Back to skill

Security audit

Binance Trading Assistant

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Binance account-monitoring helper, but it handles high-value financial credentials while making misleading local-only safety claims and using an unpinned exchange dependency.

Review this before installing. Use a dedicated Binance API key with withdrawals disabled, read-only permissions where possible, and IP restrictions. Do not reuse exchange credentials, protect the local secrets file, and be aware that account balances and positions are sent to Binance through authenticated API calls and printed for the assistant to consume. Prefer a version with pinned dependencies and corrected safety documentation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
package.json:15
Finding

Unpinned Security-Sensitive Dependency Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: package.json, lines 15-17
Vulnerability Type: Unpinned third-party dependency without a committed lockfile
Risk Level: Medium

Vulnerable Code

json
"dependencies": {
  "ccxt": "^4.0.0"
}

Technical Analysis

The project permits npm to install any compatible ccxt 4.x release through the caret version range ^4.0.0. No package lockfile is present to pin the exact package and transitive dependency versions resolved during installation.

This dependency occupies a security-sensitive trust boundary. Both scripts provide ccxt with the user's Binance API key and secret and use it to process authenticated Binance requests and private financial account responses. Consequently, newly resolved dependency code executes with access to:

  • The Node.js process and its operating-system permissions.
  • Binance API credentials loaded from ~/.openclaw/secrets/binance.json.
  • Private balance, position, leverage, and profit-and-loss information.
  • Network access available to the process.

The audited project contains no evidence that the current dependency is malicious. The vulnerability is that future installations are not reproducible and may silently resolve to code that was not included in this audit. If an allowed future release or one of its transitive dependencies is compromised, it could misuse credentials or account data.

The documentation recommends read-only Binance keys, but the scripts cannot verify that the supplied keys are actually restricted. Therefore, the practical impact of a dependency compromise depends on the permissions configured for the user's Binance API key.

Attack Path

  1. An attacker compromises a future ccxt 4.x release, its publication account, or a transitive dependency.
  2. The malicious release remains semantically compatible with the declared ^4.0.0 version range.
  3. A user performs a fresh dependency installation, and npm resolves the compromised version because ...[truncated 1311 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the caret range with an exact, reviewed version:

    json
    "dependencies": {
      "ccxt": "4.x.y"
    }
    

    Substitute 4.x.y with a currently supported version that has been explicitly reviewed and tested.

  2. Generate and commit package-lock.json so that the complete transitive dependency graph and integrity hashes are reproducible.

  3. Use npm ci in installation and deployment workflows instead of unconstrained dependency resolution.

  4. Review lockfile changes as security-sensitive changes and require explicit approval before updating ccxt or its transitive dependencies.

  5. Run dependency auditing and provenance checks in continuous integration, including npm audit and package integrity verification.

  6. Require Binance API keys to be read-only and IP-restricted. Explicitly warn users not to enable trading or withdrawal permissions.

  7. Consider isolating these scripts in a restricted runtime with only the filesystem access needed to read the designated credential file and network access limited to official Binance API endpoints.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The safety claim is misleading because Binance API authentication necessarily sends signed requests derived from the API key and secret to Binance. Stating that keys are 'never transmitted' may cause users to underestimate data exposure and trust boundaries, which is especially risky for financial credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to configure Binance API credentials and emphasizes account monitoring, but it does not prominently warn about the sensitivity of exchange API keys, account balances, positions, and other financial data. In a crypto-trading context, insufficient disclosure can lead users to expose high-value credentials or connect accounts without understanding the privacy and financial risks, especially if keys are mis-scoped or reused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill handles sensitive financial account information, yet the description does not warn users that balances, positions, and portfolio data may be processed by the assistant and related tooling. Without an explicit privacy warning, users may disclose or connect highly sensitive account data without understanding the exposure risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The setup instructs users to persist long-lived Binance credentials in a local secrets file, which creates a standing target for theft by local malware, other users on the system, backups, or accidental exposure. Even read-only exchange keys can expose highly sensitive financial intelligence such as holdings, positions, and trading activity.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Setup

  1. Create Binance API keys (read-only recommended)
  2. Store credentials in ~/.openclaw/secrets/binance.json:
json
{

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/check_balance.js (reported line 16)May include surrounding context.

js
// Load credentials
    const secretsPath = path.join(process.env.HOME, '.openclaw/secrets/binance.json');
    if (!fs.existsSync(secretsPath)) {
      console.error('Error: Binance credentials not found. Please create ~/.openclaw/secrets/binance.json');
      process.exit(1);
    }

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README gives example phrases under 'Ask your assistant' but does not clearly state whether only these phrases activate the skill or what similar requests should not trigger it. This leaves the invocation boundary somewhat ambiguous for a skill that may respond to broad portfolio- and trading-related language.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The dependency version for ccxt is specified with a caret range (^4.0.0), which allows newer minor and patch releases to be installed automatically. This can introduce supply-chain risk or unexpected behavior if a future upstream release is compromised, vulnerable, or incompatible, which is especially sensitive in a finance and trading skill that may handle account data or trading actions.

Content

Scanner excerpt · package.json (reported line 16)May include surrounding context.

json
"keywords": ["binance", "trading", "crypto", "balance", "positions", "alerts"],
  "category": "finance",
  "dependencies": {
    "ccxt": "^4.0.0"
  },
  "scripts": {
    "check-balance": "node scripts/check_balance.js",

Static analysis

No suspicious patterns detected.