Back to skill

Security audit

Gate DEX Trade

Security checks for vulnerabilities and agentic risk

Overview

This DEX trading skill has a real trading purpose, but it handles wallet keys, tokens, persistent agent routing, mutable remote rules, and transaction signing in ways that require careful review before installation.

Install only if you are comfortable with a skill that can influence future agent routing and participate in real on-chain transactions. Do not paste wallet private keys or let the agent read .env or keystore files; prefer an external wallet or hardware signer. Review and back up existing agent/MCP configs before running install.sh, and do not run any missing or separately downloaded check-in binary unless its source and hash are independently verified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (10)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:15
Finding

Mutable Remote Instructions Are Granted Highest Priority

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
install.sh:126
Finding

Installer Overwrites Agent Configuration and Installs Persistent Routing Instructions

Content
View full analysis
"$cursor_mcp_path" << 'EOF' { "mcpServers": { "gate-dex": { "transport": "http", "url": "https://api.gatemcp.ai/mcp/dex", "headers": { "Authorization": "Bearer " } } } } EOF ``` The installer also creates persistent agent instructions: ```bash cat > CLAUDE.md << 'EOF' # Gate DEX Trade Skills ... - Auto-fallback to OpenAPI mode when MCP Server unavailable ... Prioritize trading-related functions. Auto-guide to MCP login process or configure OpenAPI credentials when authentication needed. EOF ``` ```bash cat > AGENTS.md << 'EOF' # Gate DEX Trade Skills ... Prioritize trading-related functions. Auto-fallback to OpenAPI mode when MCP Server unavailable. EOF ``` ```bash cat > .cursor/rules/gate-dex-trade.md << 'EOF' # Gate DEX Trade Priority Routing When users mention the following keywords, prioritize trading-related functions: ... EOF ``` ### Technical Analysis The installer replaces Cursor’s entire MCP configuration instead of adding or merging only the `gate-dex` entry. A backup is created, but no merge, validation, restoration, or user confirmation is performed before replacement. It also writes `CLAUDE.md`, `AGENTS.md`, and Cursor rule files that affect how future agent sessions route user requests. These files persist after installation and prioritize this financial transaction Skill. When multiple supported platfo ...[truncated 1330 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/openapi/sign.md:139
Finding

Signing Workflow Directs the Agent to Discover and Read Private-Key Files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/mcp.md:327
Finding

MCP Bearer Token Is Exposed Through Process Command-Line Arguments

Content
View full analysis
' # Linux (same flags) ../tools/tx-checkin/swap-checkin-linux --preview-json '' ``` The documented concrete invocation confirms that the token is embedded in the argument: ```bash ./swap-checkin-mac --preview-json '{"mcp_token":"...","user_wallet":"0x123","chain":"ethereum","chain_category":"evm","checkin_message":"...","type":"swap"}' ``` ### Technical Analysis The complete preview object, including the MCP authentication token, is passed through `argv`. Process arguments can be exposed through process-listing tools, process-monitoring software, shell or agent command logs, audit systems, crash reports, and debugging telemetry. The token is not merely contextual metadata: the documentation states that it is used directly as the outbound `Authorization` header value. ### Attack Path 1. The agent requests `dex_tx_swap_checkin_preview`. 2. The MCP server returns the current session token in the preview. 3. The agent serializes the object into a command-line argument. 4. A local process, monitoring agent, log collector, or user cap ...[truncated 519 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
tools/tx-checkin/README.md:1
Finding

Security-Critical Check-In Executables Are Required but Absent and Unauditable

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gate-api-call.py:36
Finding

Hardcoded API Secret and Plaintext Long-Lived Credential Storage

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/openapi/sign.md:52
Finding

Unpinned Third-Party Packages Execute in Private-Key Signing Processes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sign-tx-evm.py:65
Finding

Opaque Server-Generated Transactions Are Signed Without Semantic Validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check-allowance.py:33
Finding

Caller-Controlled RPC URLs Enable Server-Side Request Forgery and Wallet Metadata Disclosure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check-allowance.py:76
Finding

