T05 · Unauthorized Access and Privilege Escalation
- Location
references/mcp.md:20- Finding
Unnecessary Full-Account Balance Probe Exceeds Requested Scope
- Content
View full analysis
Vulnerability Details
File Location:
references/mcp.md, lines 20–24
Vulnerability Type: Excessive authenticated financial-data access
Risk Level: MediumVulnerable Code
markdown ## 2. MCP Detection and Fallback Detection: 1. Verify Gate MCP read tools are available (`cex_wallet_get_total_balance` + account-specific reads). 2. Probe with total balance endpoint.Technical Analysis
The MCP detection procedure mandates a call to
cex_wallet_get_total_balancebefore limiting collection to the scope requested by the user. This endpoint returns valuation information covering multiple Gate account systems.Consequently, a narrow request such as checking one currency in a spot account can cause the Skill to retrieve the user's broader account valuation. This contradicts the scope-first execution procedure at
references/mcp.md, lines 52–53, which requires identifying the requested account scope and fetching only the requested modules.Although the endpoint is read-only and uses the user's configured Gate MCP credentials, read-only financial records remain sensitive. Retrieving a complete balance when only a narrow balance is required violates data-minimization and least-privilege principles. The excessive response can enter the Agent context and may also be exposed to MCP, application, transcript, or telemetry logging.
No evidence indicates that this information is sent to an unrelated or attacker-controlled service. The security issue is excessive collection through the authenticated Gate integration rather than deliberate credential theft or third-party exfiltration.
Attack Path
- A user submits a narrow request, such as asking for the USDT balance in the spot account.
- The Skill begins the mandatory MCP detection procedure.
- The procedure invokes
cex_wallet_get_total_balanceinstead of checking availability without accessing account data or calling only the narrow endpoint.
...[truncated 1053 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the unconditional
cex_wallet_get_total_balanceprobe from MCP detection. - Detect tool availability through MCP capability discovery or tool metadata without invoking an authenticated account-data endpoint.
- Determine the user's requested account and currency scope before making any financial-data request.
- Call only the narrowest endpoint necessary. For example, use
cex_spot_get_spot_accountswith the requested currency for a spot-only query. - Use
cex_wallet_get_total_balanceonly when the user explicitly requests a total balance, account overview, or cross-account valuation. - If a live authenticated probe is technically unavoidable, use the narrowest endpoint relevant to the request and obtain explicit user consent before retrieving all-account data.
- Ensure MCP responses containing account information are excluded from unnecessary logs and telemetry, and redact them where retention is required.
- Add tests confirming that account-specific and currency-specific requests do not invoke the total-balance endpoint.
- Remove the unconditional
