Back to skill

Security audit

Binance Event Contract Skill System

Security checks for vulnerabilities and agentic risk

Overview

This skill is not plainly malicious, but it should be reviewed because it asks for continuous automated trading-data workflows, uses mutable install commands, and contains flawed high-impact risk guidance.

Install only after you are comfortable with a skill that can run unattended, poll Binance continuously, cache and share market data across related skills, and produce trading recommendations. Use pinned, reviewed installer and skill versions, require an explicit opt-in schedule with pause/uninstall controls, and do not rely on the risk-manager output until the position-size math is corrected and independently tested.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:44
Finding

Persistent Unattended Execution Through an Automatic Cron Task

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 4 and 44-48; lines 99-100
Vulnerability Type: T06: System Persistence
Risk Level: High

Vulnerable Code

text
- **Trigger Timing**: Auto-run every minute after Agent startup; also supports manual trigger via `/binance-fetch-data`; runs 24/7, aligned with Binance 7×24 trading hours
text
### 3.4 Running Rule
- Auto-start cron task at Agent startup
- Run at second 0 of every minute
- Auto-cache data after fetch
- Sync to all related Skills for call
text
## Auto-Run Trigger
24/7, run every minute automatically after activation

Technical Analysis

The Skill explicitly instructs the Agent to create or activate a cron-style task that runs every minute, 24 hours a day. This changes the behavior from a user-invoked data-fetch operation into persistent, unattended execution tied to Agent startup.

The scheduled task continuously performs external network requests, writes cached state, and synchronizes that state with related Skills. No explicit consent workflow, scheduler scope, ownership model, disable mechanism, resource limit, or uninstall procedure is defined.

Although the repository contains only instruction files and does not include the scheduler implementation, an Agent that follows these instructions would establish the persistent behavior described by the Skill.

Attack Path

  1. A user installs and activates the data-fetcher Skill.
  2. The Agent interprets the running rules and registers or enables the requested cron task.
  3. The task begins at Agent startup and executes at second zero of every minute.
  4. Each invocation performs Binance network requests, updates cached data, and synchronizes data to related Skills.
  5. The behavior continues without a new user request and may persist across individual Skill invocations or Agent sessions, depending on the scheduler used.
  6. If the Skill or one of its ...[truncated 853 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic scheduler registration from the default activation path.
  2. Require explicit, informed user consent before creating any scheduled task.
  3. Display the exact scheduler entry, command, frequency, working directory, network destinations, and execution identity before installation.
  4. Prefer a foreground or user-invoked operation unless continuous execution is essential.
  5. If scheduling is required, use a least-privileged service account and restrict filesystem and network access.
  6. Add execution locking, rate limits, timeouts, bounded retries, and resource quotas.
  7. Provide documented commands to pause, disable, inspect, and permanently remove the scheduled task.
  8. Ensure uninstalling the Skill also removes all scheduler entries and cached state.
  9. Pin and verify every component executed by the scheduled task so that reviewed behavior cannot change silently.

T08 · Insecure Dependencies

Error
Location
SKILL.md:94
Finding

Remote Execution of an Unpinned Latest-Version Package During Installation

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md, lines 94-96
  • binance-executor/SKILL.md, lines 96-98
  • binance-ict-recognizer/SKILL.md, lines 80-82
  • binance-reporter/SKILL.md, lines 31-33
  • binance-risk-manager/SKILL.md, lines 80-82
  • binance-signal-calculator/SKILL.md, lines 97-99

Vulnerability Type: T08: Insecure Dependencies
Risk Level: High

Vulnerable Code

SKILL.md:

bash
npx clawhub@latest install binance-event-contract-data-fetcher --dir /workspace/skills

binance-executor/SKILL.md:

bash
npx clawhub@latest install binance-event-contract-executor --dir /workspace/skills

binance-ict-recognizer/SKILL.md:

bash
npx clawhub@latest install binance-event-contract-ict-recognizer --dir /workspace/skills

binance-reporter/SKILL.md:

bash
npx clawhub@latest install binance-event-contract-reporter --dir /workspace/skills

binance-risk-manager/SKILL.md:

bash
npx clawhub@latest install binance-event-contract-risk-manager --dir /workspace/skills

binance-signal-calculator/SKILL.md:

bash
npx clawhub@latest install binance-event-contract-signal-calculator --dir /workspace/skills