Floating-Point Token Conversion Can Produce Incorrect Allowance Decisions

Content
View full analysis
= required_raw ``` ### Technical Analysis Token quantities are decimal fixed-point values and must not be converted through binary floating point. `float(amount_human)` can round values that cannot be represented exactly. The subsequent `int(...)` truncates the result rather than rejecting excess precision or applying a defined rounding rule. For sufficiently large or precision-sensitive values, `required_raw` can differ from the exact token-unit amount. The script can consequently classify an insufficient allowance as sufficient or request an incorrect approval amount. ### Attack Path 1. A user supplies a token amount with precision that cannot be represented exactly as a binary float. 2. The helper converts it using `float`. 3. Multiplication by `10 ** decimals` produces a rounded value. 4. `int` truncates the result. 5. The incorrect raw amount is compared with the on-chain allowance. 6. The workflow skips a required approval or unnecessarily requests another approval. ### Impact Assessment The likely consequences are transaction failure, incorrect approval behavior, wasted gas, or workflow inconsistency. In edge cases, an underestimated amount can cause the Skill to proceed under the false assumption that the allowance is adequate. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (100)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · CHANGELOG.md (reported line 106)May include surrounding context.

md
- Unified `transport: "http"` configuration format
  - Optimized token placeholder descriptions
- **Security Rules Enhancement**:
  - Added proper authentication URL display rules
  - Clarified multi-authentication method support policy
  - Strengthened token confidentiality and desensitization display requirements

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Documented capability to manage a private key, derive wallet addresses, and sign arbitrary Solana transactions is materially broader than executing a specific DEX swap workflow. This creates risk of arbitrary transaction signing, misuse of wallet identity, and user confusion about the real trust boundary of the skill.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
- "what is the price of ETH" → `gate-dex-market` (read-only lookup, no trade intent)
- "check my swap history" → `gate-dex-wallet` (account query)
- "transfer ETH to 0xABC..." → `gate-dex-wallet` (direct transfer, not swap)
- "approve contract" (outside swap context) → `gate-dex-wallet` (DApp interaction)

---

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · install.sh (reported line 188)May include surrounding context.

sh
echo -e "${CYAN}🤖 Configuring Claude Code (trading priority)...${NC}"
    
    # Create project-level MCP config
    cat > .mcp.json << 'EOF'
{
  "mcpServers": {
    "gate-dex": {

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

The instruction to display complete authentication URLs directly can facilitate prompt-injection or phishing propagation if the URL returned by the MCP server is compromised or insufficiently validated. Because the skill forbids sanitizing/decorating and frames the URL as authoritative login guidance, users may be nudged to trust and open malicious links.

Content

Scanner excerpt · references/mcp.md (reported line 29)May include surrounding context.

md
- Google OAuth login (Google Device Flow)
- Gate OAuth login (Gate account system)

**Authentication URL Display Rules**:
- When MCP returns login authorization URL, display complete clickable link directly
- Do not add extra decorative symbols around URL (such as quotes, brackets, etc.)
- Do not escape URL content, ensure users see complete copyable links

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to execute a local OS-specific binary with transaction-preview JSON and then consume its output as a security-critical check-in token. That creates a code-execution and trust-boundary expansion far beyond normal documentation behavior: a compromised binary, path hijack, or tampered preview payload could exfiltrate sensitive material or authorize unintended transactions on the user's machine.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/mcp.md (reported line 1014)May include surrounding context.

SOP Step 3: Signature Authorization Confirmation

Display prompt text, then use AskQuestion for user final confirmation:

text
Next step will involve contract authorization and transaction signing. This is necessary step for executing transaction.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger metadata includes very broad terms like swap, exchange, buy, sell, quotes, gas price, order status, and configuration. Overbroad triggers can cause the skill to activate in ordinary conversation or in contexts where users did not intend a high-risk trading or secret-handling workflow.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The metadata and manifest text push broad activation, credential setup, signing, and transaction submission behaviors into a single skill, which is consistent with tool/skill poisoning risk. In combination with embedded secrets and secret-harvesting instructions, the manifest meaningfully increases the chance the agent routes sensitive requests into an overprivileged workflow.

Content

Scanner excerpt · references/openapi.md (reported line 5)May include surrounding context.

md
---
name: gate-dex-trade-openapi
version: "2026.3.12-1"
updated: "2026-03-12"
description: "Gate DEX OpenTrade trading skill. Directly calls Gate DEX aggregated trading API via AK/SK authentication, centered on Swap, covering quotes, authorization, transaction building, signing, submission, and status queries. Supports EVM (Ethereum/BSC/Arbitrum/Base and 13 other chains), Solana, SUI, Tron, Ton. Triggered when users mention swap, exchange, buy, sell, DEX trading, OpenAPI, AK/SK, quotes, Gas price, order status, transaction history."
---

# Gate DEX OpenTrade

Gate DEX OpenTrade trading skill. Directly calls Gate DEX aggregated trading API via AK/SK authentication, cente

