Back to skill

Security audit

Binance Skills

Security checks for vulnerabilities and agentic risk

Overview

This Binance skill is mostly purpose-aligned, but it gives an agent broad live financial authority with weak boundaries around signed requests, credentials, and installation provenance.

Install only if you intentionally want an agent to operate a Binance account. Use testnet or demo first, create least-privilege API keys, disable withdrawals unless absolutely needed, apply exchange-side IP restrictions, avoid passing secrets in command arguments, and require a fresh explicit confirmation for every trade, withdrawal, transfer, loan, staking, or account-permission change. Avoid arbitrary signed request URLs unless you have independently verified the destination is an intended Binance API endpoint.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:69
Finding

Arbitrary Signed Requests to User-Controlled URLs

Content
View full analysis
[--signed]`. Any Parameters can be added to the request (e.g: `--param1 value --param2 value`). ``` ### Technical Analysis The Skill permits the agent to submit a request to an arbitrary URL and optionally sign that request with the user's Binance credentials. The instruction does not restrict the URL to an approved Binance API hostname, require HTTPS, prohibit redirects, or exclude local and private-network addresses. If `binance-cli` attaches API authentication data or request signatures before validating the destination, an attacker-controlled URL could receive sensitive authentication metadata. Even when the secret key itself is not transmitted, signed request material and API identifiers may expose account information or facilitate replay attempts, depending on the CLI and server-side verification behavior. The generic request capability also exceeds the minimum privileges needed for the documented endpoint catalog because it creates a broad authenticated network-request primitive rather than limiting access to known Binance services. ### Attack Path 1. An attacker supplies a task or untrusted content containing a crafted external URL. 2. The requested operation is represented as an endpoint not listed in the Skill. 3. The agent follows the fallback instruction and invokes `binance-cli request` with the attacker-controlled URL and `--signed`. 4. The CLI sends the request, potentially including an API key, timestamp, signature, and user-supplied parameters. 5. The attacker-controlled server records the authentication metadata or manipulates redirects and responses to influence subsequent agent behavior. Actual credential exposure depends on how `binance-cli` validate ...[truncated 643 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/auth.md:14
Finding

Binance Credentials Passed Through Process Command-Line Arguments

Content
View full analysis
--api-key --api-secret --env ``` ### Technical Analysis The documented profile-creation command places the Binance API key and API secret or private key directly in the process argument vector. Command-line arguments may be exposed through shell history, process-monitoring tools, audit logs, terminal session capture, wrapper scripts, debugging output, or automation logs. The security rules later in `references/auth.md` prohibit echoing or logging raw credentials, but they do not prevent disclosure caused by argv-based secret transmission. If the shell records the generated command, the credentials can remain recoverable after execution. A Binance secret or private key is especially sensitive because the Skill supports authenticated financial operations, including trading, transfers, borrowing, repayment, gift-card operations, and account administration. ### Attack Path 1. The user provides Binance credentials to configure a profile. 2. The agent constructs the documented `binance-cli profile create` command with the credentials in command-line arguments. 3. The shell, process subsystem, terminal recorder, audit service, or automation platform records or exposes the command. 4. A local user, monitoring process, log reader, or later attacker retrieves the API key and secret. 5. The attacker uses the credentials through Binance APIs, subject to the permissions and network restrictions assigned to the key. ### Impact Assessment Exposure may permit unauthorized account queries, trading, order cancellation, transfers, gift-card actions, loan operations, or account configuration changes. The precise scope is controlled by the compromised key's Binance permissions, ...[truncated 228 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Global Installation of a Security-Sensitive npm Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 11)May include surrounding context.

md
### Added (7)

- `cancel-all-um-algo-open-orders` (`DELETE /papi/v1/um/algo/allOpenOrders`)
- `cancel-um-algo-order` (`DELETE /papi/v1/um/algo/order`)
- `futures-tradfi-perps-contract` (`POST /papi/v1/um/stock/contract`)
- `new-um-algo-order` (`POST /papi/v1/um/algo/order`)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 12)May include surrounding context.

md
### Added (7)

- `cancel-all-um-algo-open-orders` (`DELETE /papi/v1/um/algo/allOpenOrders`)
- `cancel-um-algo-order` (`DELETE /papi/v1/um/algo/order`)
- `futures-tradfi-perps-contract` (`POST /papi/v1/um/stock/contract`)
- `new-um-algo-order` (`POST /papi/v1/um/algo/order`)
- `query-all-current-um-open-algo-orders` (`GET /papi/v1/um/algo/openAlgoOrders`)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 23)May include surrounding context.

md
### Added (3)

- `delete-margin-call-level` (`DELETE /sapi/v1/portfolio/margin-call-level`)
- `get-margin-call-level` (`GET /sapi/v1/portfolio/margin-call-level`)
- `set-margin-call-level` (`POST /sapi/v1/portfolio/margin-call-level`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
| [`spot`](./references/spot.md) | Spot Trading |

