Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - `SKILL.md` keeps routing and reporting policy.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a read-only Gate affiliate reporting assistant that uses disclosed Gate MCP credentials and scoped rebate tools to show partner commission, transaction, referral, and application data.
Install only if you intend the agent to access your Gate partner rebate data through a locally configured Gate MCP session. Use a key limited to Rebate:Read, be aware reports can include referral users, commissions, trading volume, fees, and application status, and double-check any query triggered only by the generic word "commission" or by relative dates interpreted in UTC+8.
Referenced artifact was not completely inspected
- `SKILL.md` keeps routing and reporting policy.
The trigger phrase 'commission' is overly broad and can cause this affiliate skill to activate for unrelated financial or employment questions. That misrouting can expose partner-only data paths or cause the agent to use affiliate tooling in contexts the user did not intend, increasing the risk of unintended data access or confusing disclosures.
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
## General Rules
⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read `./references/gate-runtime-rules.md`
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
exist in the MCP server.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Credentials Source: Local Gate MCP deployment (`GATE_API_KEY`, `GATE_API_SECRET`)
- API Key Required: Yes
- Permissions: Rebate:Read
- Never ask the user to paste secrets into chat; rely on the configured MCP session only.
- API Key Provisioning Reference: https://www.gate.com/myaccount/profile/api-key/manage (create or rotate keys outside the chat when the local MCP setup requires them).
### Installation Check
The instructions state that all query windows use the user's current calendar date in UTC+8, and later repeat that all relative time calculations must be based on UTC+8. This forces a specific locale/timezone policy on every user without opt-in or a clear region-specific justification.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## 1. MCP Session and Authentication
- Use the already configured Gate MCP session for the current host.
- Local Gate MCP deployments use `GATE_API_KEY` and `GATE_API_SECRET`; never ask the user to paste these secrets into chat.
- Minimal permission for this skill is `Rebate:Read`.
- If the required Gate rebate tools are missing, stop and switch to setup guidance only.
- If the MCP session returns an auth or permission error, stop and guide the user to repair the configured local MCP credentials before continuing.
No suspicious patterns detected.