembles popular package 'gunicorn'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

This is a true tool-parameter abuse issue because the build command is assembled into a shell string and executed through cmd.exe. That design gives attacker-controlled path fragments an opportunity to alter compiler or shell behavior, potentially leading to arbitrary code execution or malicious build artifacts.

Content

Scanner excerpt · scripts/bridge/build_windows.py (reported line 78)May include surrounding context.

python
full_cmd = f'cmd /c ""{vcvars}" >nul 2>&1 && {cl_cmd}"'

    print("[INFO] 编译 ctp_bridge.dll ...")
    ret = subprocess.call(full_cmd, shell=True)
    if ret != 0:
        sys.exit("[ERROR] 编译失败")

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file exposes functions that place live trading orders and cancel existing orders, which are potentially irreversible financial actions. Although trading is the component's purpose, there is no inline warning, confirmation step, or user-visible disclosure indicating that these calls can execute or cancel real market orders.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains substantive user-facing skill documentation in Chinese only, including feature descriptions and operational behavior, with no indication that users may choose another language. That can violate a language/locale policy when the skill documentation effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents powerful trading features, including automatic order placement, cancellation, conditional orders, and scheduled execution, without an immediate prominent risk warning near the feature overview. In a financial trading skill, this can mislead users or integrating agents into treating the tool as a routine data assistant rather than software capable of placing real trades autonomously, increasing the chance of unintended financial loss.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares broad operational behavior that includes shell execution, file access, environment use, and network-facing services, but it does not define any explicit tool scope or permissions boundary. In a trading skill that can compile code, modify files, start daemons, and expose HTTP services, this omission materially increases the chance of over-privileged execution and misuse.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

text
   python scripts/clawtrader.py start
  • 首次运行自动编译 CTP 接口层(需已安装编译工具:Windows → VS 2019+,macOS → Xcode CLT,Linux → sudo apt install build-essential)
  • 自动弹出账户配置向导,引导填写经纪商、账号、密码、前置地址
  • 完成后 daemon 上线,开始交易

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · deploy/README.md (reported line 29)May include surrounding context.

text
   python scripts/clawtrader.py start
  • 首次运行自动编译 CTP 接口层(需已安装编译工具:Windows → VS 2019+,macOS → Xcode CLT,Linux → sudo apt install build-essential)
  • 自动弹出账户配置向导,引导填写经纪商、账号、密码、前置地址
  • 完成后 daemon 上线,开始交易

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · deploy/README.md (reported line 30)May include surrounding context.

text
   python scripts/clawtrader.py start
  • 首次运行自动编译 CTP 接口层(需已安装编译工具:Windows → VS 2019+,macOS → Xcode CLT,Linux → sudo apt install build-essential)
  • 自动弹出账户配置向导,引导填写经纪商、账号、密码、前置地址
  • 完成后 daemon 上线,开始交易

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · deploy/README.md (reported line 31)May include surrounding context.

text
   python scripts/clawtrader.py start
  • 首次运行自动编译 CTP 接口层(需已安装编译工具:Windows → VS 2019+,macOS → Xcode CLT,Linux → sudo apt install build-essential)
  • 自动弹出账户配置向导,引导填写经纪商、账号、密码、前置地址
  • 完成后 daemon 上线,开始交易

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · deploy/README.md (reported line 34)May include surrounding context.

text
   python scripts/clawtrader.py start
  • 首次运行自动编译 CTP 接口层(需已安装编译工具:Windows → VS 2019+,macOS → Xcode CLT,Linux → sudo apt install build-essential)
  • 自动弹出账户配置向导,引导填写经纪商、账号、密码、前置地址
  • 完成后 daemon 上线,开始交易

Static analysis

No suspicious patterns detected.