Technical Analysis

Every installation instruction invokes clawhub@latest through npx. The latest tag is mutable, so the downloaded package can differ from the version that existed when this repository was audited. npx may download and execute package code immediately, including package lifecycle behavior, under the permissions of the invoking user.

The individual Skills are also installed by mutable package names without a fixed version, commit identifier, content digest, or integrity hash. Consequently, neither the installer nor the installed Skill content is reproducibly tied to the reviewed repository.

This creates a supply-chain execution boundary in which compromise of the package publisher, registry account, ...[truncated 1709 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace clawhub@latest with an exact, reviewed version.
  2. Pin each installed Skill to an immutable version or cryptographic content digest.
  3. Use lockfiles and verify registry integrity hashes before execution.
  4. Vendor the reviewed installer and Skill definitions when feasible.
  5. Publish signed release artifacts and verify signatures against a trusted publisher key.
  6. Disable or strictly control dependency lifecycle scripts during installation.
  7. Run installation in a sandbox with minimal filesystem access, no secrets, and restricted outbound networking.
  8. Use a trusted registry allowlist and protect publisher accounts with strong authentication.
  9. Perform dependency review and provenance verification before updating pinned versions.
  10. Ensure scheduled tasks cannot automatically consume newly published, unreviewed Skill content.

T09 · Insecure Skill Coding Practices

Error
Location
binance-risk-manager/SKILL.md:17
Finding

Dimensionally Invalid Position-Size Calculation Can Approve Excessive Exposure

Content
View full analysis

Vulnerability Details

File Location: binance-risk-manager/SKILL.md, lines 17-22 and 50-61
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: High

Vulnerable Code

text
### 3.1 Position Size Calculation
text
Risk Amount = Capital × 2%
Position Size = Risk Amount ÷ (Entry Price - Stop Loss)
Max Position (USD) = Min(Capital × 5%, 250 USDT) ← Binance per-trade limit
Final Position = Min(Risk-based Size, Max Position)

The associated approval example states:

text
【 Risk Check PASSED | BTCUSDT Long | 12:10 UTC 】
Capital: 1,000 USDT
Risk Amount (2%): 20 USDT
Position Size: 0.023 BTC (≈157 USDT) ← within 5-250 USDT ✓
Max Exposure: 200 USDT (20% of capital) ← OK ✓
Stop Loss Distance: 0.5%
Risk/Reward: 1:2.4
Daily P&L: -2.3% ← No warning ✓
Concurrent Positions: 2/4 ← OK ✓
✅ Execution approved

Technical Analysis

The position-sizing rule mixes incompatible units:

  • Risk Amount ÷ (Entry Price - Stop Loss) produces a quantity of the base asset, such as BTC.
  • Max Position (USD) is a USDT-denominated notional limit.
  • Min(Risk-based Size, Max Position) therefore compares an asset quantity directly with a currency amount.

A valid cap cannot be applied until both operands are represented in the same unit.

The example also contains a material arithmetic inconsistency. At the executor's referenced entry price of approximately 67,880 USDT/BTC, a position of 0.023 BTC has a notional value of approximately:

text
0.023 BTC × 67,880 USDT/BTC ≈ 1,561 USDT

It is not approximately 157 USDT as stated. For a capital balance of 1,000 USDT, this would represent approximately 156% of capital and exceed both the stated 5% per-signal cap and the 250-USDT hard limit.

The risk manager may consequently mark an oversized recommendation as PASSED, undermining the primary safety control used by the advisory executor.

A

...[truncated 1673 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define and annotate the unit of every variable.