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The intent table contains ambiguous phrases without sufficient constraints, causing likely overlap with harmless requests about markets, wallets, or configuration. In a skill that can write files, use credentials, and eventually request private keys, ambiguous routing materially increases risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document instructs the agent to automatically create a persistent config file in the user's home directory containing hard-coded API credentials. Embedding default AK/SK in documentation is secret distribution and unauthorized credential provisioning, and automatic persistence makes the agent modify the host outside the workspace without explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill tells the agent to create a persistent credential file in the home directory automatically and populate it with credentials, without prior user approval. Silent host modification combined with secret persistence is dangerous because it alters the environment and may create long-lived access paths unknown to the user.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
99% confidence
Finding

The documentation itself includes a full secret key immediately before saying it should never be displayed. Embedding real credentials in prompt or reference content is direct secret exposure and also risks prompt extraction leaking reusable credentials.

Content

Scanner excerpt · references/openapi.md (reported line 111)May include surrounding context.

SK: COnwcshYA3EK4BjBWWrvwAqUXrvxgo0wGNvmoHk7rl4.6YLniz4h

text

### 3.3 Secure Display Rules

- **Never display complete SK in conversation**. Only show last 4 digits, format: `sk_****z4h`
- When user requests to view current configuration, AK can be fully displayed, SK must be masked

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs the agent to solicit private keys directly from the user, ask for key file paths, and inspect .env or keystore files in the workspace. This gives the skill secret-harvesting capability far beyond its stated purpose and creates a direct path to exfiltration or misuse of wallet credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Encouraging users to paste private keys into the conversation is an unsafe secret-collection pattern. Conversation channels are not appropriate for raw wallet secrets, and the warning provided is insufficient because it does not prefer safer alternatives such as hardware wallets or external signing.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions explicitly tell the agent to solicit private keys and inspect key-bearing files in plain language. In the context of a transaction-executing skill, this is especially dangerous because possession of the private key enables direct irreversible asset theft, not merely account access.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill authorizes reading .env files and keystores to obtain private keys, but does not provide a strong, specific warning or require narrowly scoped consent for secret access. This normalizes credential scraping from the user's workspace and expands the agent from trader to secret extractor.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Instructing the agent to obtain a PRIVATE_KEY from a .env file is direct credential access to a highly sensitive secret. In this skill context, that access can immediately be used to sign transactions and drain assets.

Content

Scanner excerpt · references/openapi.md (reported line 1032)May include surrounding context.

md
Skill does not specify how Agent gets private keys. Agent handles flexibly based on context:

1. **Ask user to paste directly**: First display security notice from 9.1, clearly inform private key only used in local context, won't upload to any server, then wait for user to paste private key
2. **Ask user to provide file path**: Like keystore file, `PRIVATE_KEY` variable in .env file
3. **Read existing key files in user workspace**: If Agent finds .env or keystore files in context

Regardless of method, **do not retain or display private key content in conversation after signing completed**. If user pasted private key in conversation, prompt after signing completed: "Signing completed, recommend clearing private key messages in conversation history."

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The instruction to read existing key files in the workspace if found is explicit secret discovery behavior. This transforms the skill into a credential-scavenging agent and is incompatible with least privilege.

Content

Scanner excerpt · references/openapi.md (reported line 1033)May include surrounding context.

md
1. **Ask user to paste directly**: First display security notice from 9.1, clearly inform private key only used in local context, won't upload to any server, then wait for user to paste private key
2. **Ask user to provide file path**: Like keystore file, `PRIVATE_KEY` variable in .env file
3. **Read existing key files in user workspace**: If Agent finds .env or keystore files in context

Regardless of method, **do not retain or display private key content in conversation after signing completed**. If user pasted private key in conversation, prompt after signing completed: "Signing completed, recommend clearing private key messages in conversation history."

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
91% confidence
Finding

The 'Display rules' reveal that the agent is expected to access, inspect, and partially disclose secret key material from the shared config. Even masked-secret handling can normalize secret retrieval in prompts and increases the risk of prompt-based secret extraction or accidental disclosure, particularly because this is a broadly loaded shared instruction file.

Content

Scanner excerpt · references/openapi/_shared.md (reported line 78)May include surrounding context.

md
## Credential Management

- **Config path**: `~/.gate-dex-openapi/config.json` (shared across workspaces)
- **Display rules**: Never show complete SK. Mask as `sk_****z4h` (last 4 chars only)
- **Update flow**: Ask for new AK → Ask for new SK → Update config → Verify with `trade.swap.chain` → Rollback on failure

---

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly tell the agent to obtain private keys from file paths and existing workspace files, including likely secret stores such as .env files. This creates a direct credential-access pathway and materially increases the risk of secret exfiltration, accidental disclosure, or unauthorized signing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.