Back to skill

Security audit

ChoiGPT Binance Trading Bot

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Binance Futures auto-trading bot with unsafe live-trading defaults, weak Telegram access control, and under-disclosed sharing of account data with Google Gemini.

Review carefully before installing. Use only restricted, IP-limited Binance API keys without withdrawal permission, verify testnet or dry-run behavior before any live run, require an explicit Telegram chat allowlist, rotate/remove the embedded Gemini key, and assume balances, positions, chat history, and trade performance may be sent to Google unless the code is changed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/telegram_bot.py:151
Finding

Live Futures Trading Bypasses Configured Safety Controls

Content
View full analysis
= AUTO_TRADE_MIN_CONFIDENCE: self._execute_auto_trade(chat_id, symbol, analysis) def _execute_auto_trade(self, chat_id: int, symbol: str, analysis): """자동매매 실행 (V5.2.2)""" signal = analysis.signal with self.trade_lock: try: live_positions = self.fetcher.get_all_positions() if any(p['symbol'] == symbol for p in live_positions): return if len(live_positions) >= MAX_OPEN_POSITIONS: return self.fetcher.set_leverage(symbol, signal.leverage) self.fetcher.set_margin_type(symbol, 'ISOLATED') current_price = self.fetcher.get_price(symbol) quantity = self.fetcher.calculate_position_size( symbol, current_price, signal.stop_loss, signal.leverage ) quantity = self.fetcher._round_quantity(symbol, quantity) if quantity <= 0: return side = 'BUY' if signal.direction == 'LONG' else 'SELL' order = self.fetcher.place_limit_order_with_fallback( symbol, side, quantity, current_price ) ``` The corresponding configuration advertises safe defaults: ```python # config/config.py:56-58 AUTO_TRADE_ENABLED = os.getenv("AUTO_TRADE_ENABLED", "false").lower() == "true" DRY_RUN = os.getenv("DRY_RUN", "true").lower() == "true" ``` ### Technical Analysis The Telegram bot initializes its persistent state with automatic trading enabled. Its order-exe ...[truncated 2034 chars]
Remediation
View remediation
bool: return ( AUTO_TRADE_ENABLED and not DRY_RUN and self.state.auto_trade and USE_TESTNET is False ) ``` 3. Call the centralized guard immediately before every order, leverage change, cancellation, or position modification. 4. Refuse to start production trading unless the operator explicitly acknowledges live mode. 5. Require a separate confirmation step before the first live trade in each process lifetime. 6. Keep dry-run and live exchange clients separate so dry-run code cannot invoke authenticated order endpoints. 7. Add automated tests proving that no order method is called when either `AUTO_TRADE_ENABLED` is false or `DRY_RUN` is true. 8. Default to Binance testnet and require an explicit production-mode setting. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/telegram_bot.py:995
Finding

Binance Account and Position Data Is Disclosed to Google Gemini

Content
View full analysis
0 else 0 } for p in positions ], 'win_rate': ( self.state.winning_trades / self.state.total_trades * 100 ) if self.state.total_trades > 0 else 0, 'total_trades': self.state.total_trades, 'cycle_count': getattr(self.state, 'cycle_count', 0) } except Exception as context_err: logger.debug(f"AI 컨텍스트 수집 실패 (무시): {context_err}") response = generate_contextual_chat_response( text, chat_id, account_context=context ) ``` The account values are inserted into the prompt: ```python # src/ai_analyzer.py:239-265 today_pnl = account_context.get('today_pnl', 0) recent = account_context.get('recent_trades', []) ctx_lines.append(f"[실계좌 현황 - {datetime.now().strftime('%H:%M')} 기준]") ctx_lines.append(f"잔고: ${bal:.2f} USDT (가용: ${avail:.2f})") ctx_lines.append(f"오늘 손익: ${today_pnl:+.2f} USDT") ctx_lines.append(f"승률: {w ...[truncated 2502 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/ai_analyzer.py:49
Finding

Hard-Coded Google Gemini API Key in Source Code

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/telegram_bot.py:418
Finding

Empty Telegram Allowlist Fails Open and Grants Remote Account Control

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (86)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · src/telegram_bot.py (reported line 61)May include surrounding context.

python
� (로그용)
def strip_html(text: str) -> str:
    if not text: return ""
    return re.sub(r'<[^>]*>', '', text)

# ============================================================
# 텔레그램 API 래퍼 (raw requests)
# ============================================================

class TelegramAPI:
    def __init__(self, token: str):
        self.token = token
        self.base_url = f"https://api.telegram.org/bot{token}"

    def _post(self, method: str, data: dict = None, files: dict = None,
              timeout: int = 30) -> dict:
        url = f"{self.base_url}/{method}"
        try:
            if files:
                response = requests.post(url, data=data, files=files, timeout=timeout)
            else:
                response = requests.post(url, json=data, timeout=timeout)
            
            res_json = response.json()
            if not res_json.get('ok'):
                logger.error(f"텔레그램 API 응답 오류 ({method}): {res_json}")
            return res

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 2)May include surrounding context.

text
# 환경 설정
.env
.env.local
.env.*.local

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 3)May include surrounding context.

text
# 환경 설정
.env
.env.local
.env.*.local

# 민감한 파일

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config/config.py (reported line 4)May include surrounding context.

python
import os
from dotenv import load_dotenv

# .env 파일 로드 (config 디렉토리 내 .env 우선)
env_path = os.path.join(os.path.dirname(__file__), '.env')
if os.path.exists(env_path):
    load_dotenv(env_path, override=True)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docker-compose.yml (reported line 13)May include surrounding context.

