Back to skill

Security audit

Gate Exchange Assets

Security checks for vulnerabilities and agentic risk

Overview

This read-only Gate balance skill is mostly coherent, but it can access broad financial account data even for narrow or ambiguous balance requests.

Install only if you are comfortable giving this skill read access to Gate balances across spot, margin, futures, options, earn, TradFi, wallet, and related account areas. Prefer using tightly scoped read-only API keys, and be aware that ambiguous prompts like checking 'my balance' may trigger Gate account reads unless the agent asks for clarification.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/mcp.md:20
Finding

Unnecessary Full-Account Balance Probe Exceeds Requested Scope

Content
View full analysis

Vulnerability Details

File Location: references/mcp.md, lines 20–24
Vulnerability Type: Excessive authenticated financial-data access
Risk Level: Medium

Vulnerable Code

markdown
## 2. MCP Detection and Fallback

Detection:
1. Verify Gate MCP read tools are available (`cex_wallet_get_total_balance` + account-specific reads).
2. Probe with total balance endpoint.

Technical Analysis

The MCP detection procedure mandates a call to cex_wallet_get_total_balance before limiting collection to the scope requested by the user. This endpoint returns valuation information covering multiple Gate account systems.

Consequently, a narrow request such as checking one currency in a spot account can cause the Skill to retrieve the user's broader account valuation. This contradicts the scope-first execution procedure at references/mcp.md, lines 52–53, which requires identifying the requested account scope and fetching only the requested modules.

Although the endpoint is read-only and uses the user's configured Gate MCP credentials, read-only financial records remain sensitive. Retrieving a complete balance when only a narrow balance is required violates data-minimization and least-privilege principles. The excessive response can enter the Agent context and may also be exposed to MCP, application, transcript, or telemetry logging.

No evidence indicates that this information is sent to an unrelated or attacker-controlled service. The security issue is excessive collection through the authenticated Gate integration rather than deliberate credential theft or third-party exfiltration.

Attack Path

  1. A user submits a narrow request, such as asking for the USDT balance in the spot account.
  2. The Skill begins the mandatory MCP detection procedure.
  3. The procedure invokes cex_wallet_get_total_balance instead of checking availability without accessing account data or calling only the narrow endpoint.

...[truncated 1053 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the unconditional cex_wallet_get_total_balance probe from MCP detection.
  2. Detect tool availability through MCP capability discovery or tool metadata without invoking an authenticated account-data endpoint.
  3. Determine the user's requested account and currency scope before making any financial-data request.
  4. Call only the narrowest endpoint necessary. For example, use cex_spot_get_spot_accounts with the requested currency for a spot-only query.
  5. Use cex_wallet_get_total_balance only when the user explicitly requests a total balance, account overview, or cross-account valuation.
  6. If a live authenticated probe is technically unavoidable, use the narrowest endpoint relevant to the request and obtain explicit user consent before retrieving all-account data.
  7. Ensure MCP responses containing account information are excluded from unnecessary logs and telemetry, and redact them where retention is required.
  8. Add tests confirming that account-specific and currency-specific requests do not invoke the total-balance endpoint.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
- `SKILL.md` keeps intent routing and rendering rules.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description says the skill triggers on phrases like 'my balance' and 'total assets', which are generic expressions a user might use in many contexts. The file provides examples, but it does not give exclusion conditions or clear boundaries distinguishing Gate exchange balances from other financial, banking, or portfolio requests.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
## General Rules

⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read `./references/gate-runtime-rules.md`
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
  exist in the MCP server.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
- Credentials Source: Local Gate MCP deployment (`GATE_API_KEY`, `GATE_API_SECRET`)
- API Key Required: Yes
- Permissions: Delivery:Read, Earn:Read, Fx:Read, Margin:Read, Options:Read, Spot:Read, Tradfi:Read, Unified:Read, Wallet:Read
- Never ask the user to paste secrets into chat; rely on the configured MCP session only.
- API Key Provisioning Reference: https://www.gate.com/myaccount/profile/api-key/manage (create or rotate keys outside the chat when the local MCP setup requires them).

### Installation Check

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Phrases such as 'How much do I have', 'Check my balance', and similar variants are broad everyday requests that could refer to many unrelated accounts or products. The routing tables do not consistently require exchange-, account-, or Gate-specific qualifiers, increasing the chance of accidental activation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/gate-runtime-rules.md (reported line 16)May include surrounding context.

md
## 1. MCP Session and Authentication

- Use the already configured Gate MCP session for the current host.
- Local Gate MCP deployments use `GATE_API_KEY` and `GATE_API_SECRET`; never ask the user to paste these secrets into chat.
- Minimal permissions for this skill are `Delivery:Read`, `Earn:Read`, `Fx:Read`, `Margin:Read`, `Options:Read`, `Spot:Read`, `Tradfi:Read`, `Unified:Read`, and `Wallet:Read`.
- If the required Gate asset tools are missing, stop and switch to setup guidance only.
- If the MCP session returns an auth or permission error, stop and guide the user to repair the configured local MCP credentials before continuing.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The response templates hardcode timestamps as '(UTC+8)', which imposes a specific locale/timezone format on all users regardless of their preference or region. The file does not offer a user choice or explain that this timezone is mandatory for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.