T09 · Insecure Skill Coding Practices
- Location
scripts/server.py:315- Finding
Unauthenticated caching proxy exposed on all network interfaces
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real Hyperliquid trading skill, but it can make live financial trades and runs an unauthenticated proxy with broader network exposure than users may expect.
Review carefully before installing. Use a separate low-privilege Hyperliquid API wallet with limited funds, prefer testnet first, do not expose the proxy port to other machines or containers, bind or firewall it to localhost, and avoid enabling Grok features unless you are comfortable sending queries to xAI. Treat the .env file as a private key store.
scripts/server.py:315Unauthenticated caching proxy exposed on all network interfaces
scripts/requirements.txt:1Security-sensitive dependencies are installed from mutable version ranges without integrity verification
The code sends the account address to a URL taken directly from the HL_PROXY_URL environment variable without validation. Because this skill is explicitly designed to handle trading credentials and account state, a malicious or misconfigured proxy URL can exfiltrate user-identifying trading metadata to an attacker-controlled host and create SSRF-style outbound requests from the agent environment.
return
try:
import requests
requests.post(f"{proxy_url}/cache/clear", json={"user": address}, timeout=2)
except Exception:
pass # Proxy may be down; not critical
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
tool_specs = [{"type": t} for t in tools]
try:
response = req.post(
"https://api.x.ai/v1/responses",
headers={
"Authorization": f"Bearer {grok_api_key}",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash hyperclaw/scripts/setup.sh
# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key
# 4. Start the caching proxy (recommended)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash hyperclaw/scripts/setup.sh
# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key
# 4. Start the caching proxy (recommended)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash hyperclaw/scripts/setup.sh
# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key
# 4. Start the caching proxy (recommended)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash hyperclaw/scripts/setup.sh
# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key
# 4. Start the caching proxy (recommended)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash hyperclaw/scripts/setup.sh
# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key
# 4. Start the caching proxy (recommended)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash hyperclaw/scripts/setup.sh
# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key
# 4. Start the caching proxy (recommended)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash hyperclaw/scripts/setup.sh
# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key
# 4. Start the caching proxy (recommended)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash hyperclaw/scripts/setup.sh
# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key
# 4. Start the caching proxy (recommended)
The documentation introduces a local HTTP proxy/cache server with management endpoints, which is operational behavior not reflected in the high-level skill description. That mismatch matters because it adds an always-on local service and extra network surface that users may not realize they are deploying.
The documentation introduces a local HTTP proxy/cache server with management endpoints, which is operational behavior not reflected in the high-level skill description. That mismatch matters because it adds an always-on local service and extra network surface that users may not realize they are deploying.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
HL_TESTNET=false
Get API keys from: https://app.hyperliquid.xyz/API — use a separate API wallet, not your main wallet private key.
Optional for intelligence commands (sentiment, unlocks, devcheck, ask, search):
The trading section documents direct buy, sell, leverage, close, cancel, and order-modification commands without a prominent irreversible-action warning or confirmation requirement. In a live trading context, this creates a substantial risk of accidental loss, liquidation, or unintended account changes from mis-invocation or misunderstanding.
Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"$VENV_DIR/bin/pip" install -q -r "$SCRIPT_DIR/requirements.txt"
# Create .env from example if it doesn't exist
if [ ! -f "$SKILL_DIR/.env" ]; then
if [ -f "$SKILL_DIR/.env.example" ]; then
cp "$SKILL_DIR/.env.example" "$SKILL_DIR/.env"
echo ""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"$VENV_DIR/bin/pip" install -q -r "$SCRIPT_DIR/requirements.txt"
# Create .env from example if it doesn't exist
if [ ! -f "$SKILL_DIR/.env" ]; then
if [ -f "$SKILL_DIR/.env.example" ]; then
cp "$SKILL_DIR/.env.example" "$SKILL_DIR/.env"
echo ""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"$VENV_DIR/bin/pip" install -q -r "$SCRIPT_DIR/requirements.txt"
# Create .env from example if it doesn't exist
if [ ! -f "$SKILL_DIR/.env" ]; then
if [ -f "$SKILL_DIR/.env.example" ]; then
cp "$SKILL_DIR/.env.example" "$SKILL_DIR/.env"
echo ""
The README advertises account-affecting commands such as buy, sell, cancel, leverage, and close, but does not clearly warn that these actions can place, modify, or cancel real orders using configured credentials. In an agent-skill context, this omission increases the chance that a user or autonomous agent will invoke destructive live-trading actions without understanding the financial consequences.
The skill declares no explicit tool scope while clearly requiring environment variables and network access, including account credentials and remote API calls. For a user-invocable trading skill, missing scope boundaries increases the chance that an agent or platform grants broader capabilities than users expect, weakening reviewability and least-privilege controls.
This is a user-invocable skill with a very broad description covering trading and intelligence gathering but without clear trigger constraints or guardrails. Broad invocation criteria increase the risk of the skill being selected in contexts where the user did not explicitly intend financial transactions or external searches.
This line transmits the user's account address to an externally configured proxy endpoint. External transmission is expected in a trading client, but here the destination is user/environment-controlled rather than fixed to the trusted exchange, which makes the disclosure materially riskier in the context of a credential-handling skill.
return
try:
import requests
requests.post(f"{proxy_url}/cache/clear", json={"user": address}, timeout=2)
except Exception:
pass # Proxy may be down; not critical
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests
try:
resp = requests.post(
config['api_url'] + "/info",
json={"type": "predictedFundings"},
timeout=10
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests
try:
resp = requests.post(
config['api_url'] + "/info",
json={"type": "predictedFundings"},
timeout=10
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests
try:
resp = requests.post(
config['api_url'] + "/info",
json={"type": "predictedFundings"},
timeout=10
No suspicious patterns detected.