Back to skill

Security audit

Nansen Binance Publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for crypto report publishing, but it grants unattended public posting authority and cron-based persistence with stored API keys.

Review carefully before installing. Use manual `/nansen` approval mode unless you intentionally want unattended public posting, avoid cron until you have scoped and revocable keys, pin or verify dependencies where possible, and do not treat the mandatory referral links as required official setup paths.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:27
Finding

Mandatory Affiliate Link Injection into Agent Responses

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:39
Finding

Unpinned Third-Party Package and Skill Installation

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
SKILL.md:308
Finding

Persistent Cron Job Performs Unattended Authenticated Publishing

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (18)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: nansen-binance-publisher
description: Automatically fetch multi-dimensional on-chain data using Nansen CLI, compile a comprehensive and beautifully formatted daily report, and publish it to Binance Square. Auto-run on messages like 'generate nansen daily report', 'post nansen daily to square', or when the user triggers the slash commands `/nansen` or `/post_square`.
author: AntCaveClub
version: 1.2
env:
  - NANSEN_API_KEY
  - X_SQUARE_OPENAPI_KEY
dependencies:
  - nansen-cli (npm)
---

# Nansen to Binance Square Daily Publisher

## Overview
This skill instructs the Agent to act as a professional crypto data analyst an

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The /nansen_auto command is defined to fetch data, generate content, and post it, while only loosely noting that permission is required. Because this mode is described as a full workflow trigger, it creates a path for unattended or insufficiently reviewed publication to an external platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The security section explicitly carves out an exception allowing content transmission without display to the user when /nansen_auto is used. This undermines transparency and user review, making accidental, manipulated, or unwanted outbound posting materially more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says the AI may handle dependency installation automatically and frames that as part of normal operation, extending the skill from content generation into environment modification. This broadens the trust boundary and can lead an agent to perform software installation actions unrelated to the minimal reporting/publishing task, increasing the chance of unsafe system changes or abuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The README instructs users to install the skill via npx skills add ... without pinning a specific version or immutable source. That creates a supply-chain risk: if the package or resolver behavior changes, users may install unexpected code, and this skill already requests sensitive API keys and publishing authority, which raises the stakes.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
96% confidence
Finding

The phrase 'WITHOUT asking for confirmation' indicates autonomous decision-making for a sensitive external action: publishing to a user's Binance Square account. In this context, autonomy is more dangerous than in a read-only skill because the agent can create irreversible public outputs that affect reputation, compliance posture, and account trust.

Content

Scanner excerpt · README.md (reported line 69)May include surrounding context.

md
| :--- | :--- |
| `/nansen` | Default. Fetches Ethereum data, drafts a report, and waits for your approval. |
| `/nansen <chain>` | Fetch data for a specific chain. e.g., `/nansen solana` or `/nansen base`. |
| `/nansen_auto` | **Silent Mode**. Fetches, writes, and posts **WITHOUT asking for confirmation**. (Perfect for Cron jobs). |

---

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The /nansen_auto mode explicitly publishes to Binance Square without confirmation, but that higher-risk capability is not clearly surfaced in the skill metadata. Hidden or under-disclosed autonomous posting is dangerous because it can cause unauthorized or erroneous posts from a user's external account, especially when combined with stored API keys.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Describing silent auto-posting without a strong warning normalizes bypassing human review before content is published to a real external account. In this skill's context, the action is especially sensitive because it affects a public Binance Square identity and could spread inaccurate, harmful, or account-damaging content instantly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The cron instructions guide the AI to help configure crontab, which is an administrative system capability beyond simple report drafting and publishing. This matters because scheduled execution combined with stored credentials creates persistent, unattended authority that could be misused for repeated unauthorized posts or other agent-driven actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The cron-based automation instructions omit a clear warning that the system will publish unattended to an external Binance Square account on a schedule. That is risky because mistakes, prompt injection, bad data, or configuration drift can repeatedly trigger public posts without human intervention.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The Chinese section repeats the same unpinned npx skills add ... installation flow, so the same supply-chain exposure applies to another audience segment. Because the skill is designed to obtain API credentials and perform external posting, a compromised install path could lead to credential theft or unauthorized account actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description enables auto-run on vague natural-language phrases like 'generate nansen daily report' and 'post nansen daily to square'. Ambiguous triggers can cause the skill to activate unintentionally and begin data fetching or posting workflows without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill includes a zh-CN registration link and multiple mandatory Chinese report templates, but it does not state that users can choose their preferred language or that the skill is intentionally limited to a Chinese-speaking region. This can violate language/locale policy because it effectively forces a specific language/locale without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill first states that any CLI failure or missing data must abort report generation entirely, but later says failed sections may be skipped or replaced. This contradiction weakens safety guarantees and can lead the agent to continue with incomplete or unverifiable data, increasing the chance of misleading output or unintended posting.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
**CRITICAL FORMATTING RULES:**
- Adopt the tone of a **Senior Crypto Researcher**. Provide real insights, not just raw numbers.
- Format large numbers elegantly (e.g., `$1.23M`, `$500K`).
- **NO MARKDOWN:** Binance Square's API `bodyTextOnly` does NOT support Markdown. You MUST NOT use syntax like `**bold**`, `*italic*`, or `### headers`. Use emojis and plain text spacing only to create visual hierarchy.
- **ANTI-HALLUCINATION RULE:** NEVER make up data. If Nansen CLI returns no data for a specific query, you MUST gracefully abort and inform the user.

**DAILY RANDOM TEMPLATE SELECTION:**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All six required output templates are written in Chinese and the workflow says the agent must randomly select one of them, which effectively mandates Chinese output for all users. There is no documented user choice of language or justification that the skill is region-specific, so this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill's security boundary says network communication must be limited to Nansen CLI and the Binance Square API, yet earlier instructions require visiting arbitrary user-provided URLs and using web search. This inconsistency can bypass intended network restrictions and expose the agent to untrusted external content, tracking, prompt injection, or data exfiltration paths.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Allowing silent automation to publish without showing the final content first reduces transparency around exactly what user inputs, web-fetched context, or tool-derived content will be transmitted externally. This makes prompt-injected, inaccurate, or policy-violating content more likely to be sent without user awareness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.