Back to skill

Security audit

gate-exchange-activitycenter

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed, read-only Gate activity lookup skill, with routing wording that users should keep specific but no evidence of hidden or destructive behavior.

Install if you want Gate activity-center help and are comfortable granting read-only Gate activity access through your local MCP credentials. Use explicit prompts like 'my Gate activities' or 'Gate trading competitions' to avoid accidental routing from generic activity requests, and verify any campaign details in Gate before acting.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to cause the skill to activate on vague user requests such as general questions about activities, which can lead to unintended access to account-scoped activity data or unnecessary API calls. In a credentialed exchange context, overbroad routing increases the chance of the wrong skill handling a request and exposing links or account entry points the user did not explicitly request.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description advertises ambiguous invocation text that can match ordinary conversation, increasing accidental routing into a skill that uses authenticated exchange APIs. Because this skill can query personalized activity entry points, weak invocation boundaries raise the risk of privacy-impacting or confusing tool use in the wrong context.

Natural-Language Policy Violations

High
Confidence
94% confidence
Finding
Mandating translation of non-English user input to English before submitting search keywords can transform or leak user-provided text without consent, and may change semantic meaning for proper nouns or campaign names. In a financial-platform context, silent language conversion can produce incorrect results, mishandle localized activity names, and violate user expectations around data handling.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger examples are broad natural-language phrases like 'Recommend some activities' and 'What activities are available,' which can overlap with ordinary conversation and cause the skill to activate when the user did not specifically intend to invoke this activity-center workflow. In an agent setting, unintended invocation can leak behavioral context, trigger unnecessary backend queries, or route the user away from a more appropriate skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger example 'My activities' is especially ambiguous because it is short, generic, and likely to collide with unrelated product areas such as tasks, orders, subscriptions, or learning modules. In a multi-skill assistant, this raises the chance of misrouting and unauthorized or confusing retrieval of user-specific activity enrollment data.

Static analysis

No suspicious patterns detected.