T09 · Insecure Skill Coding Practices
- Location
SKILL.md:69- Finding
Arbitrary Signed Requests to User-Controlled URLs
- Content
View full analysis
[--signed]`. Any Parameters can be added to the request (e.g: `--param1 value --param2 value`). ``` ### Technical Analysis The Skill permits the agent to submit a request to an arbitrary URL and optionally sign that request with the user's Binance credentials. The instruction does not restrict the URL to an approved Binance API hostname, require HTTPS, prohibit redirects, or exclude local and private-network addresses. If `binance-cli` attaches API authentication data or request signatures before validating the destination, an attacker-controlled URL could receive sensitive authentication metadata. Even when the secret key itself is not transmitted, signed request material and API identifiers may expose account information or facilitate replay attempts, depending on the CLI and server-side verification behavior. The generic request capability also exceeds the minimum privileges needed for the documented endpoint catalog because it creates a broad authenticated network-request primitive rather than limiting access to known Binance services. ### Attack Path 1. An attacker supplies a task or untrusted content containing a crafted external URL. 2. The requested operation is represented as an endpoint not listed in the Skill. 3. The agent follows the fallback instruction and invokes `binance-cli request` with the attacker-controlled URL and `--signed`. 4. The CLI sends the request, potentially including an API key, timestamp, signature, and user-supplied parameters. 5. The attacker-controlled server records the authentication metadata or manipulates redirects and responses to influence subsequent agent behavior. Actual credential exposure depends on how `binance-cli` validate ...[truncated 643 chars]- Remediation
View remediation
