Back to skill

Security audit

HyperClaw

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Hyperliquid trading skill, but it can make live financial trades and runs an unauthenticated proxy with broader network exposure than users may expect.

Review carefully before installing. Use a separate low-privilege Hyperliquid API wallet with limited funds, prefer testnet first, do not expose the proxy port to other machines or containers, bind or firewall it to localhost, and avoid enabling Grok features unless you are comfortable sending queries to xAI. Treat the .env file as a private key store.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/server.py:315
Finding

Unauthenticated caching proxy exposed on all network interfaces

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Security-sensitive dependencies are installed from mutable version ranges without integrity verification

Content
View full analysis
=0.4.0 eth-account>=0.13.0 requests>=2.31.0 python-dotenv>=1.0.0 httpx>=0.27.0 fastapi>=0.115.0 uvicorn[standard]>=0.32.0 ``` ### Technical Analysis Every dependency is specified using an open-ended lower bound. Consequently, setup can install different direct and transitive package versions depending on when it runs. No lock file, exact version constraint, package hash, or integrity-enforcement option is used. This is particularly security-sensitive because the resulting Python process handles: - A Hyperliquid API-wallet private key through `HL_SECRET_KEY`. - An xAI bearer credential through `XAI_API_KEY`. - Locally signed financial transactions. - Account and position information. A malicious or compromised future release of a direct or transitive dependency would execute with the same operating-system permissions as the Skill and could access loaded environment variables, alter transaction construction, intercept signed requests, or transmit sensitive information. The reviewed package names appear legitimate, and no dependency-confusion domain, typo-squatted name, or known malicious package was established by this static audit. The confirmed issue is the absence of reproducible and integrity-verified dependency resolution. ### Attack Path 1. A direct or transitive package account, release process, or distribution artifact is compromised, or a future incompatible release introduces unsafe behavior. 2. The user follows the documented setup process. 3. `pip` resolves the unrestricted ...[truncated 944 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (45)

Tainted flow: 'proxy_url' from os.getenv (line 154, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The code sends the account address to a URL taken directly from the HL_PROXY_URL environment variable without validation. Because this skill is explicitly designed to handle trading credentials and account state, a malicious or misconfigured proxy URL can exfiltrate user-identifying trading metadata to an attacker-controlled host and create SSRF-style outbound requests from the agent environment.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 162)May include surrounding context.

python
return
    try:
        import requests
        requests.post(f"{proxy_url}/cache/clear", json={"user": address}, timeout=2)
    except Exception:
        pass  # Proxy may be down; not critical

Tainted flow: 'grok_api_key' from os.getenv (line 2871, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 2674)May include surrounding context.

python
tool_specs = [{"type": t} for t in tools]

    try:
        response = req.post(
            "https://api.x.ai/v1/responses",
            headers={
                "Authorization": f"Bearer {grok_api_key}",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 19)May include surrounding context.

md
bash hyperclaw/scripts/setup.sh

# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key

# 4. Start the caching proxy (recommended)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 20)May include surrounding context.

md
bash hyperclaw/scripts/setup.sh

# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key

# 4. Start the caching proxy (recommended)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 31)May include surrounding context.

python
bash hyperclaw/scripts/setup.sh

# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key

# 4. Start the caching proxy (recommended)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 70)May include surrounding context.

python
bash hyperclaw/scripts/setup.sh

# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key

# 4. Start the caching proxy (recommended)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 1849)May include surrounding context.

python
bash hyperclaw/scripts/setup.sh

# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key

# 4. Start the caching proxy (recommended)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 40)May include surrounding context.

sh
bash hyperclaw/scripts/setup.sh

# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key

# 4. Start the caching proxy (recommended)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 45)May include surrounding context.

sh
bash hyperclaw/scripts/setup.sh

# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key

# 4. Start the caching proxy (recommended)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 53)May include surrounding context.

sh
bash hyperclaw/scripts/setup.sh

# 3. Configure credentials
cp hyperclaw/.env.example hyperclaw/.env
# Edit .env with your Hyperliquid API key

# 4. Start the caching proxy (recommended)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation introduces a local HTTP proxy/cache server with management endpoints, which is operational behavior not reflected in the high-level skill description. That mismatch matters because it adds an always-on local service and extra network surface that users may not realize they are deploying.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation introduces a local HTTP proxy/cache server with management endpoints, which is operational behavior not reflected in the high-level skill description. That mismatch matters because it adds an always-on local service and extra network surface that users may not realize they are deploying.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

HL_TESTNET=false

text

Get API keys from: https://app.hyperliquid.xyz/API — use a separate API wallet, not your main wallet private key.

