T01 · Skill Instruction Hijacking
- Location
SKILL.md:12- Finding
Mutable Remote Instructions Are Assigned Highest Priority
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is for legitimate Gate crypto flash swaps, but it gives an agent high-impact financial authority with under-scoped confirmation rules, undeclared balance access, and mutable remote runtime instructions.
Review this before installing because it can place real cryptocurrency conversion orders using your Gate account. Only use it with narrowly scoped API keys and a client policy that requires explicit confirmation of the exact returned quote before every create call. The remote runtime-rules reference should be bundled or pinned before trusting the workflow.
SKILL.md:12Mutable Remote Instructions Are Assigned Highest Priority
SKILL.md:183One-Click Flow Executes a Financial Order Without Confirmation of the Actual Quote
Referenced artifact was not completely inspected
- `SKILL.md` keeps routing and scenario boundaries.
The documentation depends on an undeclared balance-access capability that is neither listed among allowed MCP tools nor justified by the skill's stated purpose. In an agent setting, this mismatch can cause tool-policy bypass pressure or accidental use of broader account-access tools, leading to unauthorized disclosure of sensitive financial holdings.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Added
- MCP Tool Inventory table in Domain Knowledge section listing all 9 tools with type and description
- Explicit "No write operations without confirmation" safety rule
- Stale confirmation handling rule (auto re-preview if quote_id > 5 min old)
### Fixed
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Many-to-one flash swap: preview via `cex_fc_preview_fc_multi_currency_many_to_one_order`, create via `cex_fc_create_fc_multi_currency_many_to_one_order`
- Quote expiry handling (code 1052) with auto-retry guidance
- Multi-currency failed item exclusion logic (prevent code 4 rejection)
- Safety rule: always preview before creating, never skip confirmation
- Warning for large swap amounts exceeding 10,000 USDT equivalent
- 5 comprehensive scenarios covering all swap modes and query operations
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
## General Rules
⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read [gate-runtime-rules.md](https://github.com/gate/gate-skills/blob/master/skills/gate-runtime-rules.md)
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
exist in the MCP server.
The trigger conditions include broad terms like 'swap', 'convert', and 'exchange', which can match common portfolio, pricing, or educational requests that do not clearly authorize trading behavior. Over-broad activation increases the chance that the skill takes control in ambiguous contexts and steers the agent toward account-linked financial operations the user did not intend.
The skill instructs the agent to query user spot balances for the many_to_one_all flow, but balance access is outside the documented flash-swap/order-history scope and is not declared in the tool inventory. This creates covert data-access expansion: an operator or model following the skill may reach for additional account-read capabilities and expose portfolio holdings without the user clearly consenting to a balance lookup.
The one_to_one_auto flow permits a write operation immediately after preview based on phrases like 'directly' or 'one-click', without a separate confirmation step showing the quoted terms. In a financial trading context, linguistic ambiguity, prompt injection, or user misunderstanding can lead to irreversible asset conversion without an explicit final approval tied to the actual quote.
- **NEVER fabricate results**: If any API call returns an error (code != 0), you MUST report the actual error to the user. NEVER fabricate a successful response, fake order ID, fake quote_id, or fake transaction result. This is the most critical safety rule
- **NEVER proceed after preview failure**: If the preview API returns any error (code != 0, including code -2 for region restriction), you MUST stop immediately. Do NOT call the create API. Do NOT invent a quote_id (e.g. "AUTO-GT-001"). Report the error honestly
- **Always preview before creating**: Every swap must go through the preview step first. For standard flows, show the quote to the user and wait for explicit confirmation before calling the create API. For `one_to_one_auto` mode only: the user has explicitly requested a direct swap (e.g. "directly swap", "one-click"), which counts as pre-authorized confirmation — proceed to create immediately after preview without a separate confirmation prompt
- **No write operations without confirmation**: Never call any create/order API unless (a) the user has explicitly confirmed the preview result, or (b) the user explicitly requested a one-click/direct swap. Query operations (list pairs, list orders, get order) do not require confirmation
- **Exclude failed preview items**: When creating multi-currency orders, only include items that succeeded in preview (`error.code == 0`)
- **Do not expose sensitive info**: Never output API Key, Secret, or authentication tokens
- **Display amounts as-is**: Do not round or modify amounts from API responses
The manifest describes a skill for instantly converting or exchanging cryptocurrencies, with examples centered on swap and convert intents. This file additionally documents querying the user's flash swap order history/details and, later, consolidating holdings by first querying spot balances, which goes beyond the narrow 'instant convert/exchange' scope described in the manifest.
The one-click flow explicitly performs preview and order creation back-to-back without a separate confirmation checkpoint. In a financial skill, immediate execution materially increases the chance of accidental trades, misunderstanding of quoted prices, or user harm from ambiguous prompts, especially if natural-language intent is misclassified.
The many-to-one consolidation flows substantially broaden the skill from simple pair conversion into portfolio-wide asset sweeping behavior. Because the manifest describes instant conversion requests, users may not expect automated balance discovery and bulk liquidation across holdings, which increases the risk of overbroad actions and unintended asset conversion.
The documentation instructs the agent to query spot account balances, which is more sensitive than the manifest's limited flash-swap description suggests. Accessing balances expands the data exposure surface and can reveal a user's portfolio composition even when they only asked for a swap, creating unnecessary privacy and authorization risk.
For markdown files, natural-language policy violations include forcing a specific language without user opt-in. The changelog entry at L102 says all documentation was converted to English, but this file does not indicate that users can choose another language or that the English-only constraint is justified by a documented regional or compliance need.
No suspicious patterns detected.