Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - src/index.cjs
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed read-only Binance trading-history analyzer that uses API credentials for the expected purpose and shows no evidence of trading, withdrawal, persistence, or hidden data transfer.
Install only with Binance API keys restricted to read-only permissions, disabled trading and withdrawals, and preferably IP restrictions. Expect the tool to contact Binance and display sensitive balances and trading history locally in the console.
Referenced artifact was not completely inspected
- src/index.cjs
Referenced artifact was not completely inspected
- src/binance.cjs
Referenced artifact was not completely inspected
- src/shadowSim.cjs
Referenced artifact was not completely inspected
- src/coach.cjs
Referenced artifact was not completely inspected
- tests/analyzer.test.cjs
Referenced artifact was not completely inspected
- tests/shadowSim.test.cjs
Referenced artifact was not completely inspected
- tests/binance.test.cjs
This file performs authenticated HTTPS requests to Binance endpoints using API keys and returns sensitive financial account data such as balances, income history, and trade history. While the code has technical comments, it lacks any user-facing confirmation prompt or explicit warning that account data will be sent to an external service.
This code uses API credentials and then connects to Binance, fetches balances, and retrieves futures/spot trading history. While it logs operational progress, it does not clearly disclose to the user that real account portfolio and transaction data will be sent to Binance APIs when real credentials are present.
This code file analyzes income events from Binance, including realized PnL, commissions, funding, timestamps, and daily/hourly trading behavior. Although it does not transmit or delete data, it handles sensitive financial-trading records and there is no confirmation prompt, warning comment, or user-facing disclosure in this file about that sensitivity.
No suspicious patterns detected.