Back to skill

Security audit

ZKE Exchange Trading Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a real ZKE trading skill, but it exposes live trading and withdrawals with weak enforced safeguards and stores sensitive activity logs locally.

Install only if you understand it can place real trades, move funds between accounts, change futures settings, cancel orders, and request withdrawals. Use API keys with withdrawals disabled, minimal trading permissions, IP allowlisting, and account-level limits; review or disable the local log at ~/.zke-trading/openclaw-plugin.log before using it with sensitive balances or withdrawal addresses.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
openclaw-plugin/src/index.ts:68
Finding

High-Impact Financial Operations Lack Enforceable Authorization and Confirmation

Content
View full analysis
) { writeLog(`TOOL_CALL ${tool.name} params=${JSON.stringify(params)}`); try { const result = await tool.execute(params); writeLog(`TOOL_RESULT ${tool.name} result=${JSON.stringify(result)}`); return result; } catch (err: any) { writeLog(`TOOL_ERROR ${tool.name} error=${err?.stack || err?.message || String(err)}`); throw err; } }, }) ``` `openclaw-plugin/src/tools/wallet.ts:86-107`: ```typescript { name: "zke_create_withdraw", description: "Create a ZKE withdrawal request", inputSchema: { type: "object", properties: { coin: { type: "string", description: "e.g. USDTBSC or asset symbol used by your local CLI" }, address: { type: "string" }, amount: { type: "string" }, memo: { type: "string" }, }, required: ["coin", "address", "amount"], additionalProperties: false, }, execute: async ({ coin, address, amount, memo = "" }) => { const args = ["withdraw", String(coin), String(address), String(amount)]; if (String(memo).trim()) { args.push(String(memo)); } args.push("--json"); return await runMainJson(args, config); }, }, ``` `main.py:494-510`: ```python if cmd == "withdraw": coin = sys.argv[2] address = sys.argv[3] amount = sys.argv[4] memo = sys.argv[5] if len(sys.argv) > 5 and sys.argv[5] != "" else None data = withdraw ...[truncated 3471 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
openclaw-plugin/src/index.ts:42
Finding

Sensitive Financial Tool Parameters and Results Are Persisted in Plaintext

Content
View full analysis
) { writeLog(`TOOL_CALL ${tool.name} params=${JSON.stringify(params)}`); try { const result = await tool.execute(params); writeLog(`TOOL_RESULT ${tool.name} result=${JSON.stringify(result)}`); return result; } catch (err: any) { writeLog(`TOOL_ERROR ${tool.name} error=${err?.stack || err?.message || String(err)}`); throw err; } }, ``` ### Technical Analysis The wrapper serializes every tool’s complete input parameters and complete result into `~/.zke-trading/openclaw-plugin.log`. No field-level redaction, retention limit, rotation policy, encryption, or explicit restrictive file mode is applied. Sensitive values can include: - Cryptocurrency withdrawal addresses and memos. - Withdrawal and transfer amounts. - Account balances and positions. - Open-order, trade, and transaction history. - Order, trade, withdrawal, and client identifiers. - Details returned in error payloads or stack traces. Although the reviewed tool schemas do not directly accept the ZKE secret as a normal parameter, the logged financial data remains sensitive. Error objects may also contain unexpectedly detailed payloads. The behavior conflicts with the root Skill documentation’s broad claim that the plugin does not use plaintext local storage. Because `appendFileSync` uses normal filesystem defaults, protection depends on the pro ...[truncated 1376 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
install_openclaw_plugin.sh:34
Finding

