Back to skill

Security audit

Gate Exchange Assets

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed read-only Gate balance skill, but it can expose sensitive financial account data when used with configured Gate credentials.

Install this only if you want the agent to read your Gate exchange balances through a local MCP session. Use read-only Gate API keys, avoid enabling trading or transfer permissions for this skill, and be aware that broad requests like 'check my balance' may cause a Gate balance lookup unless the agent asks for clarification.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
- `SKILL.md` keeps intent routing and rendering rules.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description embeds broad trigger phrases such as 'total assets' and 'my balance' that can match ordinary conversation without sufficient scoping to Gate accounts. In a financial skill that reads sensitive account balances via authenticated MCP tools, overbroad activation can cause unintended invocation and disclosure of private portfolio information.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
## General Rules

⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read `./references/gate-runtime-rules.md`
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
  exist in the MCP server.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
- Credentials Source: Local Gate MCP deployment (`GATE_API_KEY`, `GATE_API_SECRET`)
- API Key Required: Yes
- Permissions: Delivery:Read, Earn:Read, Fx:Read, Margin:Read, Options:Read, Spot:Read, Tradfi:Read, Unified:Read, Wallet:Read
- Never ask the user to paste secrets into chat; rely on the configured MCP session only.
- API Key Provisioning Reference: https://www.gate.com/myaccount/profile/api-key/manage (create or rotate keys outside the chat when the local MCP setup requires them).

### Installation Check

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The case-routing table contains many underspecified trigger phrases like 'How much do I have' and 'Check my balance' that can overlap multiple intents and accounts. Because this skill has access to broad read permissions across spot, futures, margin, options, unified, and TradFi data, ambiguous routing increases the chance of unnecessary data access or exposing a broader financial picture than the user intended.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/gate-runtime-rules.md (reported line 16)May include surrounding context.

md
## 1. MCP Session and Authentication

- Use the already configured Gate MCP session for the current host.
- Local Gate MCP deployments use `GATE_API_KEY` and `GATE_API_SECRET`; never ask the user to paste these secrets into chat.
- Minimal permissions for this skill are `Delivery:Read`, `Earn:Read`, `Fx:Read`, `Margin:Read`, `Options:Read`, `Spot:Read`, `Tradfi:Read`, `Unified:Read`, and `Wallet:Read`.
- If the required Gate asset tools are missing, stop and switch to setup guidance only.
- If the MCP session returns an auth or permission error, stop and guide the user to repair the configured local MCP credentials before continuing.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs responses to present update times in 'UTC+8', which imposes a locale-specific format on all users. This is a natural-language policy issue because no user opt-in or rationale is provided for why that timezone must be used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.