T01 · Skill Instruction Hijacking
- Location
SKILL.md:15- Finding
Mutable Remote Instructions Are Granted Highest Priority
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This DEX trading skill has a real trading purpose, but it handles wallet keys, tokens, persistent agent routing, mutable remote rules, and transaction signing in ways that require careful review before installation.
Install only if you are comfortable with a skill that can influence future agent routing and participate in real on-chain transactions. Do not paste wallet private keys or let the agent read .env or keystore files; prefer an external wallet or hardware signer. Review and back up existing agent/MCP configs before running install.sh, and do not run any missing or separately downloaded check-in binary unless its source and hash are independently verified.
SKILL.md:15Mutable Remote Instructions Are Granted Highest Priority
install.sh:126Installer Overwrites Agent Configuration and Installs Persistent Routing Instructions
references/openapi/sign.md:139Signing Workflow Directs the Agent to Discover and Read Private-Key Files
references/mcp.md:327MCP Bearer Token Is Exposed Through Process Command-Line Arguments
tools/tx-checkin/README.md:1Security-Critical Check-In Executables Are Required but Absent and Unauditable
scripts/gate-api-call.py:36Hardcoded API Secret and Plaintext Long-Lived Credential Storage
references/openapi/sign.md:52Unpinned Third-Party Packages Execute in Private-Key Signing Processes
scripts/sign-tx-evm.py:65Opaque Server-Generated Transactions Are Signed Without Semantic Validation
scripts/check-allowance.py:33Caller-Controlled RPC URLs Enable Server-Side Request Forgery and Wallet Metadata Disclosure
scripts/check-allowance.py:76Floating-Point Token Conversion Can Produce Incorrect Allowance Decisions
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
- Unified `transport: "http"` configuration format
- Optimized token placeholder descriptions
- **Security Rules Enhancement**:
- Added proper authentication URL display rules
- Clarified multi-authentication method support policy
- Strengthened token confidentiality and desensitization display requirements
Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.
Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.
Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.
Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.
Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
- "what is the price of ETH" → `gate-dex-market` (read-only lookup, no trade intent)
- "check my swap history" → `gate-dex-wallet` (account query)
- "transfer ETH to 0xABC..." → `gate-dex-wallet` (direct transfer, not swap)
- "approve contract" (outside swap context) → `gate-dex-wallet` (DApp interaction)
---
Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.
echo -e "${CYAN}🤖 Configuring Claude Code (trading priority)...${NC}"
# Create project-level MCP config
cat > .mcp.json << 'EOF'
{
"mcpServers": {
"gate-dex": {
The instruction to display complete authentication URLs directly can facilitate prompt-injection or phishing propagation if the URL returned by the MCP server is compromised or insufficiently validated. Because the skill forbids sanitizing/decorating and frames the URL as authoritative login guidance, users may be nudged to trust and open malicious links.
- Google OAuth login (Google Device Flow)
- Gate OAuth login (Gate account system)
**Authentication URL Display Rules**:
- When MCP returns login authorization URL, display complete clickable link directly
- Do not add extra decorative symbols around URL (such as quotes, brackets, etc.)
- Do not escape URL content, ensure users see complete copyable links
The skill instructs the agent to execute a local OS-specific binary with transaction-preview JSON and then consume its output as a security-critical check-in token. That creates a code-execution and trust-boundary expansion far beyond normal documentation behavior: a compromised binary, path hijack, or tampered preview payload could exfiltrate sensitive material or authorize unintended transactions on the user's machine.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
Display prompt text, then use AskQuestion for user final confirmation:
Next step will involve contract authorization and transaction signing. This is necessary step for executing transaction.
The trigger metadata includes very broad terms like swap, exchange, buy, sell, quotes, gas price, order status, and configuration. Overbroad triggers can cause the skill to activate in ordinary conversation or in contexts where users did not intend a high-risk trading or secret-handling workflow.
The metadata and manifest text push broad activation, credential setup, signing, and transaction submission behaviors into a single skill, which is consistent with tool/skill poisoning risk. In combination with embedded secrets and secret-harvesting instructions, the manifest meaningfully increases the chance the agent routes sensitive requests into an overprivileged workflow.
---
name: gate-dex-trade-openapi
version: "2026.3.12-1"
updated: "2026-03-12"
description: "Gate DEX OpenTrade trading skill. Directly calls Gate DEX aggregated trading API via AK/SK authentication, centered on Swap, covering quotes, authorization, transaction building, signing, submission, and status queries. Supports EVM (Ethereum/BSC/Arbitrum/Base and 13 other chains), Solana, SUI, Tron, Ton. Triggered when users mention swap, exchange, buy, sell, DEX trading, OpenAPI, AK/SK, quotes, Gas price, order status, transaction history."
