Back to skill

Security audit

Binance ICT Structure Recognizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a market-analysis prompt, but it gives contradictory financial-trading instructions and uses a mutable installer that should be reviewed before installation.

Review this carefully before installing. Treat its outputs as analysis, not trading advice, because the skill both forbids direct trade signals and shows a direct entry/target/stop-loss recommendation. Prefer a pinned and verified ClawHub installer version instead of `@latest`, and run it only in an environment without exchange credentials or automatic order execution unless you have separately reviewed those integrations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:81
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 81–83
Vulnerability Type: Unpinned and mutable third-party dependency execution
Risk Level: Medium

Complete Code Snippet:

bash
npx clawhub@latest install binance-event-contract-ict-recognizer --dir /workspace/skills

Technical Analysis

The documented installation command invokes npx with the mutable latest tag. If the requested package is not already available in a trusted local cache, npx can retrieve it from the configured npm registry and execute its package entry point or installation logic immediately.

Because latest does not identify an immutable, previously audited version, the code executed by this command can change after the Skill documentation has been reviewed. The clawhub package and its transitive dependencies are not included in this project, so their behavior, provenance, and integrity cannot be verified from the audited artifact.

This creates a supply-chain trust boundary in which compromise of the package publisher, registry account, release process, package contents, or transitive dependencies could convert the documented installation procedure into arbitrary code execution.

Attack Path

  1. An attacker compromises the clawhub package publisher, its release pipeline, or a relevant dependency.
  2. The attacker publishes a malicious release and assigns or causes it to receive the latest distribution tag.
  3. A user follows the installation command in SKILL.md.
  4. npx retrieves the mutable package release and executes its installation logic with the invoking user's permissions.
  5. The malicious installer can alter /workspace/skills and perform any other operation permitted to that user.

Impact Assessment

Successful exploitation would provide code execution with the privileges of the user running the installation command. Depending on that user's permissions and environment, the malicious packa ...[truncated 480 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version; do not use a mutable version range or distribution tag.
  2. Verify the downloaded artifact using an approved cryptographic integrity digest or signed provenance before execution.
  3. Review the selected package version and its transitive dependency tree before publishing the installation instructions.
  4. Use a lockfile or equivalent immutable dependency manifest where supported.
  5. Prefer a trusted internal registry or a vetted distribution channel with access controls, package signing, and release auditing.
  6. Run installation in a sandbox or least-privileged environment without production credentials or unnecessary filesystem access.
  7. Disable or carefully review dependency lifecycle scripts where the installation workflow permits it.
  8. Document the expected package publisher, version, digest, and verification procedure so users can detect substituted artifacts.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The installation command uses npx clawhub@latest, which pulls and executes the latest published package version at install time rather than a reviewed, pinned release. This creates a supply-chain risk: if the upstream package is compromised or changed unexpectedly, users may execute untrusted code when installing the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The example output includes Chinese text ("逆向吃到流动性") embedded in an otherwise English skill description. This can impose a language/locale expectation on users without opt-in or justification, which fits the policy category for language or locale violations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.