Back to skill

Security audit

Binance Event Contract Signal Calculator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed trading-signal prompt with no embedded code or persistence, but users should treat its financial claims and installer command cautiously.

Install only if you are comfortable with a market-signal skill that may produce highly confident trading suggestions. Do not treat the stated win rates or position sizes as reliable investment advice, and prefer a pinned, reviewed installer version over the mutable @latest command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:96
Finding

Unpinned npm Package Execution in Installation Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 96–99
Vulnerability Type: Supply-chain risk caused by execution of a mutable third-party package version
Risk Level: Medium

Complete Code Snippet:

markdown
## Installation
```bash
npx clawhub@latest install binance-event-contract-signal-calculator --dir /workspace/skills
text

### Technical Analysis

The documented installation procedure invokes `npx` with `clawhub@latest`. When the package is not already available locally, `npx` can download it from the configured npm registry and execute its package entry point. The `latest` distribution tag is mutable and does not identify an immutable, previously audited release.

Consequently, the effective code executed by this command can change after this Skill has been reviewed, without any modification to `SKILL.md`. The artifact does not provide an exact package version, lockfile, integrity digest, or other mechanism for verifying the downloaded package. This is a supply-chain weakness; the audit found no evidence that the package is currently malicious.

### Attack Path

1. An attacker compromises the `clawhub` npm publishing account, its release process, or another relevant package-publication component.
2. The attacker publishes a malicious release and assigns it to the mutable `latest` tag.
3. A user follows the installation command in `SKILL.md`.
4. `npx` retrieves the attacker-controlled package from the configured registry.
5. The package executes with the operating-system permissions and environment available to the installing user.
6. Malicious package lifecycle or application code can perform actions within those permissions before or during installation of the requested Skill.

### Impact Assessment

Successful exploitation could permit arbitrary code execution with the installing user's privileges. Depending on that user's permissions and environment, the malicious dependency could r
...[truncated 480 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, audited package version, for example clawhub@X.Y.Z.
  2. Verify the selected release's provenance and integrity before documenting it.
  3. Use a lockfile or an equivalent reproducible dependency mechanism where applicable.
  4. Pin and verify package integrity using a trusted digest or registry-supported integrity metadata.
  5. Document the expected trusted registry and reject unexpected registry overrides.
  6. Execute installation in a least-privileged, isolated environment without unnecessary credentials or sensitive environment variables.
  7. Review package lifecycle scripts and transitive dependencies before approving version upgrades.
  8. Treat upgrades as security-sensitive changes requiring renewed review rather than automatically following a mutable distribution tag.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill provides highly specific trading instructions, targets, stop losses, position sizing, and claimed win rates without any financial-risk warning or suitability disclaimer. In context, this can mislead users into treating the output as reliable investment advice, increasing the chance of financial harm, especially because the skill presents precise actionable signals and confidence scores that may create false trust.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The installation command uses npx clawhub@latest, which pulls and executes the newest published package version at runtime rather than a reviewed, pinned release. This creates a supply-chain risk: if the package is compromised, typosquatted, or a malicious update is published, users installing the skill could execute untrusted code on their system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.