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill exposes special API key management operations, including creation and IP editing for low-latency trading keys, which are sensitive credential-management capabilities. If invoked unintentionally or through prompt misuse, these functions could alter account access controls, enable unauthorized trading paths, or weaken operational security around exchange credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section documents high-risk fund-movement operations such as withdraw, broker-withdraw, and universal transfer without any user-facing warnings, confirmation guidance, or clear distinction from read-only calls. In an agent skill that can invoke authenticated Binance actions, this increases the chance of accidental or prompt-induced irreversible transfers of funds to attacker-controlled destinations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Travel Rule endpoints explicitly handle sensitive personal information fields such as originator-pii, beneficiary-pii, questionnaires, and signatures, but the documentation provides no privacy, retention, or handling warnings. In an authenticated agent context, that omission can lead to over-collection, unsafe logging, or unintended transmission of regulated personal and financial data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill instructs users to create and select Binance profiles using raw API keys and secrets, but it does not explicitly warn that these credentials may be stored locally by the CLI or explain the security consequences of doing so. In a financial trading context, unclear credential storage guidance increases the risk of accidental exposure, unsafe persistence, or use of production credentials without informed consent, which could lead to unauthorized trading or account access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This reference documents authenticated loan operations such as borrowing, repaying, and adjusting LTV without any warning that these actions can move funds, lock collateral, or trigger liquidation if used incorrectly. In an agent skill context, exposing high-impact finance actions as simple command references increases the chance that a user or downstream agent invokes them without understanding the financial risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents safety-critical actions such as kill-switch configuration and auto-cancel behavior, but it provides no warning that these endpoints can cancel open orders or materially affect active trading activity. Under the markdown-specific warning rule, descriptions that can affect user funds or system integrity should include a clear caution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file lists endpoints for cancelling all orders, cancelling specific orders, and placing new or multiple orders, but provides no accompanying warning that these are live trade actions affecting user positions and funds. For markdown skill documentation, potentially destructive or financially impactful behaviors should be explicitly disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This reference file documents multiple authenticated, account-affecting actions such as transfers, repayments, collections, and mode/status changes without any cautionary context, confirmation guidance, or indication of financial risk. In a trading/account-management skill, this increases the chance that an agent or user will invoke irreversible or costly operations without understanding the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This reference file exposes numerous authenticated, account- and trade-affecting operations such as placing orders, canceling orders, borrowing, repaying, transferring funds, and changing leverage or position mode, but provides no warning that these actions can cause immediate financial loss or irreversible account changes. In a trading skill that requires auth, omission of clear safety guidance increases the risk that an agent or user invokes destructive actions unintentionally or without adequate confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file documents authenticated trading endpoints that can change account state, including subscribing to products and changing auto-compound status, but it provides no warning that these operations place orders or modify positions on a real Binance account. In an agent-skill context, this omission is risky because an LLM-driven agent may invoke these actions without clearly surfacing the financial consequences or obtaining explicit user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file documents authenticated trade endpoints that can place, modify, or cancel orders and change leverage or margin settings, but it provides no warning that these actions are financially destructive or irreversible once sent. In an agent skill context, exposing such capabilities without cautionary guidance increases the chance that a user or downstream agent invokes high-risk actions unintentionally, causing unwanted trades, liquidation risk, or account configuration changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section documents authenticated futures trade endpoints that can place, modify, and cancel live orders, change leverage, alter margin mode, and otherwise affect real account positions without any explicit warning that these actions are state-changing and financially risky. In an agent skill context, presenting these operations alongside read-only endpoints without clear guardrails increases the chance of unintended execution, user misunderstanding, or prompt-driven misuse resulting in real financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation lists authenticated gift card creation and redemption endpoints that can directly trigger account-affecting financial actions, but it provides no warning that these operations may transfer value irreversibly or consume user balances. In an agent skill context, presenting such actions without explicit safety guidance increases the risk of accidental execution, social-engineering-driven misuse, or unsafe automation of sensitive operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The reference file documents margin-trading capabilities even though the manifest description only states Spot, Futures, Convert, and similar broad features without clearly disclosing Margin. This creates a scope mismatch that can mislead users or downstream policy systems about the real authority of the skill, increasing the chance of unintended high-risk financial actions being exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file lists destructive margin operations such as new margin orders, cancel-all actions, liquidation-related actions, and borrow/repay flows without warnings, safety notes, or confirmation requirements. In an authenticated trading skill, omission of cautionary guidance makes accidental or socially engineered execution of financially harmful actions more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation exposes authenticated fund-moving actions like redeem-bfusd and subscribe-bfusd without any warning that they change account balances or require explicit user confirmation. In an agent skill, this increases the chance that an automated workflow or a confused user triggers real financial transactions unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These endpoints include redemptions and persistent account-setting changes such as auto-subscribe and redeem options, but the reference provides no indication that they move funds or alter future account behavior. In an authenticated trading context, missing warnings make accidental execution materially more dangerous because changes can have immediate and ongoing financial effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The RWUSD subscribe and redeem commands are authenticated actions that can move user funds, yet they are presented the same way as harmless lookup commands. In a skill intended for agent use, that lack of distinction can mislead downstream systems or users into initiating unintended financial operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section documents authenticated trading and cancellation commands, including creating new orders and deleting open orders, but provides no warning that these actions can place real trades, cancel protective orders, or cause immediate financial loss. In a skill that requires Binance authentication, omission of safety guidance materially increases the risk of accidental destructive use by an agent or user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This documentation enumerates authenticated endpoints that can stake assets, redeem positions, wrap assets, and change account settings without any warning about irreversible or financially significant effects. In an agent skill context, exposing action-oriented commands without clear guardrails increases the chance that an automated agent or user invokes real-money operations unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This documentation enumerates authenticated endpoints that can move assets, transfer positions, change API-key IP restrictions, and enable trading capabilities for sub-accounts, but it provides no warning that these are financially sensitive and potentially irreversible operations. In an agent-skill context, exposing these actions without explicit confirmation, risk labeling, or safety guidance increases the chance that an LLM-driven agent or user will invoke them accidentally or with insufficient scrutiny.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.