Back to skill

Security audit

Gate Exchange Dual Investment

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Gate dual investment, but it needs Review because it can place non-cancelable financial orders and has several under-scoped or inconsistent financial-safety instructions.

Review this carefully before installing. Use it only with a Gate MCP credential limited to the minimum Earn:Write scope you are comfortable with, and confirm every order detail yourself. Treat APY, minimum amount, guarantee wording, and raw error messages cautiously because the instructions contain inconsistencies that could produce misleading financial output.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:173
Finding

Unsanitized Upstream API Error Disclosure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
- `SKILL.md` keeps routing and product semantics.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description includes many broad trigger phrases such as 'target price', 'buy-low', and 'sell-high' that can match ordinary financial discussion, not just explicit requests to use Gate dual-investment functionality. In a skill with Earn:Write capability, over-broad routing increases the chance the agent activates a trading workflow inappropriately and begins collecting account data or preparing an order flow when the user did not intend that action.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
## General Rules

⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read `./references/gate-runtime-rules.md`
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
  exist in the MCP server.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- Credentials Source: Local Gate MCP deployment (`GATE_API_KEY`, `GATE_API_SECRET`)
- API Key Required: Yes
- Permissions: Earn:Write
- Never ask the user to paste secrets into chat; rely on the configured MCP session only.
- API Key Provisioning Reference: https://www.gate.com/myaccount/profile/api-key/manage (create or rotate keys outside the chat when the local MCP setup requires them).

### Installation Check

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
- **APY sanity check (MANDATORY before responding)**: After formatting ALL APY values, scan every value in your output. Typical correct ranges after ×100: crypto sell-high plans → 10%–2000%; stablecoin buy-low plans → 5%–1800%. **If you see any APY displayed as 0.05%–20% (single or low-double digits), you almost certainly forgot to multiply by 100. STOP, go back, and recompute ALL APY values before responding.** For example, if a raw value is `19.9378`, the correct display is `1993.78%` — NOT `19.94%`.
- **No investment advice**: Do not recommend specific plans or predict prices. Present data and let the user decide.
- **Non-principal-protected**: Always clearly communicate that dual investment is NOT principal-protected and the user may receive a different currency.
- **Order placement confirmation**: Before calling `cex_earn_place_dual_order`, MUST show the user the full order details (plan, amount, target price, APY, settlement scenarios) and get **explicit user confirmation**. NEVER place an order without confirmation.
- **Sensitive data**: Never expose API keys, internal endpoint URLs, or raw error traces to the user.

## Error Handling

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/gate-runtime-rules.md (reported line 16)May include surrounding context.

md
## 1. MCP Session and Authentication

- Use the already configured Gate MCP session for the current host.
- Local Gate MCP deployments use `GATE_API_KEY` and `GATE_API_SECRET`; never ask the user to paste these secrets into chat.
- Minimal permission for this skill is `Earn:Write`.
- If the required Gate MCP tools are missing, stop write actions and switch to setup guidance only.
- If the MCP session returns an auth or permission error, stop write actions and guide the user to repair the configured local MCP credentials before continuing.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions require converting user time references to Unix timestamps specifically in UTC+0 and state to always use UTC+0. This imposes a locale/timezone policy on all users and can conflict with user expectations when they ask for natural-language periods like 'last week' or 'yesterday' in their local timezone.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The scenario guide states that minimum investment amounts are not available via API, but later workflow sections instruct the skill to compare and display min_amount. This contradiction can cause the agent to fabricate unavailable values, mishandle eligibility checks, or give inconsistent financial guidance during order flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The prompt examples around order placement use broad phrases that can match everyday financial questions without enough dual-investment-specific scoping. That can trigger the skill in the wrong context, leading the agent to initiate high-risk product discussion or order workflows when the user may have meant a generic sell/buy request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The settlement-record examples are underspecified and could overlap with general order-history or portfolio-history requests. In a financial account skill, ambiguous routing can cause the agent to fetch or summarize the wrong dataset, omit required time filtering, or reveal incomplete account information under the guise of a dual-order query.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

These later scenarios explicitly require using and presenting min_amount, directly conflicting with earlier instructions that the API does not expose minimum investment amounts. In a trading context, this can produce incorrect eligibility decisions or misleading order advice, which is especially risky because users may act on the output to place financial products.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Prompts like 'What's my balance?' or similar broad asset-summary wording can collide with general account-balance intents and incorrectly route users into the dual-investment asset view. In this context, misrouting is risky because it may present incomplete or misleading financial holdings and could prompt follow-on actions based on partial account data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template states that dual investment is "interest-guaranteed," but the surrounding guidance only describes settlement outcomes and market risk; it does not establish any guarantee from the product or platform. In a financial skill, overstating guarantees can mislead users into believing returns are assured, distorting risk disclosure and potentially causing harmful financial decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

The reference section explicitly states there is no instrument_name field and instructs filtering by invest_currency or exercise_currency instead. The later report templates for product listing and settlement simulation use {instrument_name}, which contradicts the documented API schema and can mislead an agent into fabricating or expecting unavailable data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The global formatting rules say timestamp fields must be omitted completely and specifically prohibit converting them to dates for user-facing output. Later, the product details workflow instructs the agent to present matching plan details including delivery date, which directly contradicts the earlier rule for timestamps.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.