Back to skill

Security audit

Binance Onchain Pay

Security checks for vulnerabilities and agentic risk

Overview

The skill is for a real financial API workflow, but it asks agents to handle powerful crypto-payment credentials and execute high-impact transactions with weak scoping and storage safeguards.

Install only if you are comfortable letting an agent handle crypto-payment credentials and signed financial API requests. Use test credentials first, avoid saving secrets in .local.md, keep the PEM key outside shared or synced folders, verify the Base URL belongs to the intended service before any request, and manually confirm every amount, asset, network, destination address, and contract target before execution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:368
Finding

Plaintext Storage of API Credentials and Private-Key Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:103
Finding

API Key and Sensitive Transaction Data Exposed Through Command-Line Arguments

Content
View full analysis
/scripts/sign_and_call.sh \ "" \ "" \ "" \ "" \ "" \ '' ``` The complete pre-order example repeats this pattern: ```bash bash /path/to/scripts/sign_and_call.sh \ "https://api.commonservice.io" \ "papi/v1/ramp/connect/gray/buy/pre-order" \ "connect-gray" \ "your-api-key" \ "/path/to/private.pem" \ "{\"externalOrderId\":\"$ORDER_ID\",\"merchantCode\":\"connect-gray\",\"merchantName\":\"YourMerchant\",\"ts\":$TIMESTAMP,\"fiatCurrency\":\"USD\",\"requestedAmount\":100,\"cryptoCurrency\":\"BNB\",\"amountType\":1,\"address\":\"0x...\",\"network\":\"BSC\",\"payMethodCode\":\"BUY_CARD\"}" ``` The authentication reference also embeds the API key in a `curl` command-line argument: ```bash curl --location --request POST "https://api.commonservice.io/papi/v1/ramp/connect/buy/payment-method-list" \ --header "X-Tesla-ClientId: your-client-id" \ --header "X-Tesla-SignAccessToken: your-api-key" \ --header "X-Tesla-Signature: $signature" \ --header "X-Tesla-Timestamp: $timestamp" \ --header "Content-Type: application/json" \ --data-raw "$api_params" ``` ### Technical Analysis Process arguments are not an appropriate channel for secrets. Depending on the operating system, container runtime, audit configuration, orchestration platform, and agent tool implementation, command lines may be visible through process listings, process metadata, execution telemetry, crash reports, shell debugging, command history, or centralized logs. The exposed values include: ...[truncated 1951 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:94
Finding

Configurable Base URL Can Redirect Credentials to an Untrusted Service

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:103
Finding

Referenced Security-Critical Request Script Is Missing From the Package

Content
View full analysis
/scripts/sign_and_call.sh \ "" \ "" \ "" \ "" \ "" \ '' ``` ``` The supplied project structure contains only: ```text SKILL.md references/authentication.md ``` There is no `scripts/sign_and_call.sh` file in the audited artifact. ### Technical Analysis The skill claims that a bundled script performs the security-critical signing and network request workflow, but that script is absent. As a result, the documented execution path is incomplete and cannot operate as described without obtaining or creating an external replacement. The missing implementation prevents verification of essential controls, including: - Exact URL construction and normalization. - TLS certificate validation. - Redirect behavior. - Shell quoting and command-injection resistance. - Private-key permission checks. - Temporary-file handling. - Error-output redaction. - Response-size and content handling. - Whether secrets are logged. This is not evidence that malicious code exists. It is an integrity and auditability defect that may cause users or agents to substitute an unaudited script under the expected filename. ### Attack Path 1. The user installs the skill and attempts to execute the documented API workflow. 2. The referenced `scripts/sign_and_call.sh` is not present. 3. The user or agent searches for, downloads, generates, or accepts a replacement script from another source. 4. A malicious or insecure replacement is placed at the documented path. 5. The replacement receives the API key, PEM path, and transaction body through the documented positional arguments. 6. The replacement can read the private key, exfi ...[truncated 700 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill is designed to access high-value credentials: an API signing token and a PEM private key used to authorize financial API requests. Even if operationally necessary, instructing the agent to retrieve and use these secrets materially increases risk because compromise or misuse could enable unauthorized crypto purchase or transfer actions.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
- **BASE_URL**: API base URL
- **CLIENT_ID**: Client identifier
- **API_KEY**: The sign access token
- **PEM_PATH**: Absolute path to the RSA private key PEM file

Use the account marked `(default)` in `.local.md`.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 357)May include surrounding context.

md
## Security

### Credential Display Rules

- **API Key**: Show first 5 + last 4 characters only (e.g., `2zefb...06h`)
- **PEM Private Key**: NEVER display content. NEVER display the file path.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly supports fiat-to-crypto purchases and direct on-chain sends, both of which can be irreversible and high-risk if the user provides the wrong address, network, amount, or merchant parameters. Although the skill documents mechanics, it lacks a prominent step requiring explicit user confirmation and warning about irreversible transfers before initiating purchase or send flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs storing API credentials and the PEM private-key path in .local.md, which is plaintext configuration storage, but does not prominently warn users about the security risks of local plaintext secret storage. This increases the chance of credential exposure through backups, filesystem compromise, accidental sharing, or inclusion in version control.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/authentication.md (reported line 58)May include surrounding context.

md
| openssl dgst -sha256 -sign "test.pem" \
  | openssl enc -base64 -A)

curl --location --request POST "https://api.commonservice.io/papi/v1/ramp/connect/buy/payment-method-list" \
  --header "X-Tesla-ClientId: your-client-id" \
  --header "X-Tesla-SignAccessToken: your-api-key" \
  --header "X-Tesla-Signature: $signature" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/authentication.md (reported line 58)May include surrounding context.

md
| openssl dgst -sha256 -sign "test.pem" \
  | openssl enc -base64 -A)

curl --location --request POST "https://api.commonservice.io/papi/v1/ramp/connect/buy/payment-method-list" \
  --header "X-Tesla-ClientId: your-client-id" \
  --header "X-Tesla-SignAccessToken: your-api-key" \
  --header "X-Tesla-Signature: $signature" \

Static analysis

No suspicious patterns detected.