Optional for intelligence commands (sentiment, unlocks, devcheck, ask, search):

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trading section documents direct buy, sell, leverage, close, cancel, and order-modification commands without a prominent irreversible-action warning or confirmation requirement. In a live trading context, this creates a substantial risk of accidental loss, liquidation, or unintended account changes from mis-invocation or misunderstanding.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'uvicorn' resembles popular package 'gunicorn'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 2666)May include surrounding context.

python
"$VENV_DIR/bin/pip" install -q -r "$SCRIPT_DIR/requirements.txt"

# Create .env from example if it doesn't exist
if [ ! -f "$SKILL_DIR/.env" ]; then
    if [ -f "$SKILL_DIR/.env.example" ]; then
        cp "$SKILL_DIR/.env.example" "$SKILL_DIR/.env"
        echo ""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 41)May include surrounding context.

sh
"$VENV_DIR/bin/pip" install -q -r "$SCRIPT_DIR/requirements.txt"

# Create .env from example if it doesn't exist
if [ ! -f "$SKILL_DIR/.env" ]; then
    if [ -f "$SKILL_DIR/.env.example" ]; then
        cp "$SKILL_DIR/.env.example" "$SKILL_DIR/.env"
        echo ""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 43)May include surrounding context.

sh
"$VENV_DIR/bin/pip" install -q -r "$SCRIPT_DIR/requirements.txt"

# Create .env from example if it doesn't exist
if [ ! -f "$SKILL_DIR/.env" ]; then
    if [ -f "$SKILL_DIR/.env.example" ]; then
        cp "$SKILL_DIR/.env.example" "$SKILL_DIR/.env"
        echo ""

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README advertises account-affecting commands such as buy, sell, cancel, leverage, and close, but does not clearly warn that these actions can place, modify, or cancel real orders using configured credentials. In an agent-skill context, this omission increases the chance that a user or autonomous agent will invoke destructive live-trading actions without understanding the financial consequences.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares no explicit tool scope while clearly requiring environment variables and network access, including account credentials and remote API calls. For a user-invocable trading skill, missing scope boundaries increases the chance that an agent or platform grants broader capabilities than users expect, weakening reviewability and least-privilege controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This is a user-invocable skill with a very broad description covering trading and intelligence gathering but without clear trigger constraints or guardrails. Broad invocation criteria increase the risk of the skill being selected in contexts where the user did not explicitly intend financial transactions or external searches.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This line transmits the user's account address to an externally configured proxy endpoint. External transmission is expected in a trading client, but here the destination is user/environment-controlled rather than fixed to the trusted exchange, which makes the disclosure materially riskier in the context of a credential-handling skill.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 162)May include surrounding context.

python
return
    try:
        import requests
        requests.post(f"{proxy_url}/cache/clear", json={"user": address}, timeout=2)
    except Exception:
        pass  # Proxy may be down; not critical

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 667)May include surrounding context.

python
import requests

    try:
        resp = requests.post(
            config['api_url'] + "/info",
            json={"type": "predictedFundings"},
            timeout=10

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 794)May include surrounding context.

python
import requests

    try:
        resp = requests.post(
            config['api_url'] + "/info",
            json={"type": "predictedFundings"},
            timeout=10

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/hyperliquid_tools.py (reported line 1888)May include surrounding context.

python
import requests

    try:
        resp = requests.post(
            config['api_url'] + "/info",
            json={"type": "predictedFundings"},
            timeout=10

Static analysis

No suspicious patterns detected.