---
# Gate DEX OpenTrade
Gate DEX OpenTrade trading skill. Directly calls Gate DEX aggregated trading API via AK/SK authentication, cente
The intent table contains ambiguous phrases without sufficient constraints, causing likely overlap with harmless requests about markets, wallets, or configuration. In a skill that can write files, use credentials, and eventually request private keys, ambiguous routing materially increases risk.
The document instructs the agent to automatically create a persistent config file in the user's home directory containing hard-coded API credentials. Embedding default AK/SK in documentation is secret distribution and unauthorized credential provisioning, and automatic persistence makes the agent modify the host outside the workspace without explicit user consent.
The skill tells the agent to create a persistent credential file in the home directory automatically and populate it with credentials, without prior user approval. Silent host modification combined with secret persistence is dangerous because it alters the environment and may create long-lived access paths unknown to the user.
The documentation itself includes a full secret key immediately before saying it should never be displayed. Embedding real credentials in prompt or reference content is direct secret exposure and also risks prompt extraction leaking reusable credentials.
SK: COnwcshYA3EK4BjBWWrvwAqUXrvxgo0wGNvmoHk7rl4.6YLniz4h
### 3.3 Secure Display Rules
- **Never display complete SK in conversation**. Only show last 4 digits, format: `sk_****z4h`
- When user requests to view current configuration, AK can be fully displayed, SK must be masked
The skill directs the agent to solicit private keys directly from the user, ask for key file paths, and inspect .env or keystore files in the workspace. This gives the skill secret-harvesting capability far beyond its stated purpose and creates a direct path to exfiltration or misuse of wallet credentials.
Encouraging users to paste private keys into the conversation is an unsafe secret-collection pattern. Conversation channels are not appropriate for raw wallet secrets, and the warning provided is insufficient because it does not prefer safer alternatives such as hardware wallets or external signing.
The instructions explicitly tell the agent to solicit private keys and inspect key-bearing files in plain language. In the context of a transaction-executing skill, this is especially dangerous because possession of the private key enables direct irreversible asset theft, not merely account access.
The skill authorizes reading .env files and keystores to obtain private keys, but does not provide a strong, specific warning or require narrowly scoped consent for secret access. This normalizes credential scraping from the user's workspace and expands the agent from trader to secret extractor.
Instructing the agent to obtain a PRIVATE_KEY from a .env file is direct credential access to a highly sensitive secret. In this skill context, that access can immediately be used to sign transactions and drain assets.
Skill does not specify how Agent gets private keys. Agent handles flexibly based on context:
1. **Ask user to paste directly**: First display security notice from 9.1, clearly inform private key only used in local context, won't upload to any server, then wait for user to paste private key
2. **Ask user to provide file path**: Like keystore file, `PRIVATE_KEY` variable in .env file
3. **Read existing key files in user workspace**: If Agent finds .env or keystore files in context
Regardless of method, **do not retain or display private key content in conversation after signing completed**. If user pasted private key in conversation, prompt after signing completed: "Signing completed, recommend clearing private key messages in conversation history."
The instruction to read existing key files in the workspace if found is explicit secret discovery behavior. This transforms the skill into a credential-scavenging agent and is incompatible with least privilege.
1. **Ask user to paste directly**: First display security notice from 9.1, clearly inform private key only used in local context, won't upload to any server, then wait for user to paste private key
2. **Ask user to provide file path**: Like keystore file, `PRIVATE_KEY` variable in .env file
3. **Read existing key files in user workspace**: If Agent finds .env or keystore files in context
Regardless of method, **do not retain or display private key content in conversation after signing completed**. If user pasted private key in conversation, prompt after signing completed: "Signing completed, recommend clearing private key messages in conversation history."
The 'Display rules' reveal that the agent is expected to access, inspect, and partially disclose secret key material from the shared config. Even masked-secret handling can normalize secret retrieval in prompts and increases the risk of prompt-based secret extraction or accidental disclosure, particularly because this is a broadly loaded shared instruction file.
## Credential Management
- **Config path**: `~/.gate-dex-openapi/config.json` (shared across workspaces)
- **Display rules**: Never show complete SK. Mask as `sk_****z4h` (last 4 chars only)
- **Update flow**: Ask for new AK → Ask for new SK → Update config → Verify with `trade.swap.chain` → Rollback on failure
---
The instructions explicitly tell the agent to obtain private keys from file paths and existing workspace files, including likely secret stores such as .env files. This creates a direct credential-access pathway and materially increases the risk of secret exfiltration, accidental disclosure, or unauthorized signing.
No suspicious patterns detected.