T09 · Insecure Skill Coding Practices
- Location
SKILL.md:173- Finding
Unsanitized Upstream API Error Disclosure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent for Gate dual investment, but it needs Review because it can place non-cancelable financial orders and has several under-scoped or inconsistent financial-safety instructions.
Review this carefully before installing. Use it only with a Gate MCP credential limited to the minimum Earn:Write scope you are comfortable with, and confirm every order detail yourself. Treat APY, minimum amount, guarantee wording, and raw error messages cautiously because the instructions contain inconsistencies that could produce misleading financial output.
SKILL.md:173Unsanitized Upstream API Error Disclosure
Referenced artifact was not completely inspected
- `SKILL.md` keeps routing and product semantics.
The manifest description includes many broad trigger phrases such as 'target price', 'buy-low', and 'sell-high' that can match ordinary financial discussion, not just explicit requests to use Gate dual-investment functionality. In a skill with Earn:Write capability, over-broad routing increases the chance the agent activates a trading workflow inappropriately and begins collecting account data or preparing an order flow when the user did not intend that action.
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
## General Rules
⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read `./references/gate-runtime-rules.md`
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
exist in the MCP server.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Credentials Source: Local Gate MCP deployment (`GATE_API_KEY`, `GATE_API_SECRET`)
- API Key Required: Yes
- Permissions: Earn:Write
- Never ask the user to paste secrets into chat; rely on the configured MCP session only.
- API Key Provisioning Reference: https://www.gate.com/myaccount/profile/api-key/manage (create or rotate keys outside the chat when the local MCP setup requires them).
### Installation Check
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- **APY sanity check (MANDATORY before responding)**: After formatting ALL APY values, scan every value in your output. Typical correct ranges after ×100: crypto sell-high plans → 10%–2000%; stablecoin buy-low plans → 5%–1800%. **If you see any APY displayed as 0.05%–20% (single or low-double digits), you almost certainly forgot to multiply by 100. STOP, go back, and recompute ALL APY values before responding.** For example, if a raw value is `19.9378`, the correct display is `1993.78%` — NOT `19.94%`.
- **No investment advice**: Do not recommend specific plans or predict prices. Present data and let the user decide.
- **Non-principal-protected**: Always clearly communicate that dual investment is NOT principal-protected and the user may receive a different currency.
- **Order placement confirmation**: Before calling `cex_earn_place_dual_order`, MUST show the user the full order details (plan, amount, target price, APY, settlement scenarios) and get **explicit user confirmation**. NEVER place an order without confirmation.
- **Sensitive data**: Never expose API keys, internal endpoint URLs, or raw error traces to the user.
## Error Handling
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## 1. MCP Session and Authentication
- Use the already configured Gate MCP session for the current host.
- Local Gate MCP deployments use `GATE_API_KEY` and `GATE_API_SECRET`; never ask the user to paste these secrets into chat.
- Minimal permission for this skill is `Earn:Write`.
- If the required Gate MCP tools are missing, stop write actions and switch to setup guidance only.
- If the MCP session returns an auth or permission error, stop write actions and guide the user to repair the configured local MCP credentials before continuing.
The instructions require converting user time references to Unix timestamps specifically in UTC+0 and state to always use UTC+0. This imposes a locale/timezone policy on all users and can conflict with user expectations when they ask for natural-language periods like 'last week' or 'yesterday' in their local timezone.
The scenario guide states that minimum investment amounts are not available via API, but later workflow sections instruct the skill to compare and display min_amount. This contradiction can cause the agent to fabricate unavailable values, mishandle eligibility checks, or give inconsistent financial guidance during order flows.
The prompt examples around order placement use broad phrases that can match everyday financial questions without enough dual-investment-specific scoping. That can trigger the skill in the wrong context, leading the agent to initiate high-risk product discussion or order workflows when the user may have meant a generic sell/buy request.
The settlement-record examples are underspecified and could overlap with general order-history or portfolio-history requests. In a financial account skill, ambiguous routing can cause the agent to fetch or summarize the wrong dataset, omit required time filtering, or reveal incomplete account information under the guise of a dual-order query.
These later scenarios explicitly require using and presenting min_amount, directly conflicting with earlier instructions that the API does not expose minimum investment amounts. In a trading context, this can produce incorrect eligibility decisions or misleading order advice, which is especially risky because users may act on the output to place financial products.
Prompts like 'What's my balance?' or similar broad asset-summary wording can collide with general account-balance intents and incorrectly route users into the dual-investment asset view. In this context, misrouting is risky because it may present incomplete or misleading financial holdings and could prompt follow-on actions based on partial account data.
The template states that dual investment is "interest-guaranteed," but the surrounding guidance only describes settlement outcomes and market risk; it does not establish any guarantee from the product or platform. In a financial skill, overstating guarantees can mislead users into believing returns are assured, distorting risk disclosure and potentially causing harmful financial decisions.
The reference section explicitly states there is no instrument_name field and instructs filtering by invest_currency or exercise_currency instead. The later report templates for product listing and settlement simulation use {instrument_name}, which contradicts the documented API schema and can mislead an agent into fabricating or expecting unavailable data.
The global formatting rules say timestamp fields must be omitted completely and specifically prohibit converting them to dates for user-facing output. Later, the product details workflow instructs the agent to present matching plan details including delivery date, which directly contradicts the earlier rule for timestamps.
No suspicious patterns detected.