yaml
import os
from dotenv import load_dotenv

# .env 파일 로드 (config 디렉토리 내 .env 우선)
env_path = os.path.join(os.path.dirname(__file__), '.env')
if os.path.exists(env_path):
    load_dotenv(env_path, override=True)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/ai_signal_parser.py (reported line 16)May include surrounding context.

python
import os
from dotenv import load_dotenv

# .env 파일 로드 (config 디렉토리 내 .env 우선)
env_path = os.path.join(os.path.dirname(__file__), '.env')
if os.path.exists(env_path):
    load_dotenv(env_path, override=True)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config/config.py (reported line 5)May include surrounding context.

python
from dotenv import load_dotenv

# .env 파일 로드 (config 디렉토리 내 .env 우선)
env_path = os.path.join(os.path.dirname(__file__), '.env')
if os.path.exists(env_path):
    load_dotenv(env_path, override=True)
else:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest explicitly describes an automated Binance futures trading bot, which can place leveraged trades with real financial consequences, but it does not disclose trading risk, live-order execution, or the possibility of loss. In the context of an agent skill, this omission is dangerous because a user may install or invoke it without understanding that it can trigger destructive real-money actions rather than merely provide analysis.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/dashboard.py (reported line 39)May include surrounding context.

python
def clear_screen(self):
        """터미널 화면 초기화"""
        os.system('clear' if os.name == 'posix' else 'cls')

    def display_header(self):
        """헤더 표시"""

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This function sends prior chat history plus injected system context to Gemini without any visible warning or consent handling. Because history may contain sensitive user statements and the system prompt may embed account-related context, the external transmission broadens confidentiality risk and increases the amount of sensitive data exposed to a third party. The skill context makes this more dangerous because it is a finance-oriented assistant handling potentially regulated or highly private trading information.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code packages sensitive account context such as balances, open positions, win rate, PnL, recent trades, and chat content into prompts sent to Gemini without any evidence of user notice, consent, or minimization. That creates a real privacy and confidentiality risk because a third-party AI provider receives financial and behavioral data that could be retained, logged, or exposed through provider-side compromise or policy changes. In a trading-bot skill, this is especially sensitive because the data reveals real account status and trading activity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module and class are presented as a data collection component, but the implementation includes live trading, leverage adjustment, margin-mode changes, and order cancellation. This mismatch is dangerous because a caller may supply API credentials expecting read-only market access while the code can execute state-changing account actions, increasing the risk of unintended trades or account modification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file contains broad live-trading capabilities such as placing market and limit orders, setting leverage and margin type, and canceling open and algo orders, yet no surrounding purpose, policy, or operator safeguards are defined. In the context of an agent skill, that creates a high-risk capability surface that could be invoked accidentally or by prompt abuse to cause financial loss on a real exchange account.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

Order placement and cancellation paths execute directly once called, with no explicit confirmation, dry-run mode, or user-visible warning. In an agent-integrated setting, that means a mistaken invocation, manipulated prompt, or ambiguous instruction can immediately submit or cancel live trades, causing direct financial impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file is a live trading bot that can place orders, cancel orders, alter leverage, and force-close positions against a real exchange account, yet there is no explicit runtime confirmation, interlock, or prominent warning before destructive actions begin. In a skill context, that is dangerous because accidental execution, misconfiguration, or misuse can directly cause real financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI defaults to --mode live, and the live branch immediately starts the trading bot without any explicit confirmation, dry-run gate, or environment safety check. In the context of an automated Binance futures trading bot, accidental execution can place real market orders and cause immediate financial loss, especially because the file itself advertises live trading as a standard mode.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code directly changes leverage and places live orders based on automated signals without any explicit user confirmation, approval workflow, or safety interlock at the point of execution. In a real trading bot, that creates material financial risk from bad signals, API misuse, logic errors, or compromised upstream components because funds can be committed immediately and repeatedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

A simple analysis request can directly trigger live order placement when auto-trade is enabled and model confidence passes the threshold, without a distinct confirmation step at the time of execution. In a Telegram bot handling natural-language messages, this is dangerous because ambiguous user prompts, misclassification, or model error can result in unintended leveraged trades on a real exchange account.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-trade toggle flips live trading state immediately on a single command, with no confirmation, second factor, or warning that subsequent analysis requests may execute real trades. Because this state change materially alters system behavior and financial risk, accidental or socially engineered use could enable autonomous order placement on a funded account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation explicitly instructs the agent/user to start live automated trading with real funds but does not place an immediate, explicit warning about irreversible financial loss, leverage risk, or the need for a safe default such as paper trading. In the context of an agent skill, this is more dangerous because the command is presented as a normal operational step and could be executed directly, leading to real-money trades without adequate human confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest requests highly sensitive credentials including Binance API/secret keys and Telegram bot credentials, but provides no explanation of how they are stored, used, or whether they are transmitted to third parties. This is risky because these secrets could enable unauthorized trading, account misuse, or outbound data exfiltration via Telegram, and users are not given enough information to assess that risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module title and descriptive text are written entirely in Korean, and the rest of the file continues with Korean user-facing strings and comments. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code file contains user-facing natural-language strings entirely in Korean, including the module description and all dashboard labels. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the tool is clearly documented as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The dashboard displays hard-coded healthy system states such as 'online', 'auto-trading active', and 'Telegram connected' without verifying the real runtime status. In an operational trading context, this can mislead operators into believing automation, connectivity, or monitoring is functioning when it is not, causing delayed response to outages or unsafe trading decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code defines the service description and later emits report text entirely in Korean, which constitutes a natural-language locale restriction. The file does not provide any user opt-in, configuration, or justification that this skill is intended only for Korean-speaking users or a Korea-specific deployment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.