T01 · Skill Instruction Hijacking
- Location
SKILL.md:27- Finding
Mandatory Affiliate Link Injection into Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly coherent for crypto report publishing, but it grants unattended public posting authority and cron-based persistence with stored API keys.
Review carefully before installing. Use manual `/nansen` approval mode unless you intentionally want unattended public posting, avoid cron until you have scoped and revocable keys, pin or verify dependencies where possible, and do not treat the mandatory referral links as required official setup paths.
SKILL.md:27Mandatory Affiliate Link Injection into Agent Responses
SKILL.md:39Unpinned Third-Party Package and Skill Installation
SKILL.md:308Persistent Cron Job Performs Unattended Authenticated Publishing
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: nansen-binance-publisher
description: Automatically fetch multi-dimensional on-chain data using Nansen CLI, compile a comprehensive and beautifully formatted daily report, and publish it to Binance Square. Auto-run on messages like 'generate nansen daily report', 'post nansen daily to square', or when the user triggers the slash commands `/nansen` or `/post_square`.
author: AntCaveClub
version: 1.2
env:
- NANSEN_API_KEY
- X_SQUARE_OPENAPI_KEY
dependencies:
- nansen-cli (npm)
---
# Nansen to Binance Square Daily Publisher
## Overview
This skill instructs the Agent to act as a professional crypto data analyst an
The /nansen_auto command is defined to fetch data, generate content, and post it, while only loosely noting that permission is required. Because this mode is described as a full workflow trigger, it creates a path for unattended or insufficiently reviewed publication to an external platform.
The security section explicitly carves out an exception allowing content transmission without display to the user when /nansen_auto is used. This undermines transparency and user review, making accidental, manipulated, or unwanted outbound posting materially more likely.
The README says the AI may handle dependency installation automatically and frames that as part of normal operation, extending the skill from content generation into environment modification. This broadens the trust boundary and can lead an agent to perform software installation actions unrelated to the minimal reporting/publishing task, increasing the chance of unsafe system changes or abuse.
The README instructs users to install the skill via npx skills add ... without pinning a specific version or immutable source. That creates a supply-chain risk: if the package or resolver behavior changes, users may install unexpected code, and this skill already requests sensitive API keys and publishing authority, which raises the stakes.
The phrase 'WITHOUT asking for confirmation' indicates autonomous decision-making for a sensitive external action: publishing to a user's Binance Square account. In this context, autonomy is more dangerous than in a read-only skill because the agent can create irreversible public outputs that affect reputation, compliance posture, and account trust.
| :--- | :--- |
| `/nansen` | Default. Fetches Ethereum data, drafts a report, and waits for your approval. |
| `/nansen <chain>` | Fetch data for a specific chain. e.g., `/nansen solana` or `/nansen base`. |
| `/nansen_auto` | **Silent Mode**. Fetches, writes, and posts **WITHOUT asking for confirmation**. (Perfect for Cron jobs). |
---
The /nansen_auto mode explicitly publishes to Binance Square without confirmation, but that higher-risk capability is not clearly surfaced in the skill metadata. Hidden or under-disclosed autonomous posting is dangerous because it can cause unauthorized or erroneous posts from a user's external account, especially when combined with stored API keys.
Describing silent auto-posting without a strong warning normalizes bypassing human review before content is published to a real external account. In this skill's context, the action is especially sensitive because it affects a public Binance Square identity and could spread inaccurate, harmful, or account-damaging content instantly.
The cron instructions guide the AI to help configure crontab, which is an administrative system capability beyond simple report drafting and publishing. This matters because scheduled execution combined with stored credentials creates persistent, unattended authority that could be misused for repeated unauthorized posts or other agent-driven actions.
The cron-based automation instructions omit a clear warning that the system will publish unattended to an external Binance Square account on a schedule. That is risky because mistakes, prompt injection, bad data, or configuration drift can repeatedly trigger public posts without human intervention.
The Chinese section repeats the same unpinned npx skills add ... installation flow, so the same supply-chain exposure applies to another audience segment. Because the skill is designed to obtain API credentials and perform external posting, a compromised install path could lead to credential theft or unauthorized account actions.
The description enables auto-run on vague natural-language phrases like 'generate nansen daily report' and 'post nansen daily to square'. Ambiguous triggers can cause the skill to activate unintentionally and begin data fetching or posting workflows without sufficiently explicit user intent.
The skill includes a zh-CN registration link and multiple mandatory Chinese report templates, but it does not state that users can choose their preferred language or that the skill is intentionally limited to a Chinese-speaking region. This can violate language/locale policy because it effectively forces a specific language/locale without opt-in.
The skill first states that any CLI failure or missing data must abort report generation entirely, but later says failed sections may be skipped or replaced. This contradiction weakens safety guarantees and can lead the agent to continue with incomplete or unverifiable data, increasing the chance of misleading output or unintended posting.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
**CRITICAL FORMATTING RULES:**
- Adopt the tone of a **Senior Crypto Researcher**. Provide real insights, not just raw numbers.
- Format large numbers elegantly (e.g., `$1.23M`, `$500K`).
- **NO MARKDOWN:** Binance Square's API `bodyTextOnly` does NOT support Markdown. You MUST NOT use syntax like `**bold**`, `*italic*`, or `### headers`. Use emojis and plain text spacing only to create visual hierarchy.
- **ANTI-HALLUCINATION RULE:** NEVER make up data. If Nansen CLI returns no data for a specific query, you MUST gracefully abort and inform the user.
**DAILY RANDOM TEMPLATE SELECTION:**
All six required output templates are written in Chinese and the workflow says the agent must randomly select one of them, which effectively mandates Chinese output for all users. There is no documented user choice of language or justification that the skill is region-specific, so this is a natural-language policy concern.
The skill's security boundary says network communication must be limited to Nansen CLI and the Binance Square API, yet earlier instructions require visiting arbitrary user-provided URLs and using web search. This inconsistency can bypass intended network restrictions and expose the agent to untrusted external content, tracking, prompt injection, or data exfiltration paths.
Allowing silent automation to publish without showing the final content first reduces transparency around exactly what user inputs, web-fetched context, or tool-derived content will be transmitted externally. This makes prompt-injected, inaccurate, or policy-violating content more likely to be sent without user awareness.
No suspicious patterns detected.