Back to skill

Security audit

Binance Signal Engine

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only crypto market analysis helper that fetches public candle data and prints trading signals, with no evidence of hidden persistence, credential use, order placement, or data exfiltration.

Install in an isolated environment if possible, and consider pinning dependency versions before use. Treat outputs as decision support only: the skill can recommend entries, stops, and position sizes, but it does not place trades or access your exchange account.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Mutable and Unpinned Third-Party Dependencies Create a Supply-Chain Execution Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:12-15, README.md:50-62, references/guide.md:64-68
Vulnerability Type: Unpinned third-party dependencies and mutable installation sources
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:12-15:

yaml
install:
  - kind: uv
    package: ccxt pandas numpy ta
    label: "Install Python dependencies (ccxt, pandas, numpy, ta)"

README.md:50-62:

bash
npx clawhub@latest install binance-signal-engine
bash
# Clone into your OpenClaw skills directory
git clone https://github.com/eplt/binance-signal-engine.git \
  ~/.openclaw/skills/binance-signal-engine

# Install Python dependencies
pip install ccxt pandas numpy ta

references/guide.md:64-68:

bash
Install all dependencies with:

```bash
pip install ccxt pandas ta numpy
text

### Technical Analysis

The installation instructions do not pin exact versions or verify package integrity. The use of `@latest` expressly selects mutable code, while the Python installation commands resolve the newest compatible releases and transitive dependencies available at installation time.

Consequently, the code installed on a future date may differ from the code that was reviewed. Potential exploitation mechanisms include:

- Compromise of a legitimate package or publisher account.
- Publication of a malicious future dependency release.
- Registry or dependency-resolution manipulation.
- Malicious installation hooks in a source distribution.
- Compromise of the mutable ClawHub installer version selected by `@latest`.
- Changes to the default branch fetched by the unpinned Git clone command.

No evidence shows that the currently named dependencies are malicious. The vulnerability is the absence of reproducible version and integrity controls, which leaves installation behavior dependent on mutable third-party supply-chain state.

### Attack Path

1. An
...[truncated 1387 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct Python dependency to an exact reviewed version, for example:

    text
    ccxt==X.Y.Z
    pandas==X.Y.Z
    numpy==X.Y.Z
    ta==X.Y.Z
    
  2. Generate and commit a lockfile that also fixes all transitive dependency versions.

  3. Require cryptographic hashes for Python artifacts, such as a hash-locked requirements file installed with:

    bash
    pip install --require-hashes -r requirements.txt
    
  4. Replace npx clawhub@latest with an exact reviewed ClawHub CLI version.

  5. Pin manual Git installations to a reviewed release tag or commit hash rather than cloning a mutable default branch.

  6. Verify release signatures or checksums where supported and use only explicitly trusted package registries.

  7. Install dependencies in an isolated virtual environment with minimal filesystem and credential access.

  8. Establish a dependency-update process that includes changelog review, vulnerability scanning, integrity regeneration, and testing before advancing pinned versions.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub@latest install ..., which pulls and executes the latest remote package version at install time. This creates a supply-chain risk: if the package or one of its dependencies is compromised, users may execute attacker-controlled code during installation. The fact that this is an install command in documentation increases practical exploitability because users are likely to copy-paste it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says 'Just ask naturally' and lists broad phrases like 'Analyze BTC/USDT' and 'What's the signal on ETH?', which can overlap with ordinary conversation and make the skill easier to invoke unintentionally in agentic environments. In a trading-analysis skill, accidental invocation can cause the agent to fetch external market data, generate financial guidance, or steer user decisions without an explicit opt-in boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises many natural-language trigger phrases, including broad requests like 'crypto analysis' and 'multi-timeframe analysis', and explicitly notes it may be invoked automatically by the agent. This can cause unintended execution on loosely related user queries, leading to unnecessary external network requests and tool output being introduced into the conversation without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide says users can simply ask the agent "Analyze BTC/USDT" without documenting any narrower invocation boundary, command namespace, or exclusion conditions. While the symbol makes it somewhat domain-specific, the activation pattern is still broadly framed as a plain natural-language request and provides no negative examples or context limits to prevent unintended invocation in general crypto discussion.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/guide.md (reported line 691)May include surrounding context.

md
**Past performance is not indicative of future results.** Backtesting this system on historical data may show profitable results, but market conditions change. Strategies that worked in a trending bull market may fail in a choppy, ranging market.

**The support/resistance calculation is simplistic.** Rolling min/max captures obvious levels but misses volume-weighted zones, pivot point clusters, and multi-timeframe confluence. Professional traders typically layer multiple S/R methods. Consider these levels as a starting point, not gospel.

**The divergence detector is a simplified approximation.** It compares the current bar's price and RSI against the extreme point within a 20-bar window, rather than identifying discrete swing highs and swing lows. This catches prominent divergences effectively but may miss subtler patterns or occasionally flag coincidental alignments. For higher-confidence divergence signals, consider layering this with manual chart inspection.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/binance_signal_engine.py (reported line 174)May include surrounding context.

python
default_type = "future" if cfg.is_futures else "spot"
            exchange_kwargs["options"] = {"defaultType": default_type}

        self.exchange: ccxt.Exchange = getattr(ccxt, cfg.exchange_id)(exchange_kwargs)
        self.exchange.load_markets()
        self.max_retries = max_retries
        self.cfg = cfg

Static analysis

No suspicious patterns detected.