Installer Resolves Mutable and Unverified Third-Party Dependencies

Content
View full analysis
/dev/null 2>&1 && npm run build || log_err "编译失败" log_info "构建 Python 虚拟环境..." cd "$CURRENT_DIR" "$PYTHON_BIN" -m venv .venv source .venv/bin/activate pip install -r requirements.txt >/dev/null 2>&1 || log_err "依赖安装失败" ``` `requirements.txt:1-3`: ```text requests websocket-client mcp>=1.2.0 ``` `openclaw-plugin/package.json:24-28`: ```json "dependencies": {}, "devDependencies": { "typescript": "^5.9.2", "@types/node": "^22.13.10" } ``` No npm lockfile is present in the supplied project structure. ### Technical Analysis The documented installation process contacts configured npm and Python package indexes and resolves dependency versions at installation time. The Python dependencies `requests` and `websocket-client` have no version constraints, while `mcp` permits any release at or above version 1.2.0. The npm development dependencies use caret ranges, and the absence of a lockfile prevents deterministic resolution and integrity verification through `npm ci`. As a result, the code installed and executed can differ from the artifact that was audited. Installation also suppresses npm and pip output, reducing visibility into selected versions, package sources, and warnings. This behavior is a supply-chain weakness rather than proof that the currently named packages are malicious. Exploitation requires a compromised package release, registry, mirror, dependency account, or package-resolution environment. ### Attack Path 1. An attacker compromises a permitted dependency release, maintainer account, configured registry, or package mirror. 2. The attacker publish ...[truncated 1209 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (91)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation supports margin trading and external withdrawals but those powers are not clearly declared, users and hosts cannot make informed risk decisions. This is especially severe for exchange-integrated skills because omitted disclosure can lead to accidental fund loss, liquidation exposure, or unauthorized asset egress.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Order-placement and account-modification commands such as create-order, futures-create-order, leverage edits, margin mode changes, and position adjustments can execute immediately from command arguments without confirmation, simulation, or guardrails. In an autonomous agent skill for exchange control, this creates a direct path from misunderstood or adversarial prompts to real market actions, losses, liquidation risk, or unintended strategy changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The withdraw command directly performs an irreversible on-chain asset withdrawal using only positional CLI arguments, with no confirmation prompt, dry-run mode, destination allowlist, or secondary approval step. In a trading skill context that has live exchange credentials, a mistaken instruction, prompt manipulation, or parameter mix-up can immediately cause permanent loss of funds to an attacker-controlled address.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This tool exposes a direct withdrawal primitive that can irreversibly transfer assets to an arbitrary address with no built-in confirmation, policy gate, allowlist, or secondary approval. In an agent/tooling context, that is dangerous because a prompt-injected or mistaken agent action could immediately exfiltrate funds from the connected exchange account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment explicitly referencing 'completely silent execution' is not itself exploit code, but in context it indicates an intent to suppress visibility around risky operations. In a financial-trading skill, language emphasizing silent execution increases concern because it can normalize undisclosed actions and hide behaviors that affect user assets or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section performs live order creation, cancellation, internal asset transfers, and withdrawal/history operations directly with no built-in confirmation, simulation-only default, policy check, or user-facing warning. In an AI-controlled trading skill, this creates a high-risk path where ambiguous instructions, prompt injection, or agent mistakes can immediately trigger irreversible financial actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code directly invokes api.withdraw_apply(body) to transfer funds without any built-in confirmation, re-authentication, allowlist validation, or risk checks. In an AI-driven skill, this is dangerous because a mistaken prompt, prompt injection, or ambiguous user request could trigger irreversible asset withdrawal to an attacker-controlled address.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares access to sensitive environment variables and clearly implies networked trading actions, but it does not declare any explicit tool scope such as permissions or allowed-tools. In a financial-trading context, missing scope boundaries increases the risk that the host grants broader-than-necessary capabilities, especially where API keys can move assets or place orders.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example prompts encourage order placement and asset transfers, but they do not clearly warn that these are financially risky and potentially irreversible actions. In a conversational agent setting, users may invoke these operations casually, increasing the chance of mistaken trades or unintended fund movements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The transfer commands move funds between spot and futures accounts immediately with no user-facing confirmation or transaction preview. While transfers are internal rather than external withdrawals, they still alter risk exposure and can enable subsequent leveraged trading or liquidation pathways if triggered unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file reads API credentials from environment variables via os.environ.get to build authenticated trading clients, but there is no user-facing warning, logging, or surrounding comment/docstring disclosing that sensitive credentials are being accessed. For a code file, access to sensitive environment variables should have some explicit disclosure unless already documented elsewhere in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function can cancel all futures orders, including when no symbol is supplied, without any confirmation or scope restriction. In a trading agent context this destructive action can disrupt strategies, remove protective orders, and materially increase market exposure if triggered accidentally or via prompt injection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The plugin writes persistent local logs containing full tool parameters, results, and errors to a file under the user's home directory. In a trading plugin, those values can include API-related data, balances, order details, positions, and other sensitive financial information, creating an undisclosed data-retention channel that is not necessary for core trading functionality.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code comment says dangerous-property mapping was removed to ensure 'completely silent execution,' yet the implementation still performs hidden persistent side effects by logging every call, result, and error to disk. That mismatch is a strong red flag because it suggests deliberate concealment of behavior from the runtime or user while retaining a covert audit trail of sensitive trading activity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.