Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - `SKILL.md` keeps intent routing and rendering rules.
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed read-only Gate balance skill, but it can expose sensitive financial account data when used with configured Gate credentials.
Install this only if you want the agent to read your Gate exchange balances through a local MCP session. Use read-only Gate API keys, avoid enabling trading or transfer permissions for this skill, and be aware that broad requests like 'check my balance' may cause a Gate balance lookup unless the agent asks for clarification.
Referenced artifact was not completely inspected
- `SKILL.md` keeps intent routing and rendering rules.
The skill description embeds broad trigger phrases such as 'total assets' and 'my balance' that can match ordinary conversation without sufficient scoping to Gate accounts. In a financial skill that reads sensitive account balances via authenticated MCP tools, overbroad activation can cause unintended invocation and disclosure of private portfolio information.
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
## General Rules
⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read `./references/gate-runtime-rules.md`
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
exist in the MCP server.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Credentials Source: Local Gate MCP deployment (`GATE_API_KEY`, `GATE_API_SECRET`)
- API Key Required: Yes
- Permissions: Delivery:Read, Earn:Read, Fx:Read, Margin:Read, Options:Read, Spot:Read, Tradfi:Read, Unified:Read, Wallet:Read
- Never ask the user to paste secrets into chat; rely on the configured MCP session only.
- API Key Provisioning Reference: https://www.gate.com/myaccount/profile/api-key/manage (create or rotate keys outside the chat when the local MCP setup requires them).
### Installation Check
The case-routing table contains many underspecified trigger phrases like 'How much do I have' and 'Check my balance' that can overlap multiple intents and accounts. Because this skill has access to broad read permissions across spot, futures, margin, options, unified, and TradFi data, ambiguous routing increases the chance of unnecessary data access or exposing a broader financial picture than the user intended.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## 1. MCP Session and Authentication
- Use the already configured Gate MCP session for the current host.
- Local Gate MCP deployments use `GATE_API_KEY` and `GATE_API_SECRET`; never ask the user to paste these secrets into chat.
- Minimal permissions for this skill are `Delivery:Read`, `Earn:Read`, `Fx:Read`, `Margin:Read`, `Options:Read`, `Spot:Read`, `Tradfi:Read`, `Unified:Read`, and `Wallet:Read`.
- If the required Gate asset tools are missing, stop and switch to setup guidance only.
- If the MCP session returns an auth or permission error, stop and guide the user to repair the configured local MCP credentials before continuing.
The skill instructs responses to present update times in 'UTC+8', which imposes a locale-specific format on all users. This is a natural-language policy issue because no user opt-in or rationale is provided for why that timezone must be used.
No suspicious patterns detected.