  2. For a linear spot-style calculation, calculate the base-asset quantity as:

    text
    stop_distance_usdt = abs(entry_price_usdt - stop_loss_price_usdt)
    risk_quantity_asset = risk_amount_usdt / stop_distance_usdt
    
  3. Calculate the resulting notional in the same currency as the limits:

    text
    risk_notional_usdt = risk_quantity_asset × entry_price_usdt
    maximum_notional_usdt = min(capital_usdt × 0.05, 250 USDT)
    final_notional_usdt = min(risk_notional_usdt, maximum_notional_usdt)
    final_quantity_asset = final_notional_usdt / entry_price_usdt
    
  4. Recalculate actual stop-loss risk after applying the notional cap and reject the signal if it exceeds 2% of capital.

  5. Validate that capital and prices are positive, entry and stop prices differ, and the stop is on the correct side for the trade direction.

  6. Reject non-finite, negative, zero-distance, stale, or excessive-precision inputs.

  7. Explicitly model the actual Event Contract payout and settlement mechanism rather than assuming a spot-position formula if those products have different payoff semantics.

  8. Correct the example arithmetic and ensure all displayed asset quantities and USDT notionals reconcile.

  9. Add unit-aware types or separate variable names such as _btc and _usdt.

  10. Add automated tests for long and short positions, minimum and maximum trade limits, zero stop distance, extreme prices, total exposure, and rounding boundaries.

  11. Require a fail-closed result whenever units are missing or calculations do not reconcile.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · binance-risk-manager/SKILL.md (reported line 59)May include surrounding context.

md
Daily P&L: -2.3% ← No warning ✓

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill declares automatic startup and continuous once-per-minute external API access, but does not present a clear user-facing warning or consent mechanism for persistent outbound network activity. In practice this can surprise users, create privacy/governance issues, and expose environments to unintended continuous communication with a third-party service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The installation command uses npx clawhub@latest, which pulls whatever package version is current at install time rather than a reviewed, immutable release. This creates a supply-chain risk: a compromised upstream package, malicious new release, or breaking change could be executed during installation with no version stability or integrity guarantee.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The installation command uses npx clawhub@latest, which pulls and executes the most recent package version at install time instead of a reviewed, immutable version. This creates a supply-chain risk: if the package is updated maliciously or a compromised release is published, users of the skill may execute untrusted code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The installation command uses npx clawhub@latest, which pulls and executes whatever package version is current at install time. This creates a supply-chain risk: a compromised publisher account, malicious new release, or breaking change could cause arbitrary code execution on the installer’s system. Because this is an install instruction in a skill file, readers may run it verbatim, increasing exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The installation command uses npx clawhub@latest, which fetches and executes the latest published package version at install time rather than a reviewed, fixed version. This creates a supply-chain risk: if the package is compromised or a breaking/malicious release is published later, users installing the skill could execute untrusted code on their system.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares an always-on trigger scope ('Active continuously' and validates every signal before execution), which can cause the skill to be invoked more broadly than necessary. In agent systems, overly broad activation increases the chance of unintended execution paths, noisy automation, or accidental interference with unrelated workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The installation command uses npx clawhub@latest, which fetches and executes whatever package version is current at install time. That creates a supply-chain risk: a compromised publisher account, malicious new release, or unexpected breaking change could cause arbitrary code execution during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The installation command uses npx clawhub@latest, which fetches and executes whatever package version is current at install time. This creates a supply-chain risk: a compromised upstream package, typo-squatted replacement, or malicious newly-published version could execute arbitrary code on the host during skill installation. The skill context increases risk because the command is presented as a normal setup step, making operator execution likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language rules require exclusive use of Binance official APIs and prohibit alternatives, which imposes a source/platform constraint on users. The file does not present this as an opt-in choice or explain a policy justification such as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example output includes the Chinese phrase "逆向吃到流动性" inside an otherwise English skill description and output format. This imposes a locale/language choice without any stated user opt-in or explanation, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.