Back to skill

Security audit

binance square 币安广场

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it tells the agent to save a Binance Square API key in the skill file while claiming secure storage without showing a secure mechanism.

Review this skill carefully before installing. Use only a narrowly scoped Binance Square posting key, avoid trading or withdrawal permissions, and do not paste a key unless you are comfortable with the agent potentially saving it in plaintext in the skill file. Rotate any key previously provided to this skill if it may have been stored or shared.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:124
Finding

Plaintext API Key Persistence in the Skill Definition

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 124-128
Vulnerability Type: Plaintext credential storage
Risk Level: Medium

Vulnerable Code

markdown
1. **Check key before API calls**: Verify that X-Square-OpenAPI-Key is configured and not the placeholder `your_api_key`
2. **Prompt for key if missing**: If key is not configured, ask user to provide their API Key first
3. **Prompt for content if missing**: If user triggers posting but doesn't provide specific content, ask what they want to post
4. **Never display full keys**: Only show first 5 + last 4 characters (e.g., `abc12...xyz9`)
5. **Store provided keys**: When user provides a new key, update the Accounts section in this file

The corresponding documentation in README.md, lines 50-56, and README.cn.md, lines 50-56, states that the key will be stored securely for future use, although no secure storage mechanism is defined.

Technical Analysis

The skill directs the agent to request an API key through the conversation and persist it by updating SKILL.md. This stores a sensitive credential in a plaintext project instruction file rather than an operating-system keychain, credential vault, or approved secret manager.

Masking a key when displaying it does not protect the plaintext value at rest. The project directory may be included in source-control commits, archives, backups, diagnostic bundles, or future agent context. The instruction also references an “Accounts section” that is absent from the reviewed file, leaving the storage format and access controls undefined.

The README claim that the key is stored securely is inconsistent with the implemented instruction and may cause users to provide credentials without understanding the storage risk.

Attack Path

  1. A user invokes the Square posting skill without a configured API key.
  2. The agent requests the user's X-Square-OpenAPI-Key.
  3. The user submits the credential ...[truncated 1415 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to write API keys into SKILL.md or any other project file.
  2. Store credentials in an operating-system keychain, an approved secret manager, or a platform-provided encrypted credential store.
  3. If environment variables are supported, store only the variable name in skill configuration and retrieve its value at runtime.
  4. Prevent secret values from appearing in conversation transcripts, application logs, telemetry, error messages, source-control history, and generated artifacts.
  5. Define an explicit account configuration schema that stores only non-sensitive metadata, such as account aliases and descriptions.
  6. Enforce least-privilege credentials dedicated exclusively to Binance Square posting where supported.
  7. Update both README files to accurately describe the credential-storage mechanism and provide key rotation and revocation instructions.
  8. If keys have already been written into project files, remove them from current files and repository history, rotate them immediately, and review account activity for unauthorized use.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to 'Store provided keys' by updating the Accounts section in the skill file encourages persistence of user API keys in a place that may be readable, logged, synced, or exposed to other users or operators. Even though the file says not to display full keys, persistence without a clear warning or secure secret-storage mechanism creates a significant credential-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly instructs users to provide an X-Square-OpenAPI-Key to the assistant and says the key will be stored, but it does not clearly explain the trust boundary, storage/security model, retention, or risks of sharing credentials with an AI-integrated tool. This can lead users to expose a credential that may enable posting actions and potentially broader account access if over-scoped, especially since the document itself mentions the need to minimize permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README tells users their X-Square-OpenAPI-Key will be 'stored securely for future use' but does not explain where it is stored, how it is protected, whether it is encrypted, or what scope of agent access it enables. In an agent skill context, vague credential-storage claims can cause users to hand over sensitive API keys without informed consent, increasing the risk of unintended retention, exposure, or reuse if the surrounding system is compromised or misconfigured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to post user-supplied content to Binance Square, a public external platform, but does not clearly warn that content will be transmitted off-platform and published publicly. This can cause accidental disclosure of sensitive or private information because users may trigger the skill without understanding the visibility and data-sharing implications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill explicitly sends content and an API key to an external Binance endpoint, which is expected for its function, but still represents real data exfiltration to a third party from the agent environment. In this context, the danger is heightened because the destination is a public posting API, so transmitted content may become publicly visible rather than merely processed privately.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Example Request

bash
curl -X POST 'https://www.binance.com/bapi/composite/v1/public/pgc/openApi/content/add' \
  -H 'X-Square-OpenAPI-Key: your_api_key' \
  -H 'Content-Type: application/json' \
  -H 'clienttype: binanceSkill' \

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The entire README is written in Chinese and all usage examples and interaction flows assume Chinese-language operation, but the document does not state that this is an optional localized version or provide user choice. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy issue unless the locale restriction is justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.