Back to skill

Security audit

Gate Flash Swap Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is for legitimate Gate crypto flash swaps, but it gives an agent high-impact financial authority with under-scoped confirmation rules, undeclared balance access, and mutable remote runtime instructions.

Review this before installing because it can place real cryptocurrency conversion orders using your Gate account. Only use it with narrowly scoped API keys and a client policy that requires explicit confirmation of the exact returned quote before every create call. The remote runtime-rules reference should be bundled or pinned before trusting the workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:12
Finding

Mutable Remote Instructions Are Assigned Highest Priority

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:183
Finding

One-Click Flow Executes a Financial Order Without Confirmation of the Actual Quote

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
- `SKILL.md` keeps routing and scenario boundaries.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation depends on an undeclared balance-access capability that is neither listed among allowed MCP tools nor justified by the skill's stated purpose. In an agent setting, this mismatch can cause tool-policy bypass pressure or accidental use of broader account-access tools, leading to unauthorized disclosure of sensitive financial holdings.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CHANGELOG.md (reported line 29)May include surrounding context.

md
### Added
- MCP Tool Inventory table in Domain Knowledge section listing all 9 tools with type and description
- Explicit "No write operations without confirmation" safety rule
- Stale confirmation handling rule (auto re-preview if quote_id > 5 min old)

### Fixed

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CHANGELOG.md (reported line 66)May include surrounding context.

md
- Many-to-one flash swap: preview via `cex_fc_preview_fc_multi_currency_many_to_one_order`, create via `cex_fc_create_fc_multi_currency_many_to_one_order`
- Quote expiry handling (code 1052) with auto-retry guidance
- Multi-currency failed item exclusion logic (prevent code 4 rejection)
- Safety rule: always preview before creating, never skip confirmation
- Warning for large swap amounts exceeding 10,000 USDT equivalent
- 5 comprehensive scenarios covering all swap modes and query operations

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## General Rules

⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read [gate-runtime-rules.md](https://github.com/gate/gate-skills/blob/master/skills/gate-runtime-rules.md)
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
  exist in the MCP server.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions include broad terms like 'swap', 'convert', and 'exchange', which can match common portfolio, pricing, or educational requests that do not clearly authorize trading behavior. Over-broad activation increases the chance that the skill takes control in ambiguous contexts and steers the agent toward account-linked financial operations the user did not intend.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to query user spot balances for the many_to_one_all flow, but balance access is outside the documented flash-swap/order-history scope and is not declared in the tool inventory. This creates covert data-access expansion: an operator or model following the skill may reach for additional account-read capabilities and expose portfolio holdings without the user clearly consenting to a balance lookup.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The one_to_one_auto flow permits a write operation immediately after preview based on phrases like 'directly' or 'one-click', without a separate confirmation step showing the quoted terms. In a financial trading context, linguistic ambiguity, prompt injection, or user misunderstanding can lead to irreversible asset conversion without an explicit final approval tied to the actual quote.

Content

Scanner excerpt · SKILL.md (reported line 359)May include surrounding context.

md
- **NEVER fabricate results**: If any API call returns an error (code != 0), you MUST report the actual error to the user. NEVER fabricate a successful response, fake order ID, fake quote_id, or fake transaction result. This is the most critical safety rule
- **NEVER proceed after preview failure**: If the preview API returns any error (code != 0, including code -2 for region restriction), you MUST stop immediately. Do NOT call the create API. Do NOT invent a quote_id (e.g. "AUTO-GT-001"). Report the error honestly
- **Always preview before creating**: Every swap must go through the preview step first. For standard flows, show the quote to the user and wait for explicit confirmation before calling the create API. For `one_to_one_auto` mode only: the user has explicitly requested a direct swap (e.g. "directly swap", "one-click"), which counts as pre-authorized confirmation — proceed to create immediately after preview without a separate confirmation prompt
- **No write operations without confirmation**: Never call any create/order API unless (a) the user has explicitly confirmed the preview result, or (b) the user explicitly requested a one-click/direct swap. Query operations (list pairs, list orders, get order) do not require confirmation
- **Exclude failed preview items**: When creating multi-currency orders, only include items that succeeded in preview (`error.code == 0`)
- **Do not expose sensitive info**: Never output API Key, Secret, or authentication tokens
- **Display amounts as-is**: Do not round or modify amounts from API responses

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill for instantly converting or exchanging cryptocurrencies, with examples centered on swap and convert intents. This file additionally documents querying the user's flash swap order history/details and, later, consolidating holdings by first querying spot balances, which goes beyond the narrow 'instant convert/exchange' scope described in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The one-click flow explicitly performs preview and order creation back-to-back without a separate confirmation checkpoint. In a financial skill, immediate execution materially increases the chance of accidental trades, misunderstanding of quoted prices, or user harm from ambiguous prompts, especially if natural-language intent is misclassified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The many-to-one consolidation flows substantially broaden the skill from simple pair conversion into portfolio-wide asset sweeping behavior. Because the manifest describes instant conversion requests, users may not expect automated balance discovery and bulk liquidation across holdings, which increases the risk of overbroad actions and unintended asset conversion.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs the agent to query spot account balances, which is more sensitive than the manifest's limited flash-swap description suggests. Accessing balances expands the data exposure surface and can reveal a user's portfolio composition even when they only asked for a swap, creating unnecessary privacy and authorization risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

For markdown files, natural-language policy violations include forcing a specific language without user opt-in. The changelog entry at L102 says all documentation was converted to English, but this file does not indicate that users can choose another language or that the English-only constraint is justified by a documented regional or compliance need.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.