Back to skill

Security audit

Gate Exchange MarketAnalysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly read-only market analysis, but it should be reviewed because it relies on mutable remote instructions and expands into trading and portfolio advice with weak credential guidance.

Review this before installing. Treat its outputs as market information, not personalized financial advice; do not let it place trades. Do not paste API keys into chat; configure only least-privilege, read-only credentials through the MCP server's secure settings. Prefer a version that bundles or pins the runtime rules instead of loading mutable instructions from GitHub master.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:12
Finding

Mutable External Instructions Are Assigned Highest Priority

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12–16
Vulnerability Type: Instruction hijacking through mutable remote policy content
Risk Level: High

Vulnerable Code

markdown
⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read [gate-runtime-rules.md](https://github.com/gate/gate-skills/blob/master/skills/gate-runtime-rules.md)
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
  exist in the MCP server.

Technical Analysis

The Skill instructs the Agent to retrieve a policy document from an external GitHub master branch and treat that document as having the “highest priority.” The referenced content is not bundled with the audited artifact and is not pinned to a commit or cryptographic digest.

Consequently, the effective Skill instructions can change after review without any modification to the audited package. If the upstream repository, publisher account, or referenced file is compromised or changed maliciously, new instructions could attempt to alter the Agent’s current objectives, weaken safety constraints, redirect tool calls, or induce unauthorized disclosure.

The issue is instruction hijacking rather than remote code execution: the artifact instructs the Agent to consume mutable remote text as authoritative policy, but no local execution of downloaded code was identified.

Attack Path

  1. A user or runtime loads this Skill for market analysis.
  2. The Agent processes SKILL.md:12-14.
  3. Before selecting a tool, the Agent retrieves gate-runtime-rules.md from the mutable master branch.
  4. The Agent treats the retrieved content as having the “highest priority.”
  5. An attacker who controls or compromises the remote content inserts instructions that redirect the current session, weaken safeguards, request ...[truncated 810 chars]
Remediation
View remediation

Remediation Suggestions

  1. Bundle the runtime rules inside the reviewed Skill package instead of retrieving them from a mutable external branch.
  2. If remote retrieval is unavoidable, pin the reference to an immutable commit and verify a trusted cryptographic digest before use.
  3. Remove the assertion that external Skill content has the “highest priority.” Explicitly state that system, developer, user, and runtime security policies remain authoritative.
  4. Treat remotely retrieved documents as untrusted data unless they pass authenticity, integrity, and policy validation.
  5. Restrict the Skill through runtime-enforced MCP allowlists rather than relying solely on natural-language restrictions.
  6. Include the pinned runtime-rules file in future security reviews and release artifacts.

T09 · Insecure Skill Coding Practices

Warning
Location
references/mcp.md:33
Finding

Skill May Solicit an API Key Through an Unspecified Channel

Content
View full analysis

Vulnerability Details

File Location: references/mcp.md, lines 33–35
Vulnerability Type: Insecure credential collection guidance
Risk Level: Medium

Vulnerable Code

markdown
## 3. Authentication

- Public market-data endpoints may work without private account auth.
- If runtime policy requires API key, request valid key before analysis.

Technical Analysis

The instruction tells the Agent to request a valid API key but does not require use of a secure secret-entry mechanism or prohibit users from pasting credentials into the conversation. API keys entered through chat may be retained in conversation history, logs, traces, monitoring systems, or other channels that are inappropriate for secret material.

This instruction also conflicts with the project’s security and authentication statements in README.md, which say that credentials are managed by the MCP platform layer and should be configured in MCP server settings. The inconsistency increases the chance that an Agent will solicit the credential directly rather than direct the user to secure configuration.

No hardcoded credential, credential storage implementation, or credential-exfiltration logic was found in the supplied artifact.

Attack Path

  1. The Skill attempts to use a deployment in which the MCP layer requires authentication.
  2. The runtime indicates that an API key is missing.
  3. Following references/mcp.md:35, the Agent asks the user to provide a valid key.
  4. Because no secure channel is mandated, the user pastes the key into the conversation.
  5. The credential becomes available to systems that process or retain chat content, including logs or tracing infrastructure.
  6. Anyone with unauthorized access to those records could misuse the key according to the permissions assigned to it.

Impact Assessment

Exposure is limited to credentials voluntarily supplied in response to the insecure prompt. The resulting privilege level equals the permissions granted t ...[truncated 425 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace “request valid key” with instructions directing users to configure credentials exclusively through the MCP server’s secure secret store or platform settings.
  2. Explicitly state that users must never paste API keys, secrets, private keys, or authentication tokens into chat.
  3. Require least-privilege, read-only API keys when authentication is genuinely necessary.
  4. Recommend exchange-side restrictions such as disabling withdrawal and trading permissions, enabling IP allowlisting, and rotating any credential accidentally disclosed.
  5. Align references/mcp.md with README.md so all documentation consistently states that the Skill does not collect or handle credential values.
  6. If authentication is unavailable, fail safely and provide configuration guidance without soliciting secret material.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (23)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
- `SKILL.md` keeps intent routing, scenario mapping, and output semantics.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

These modules explicitly include 'what to do' and allocation/advice behavior, pushing the agent beyond neutral market analysis into personalized investment recommendation. In a financial context, that creates compliance, suitability, and user-harm risk, especially if users rely on the output for trading decisions without proper licensing, risk profiling, or jurisdictional controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The routing rules directly instruct the model to answer prompts like 'long or short' and to provide allocation advice, which operationalizes explicit trading recommendations. This is dangerous because it encourages decisive financial guidance from a tool framed as analysis, increasing legal exposure and the chance of harmful or unsuitable recommendations to end users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The note that all trigger phrases and report templates are in English imposes a language constraint in natural language without mentioning user opt-in or a documented locale justification. This may violate language/locale policy because it appears to force a specific language regardless of user preference.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Because this is a markdown file, vague-trigger review applies. The listed activation examples include broad phrases such as "Recent liquidations?", "Any arbitrage opportunities?", and "Explain the order book," which lack clear scope constraints and could match casual discussion rather than an intentional invocation of this specific skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The phrase "Ask about liquidity, momentum, liquidation, arbitrage, basis, manipulation risk, order book, slippage simulation, K-line breakout/support–resistance, or liquidity vs weekend/weekday" describes activation in a very general way. Without explicit constraints or negative examples, it is unclear when the skill should activate versus when a general market chat request should not be routed here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says the skill triggers on generic terms like 'liquidity', 'depth', 'momentum', 'arbitrage', and 'premium'. These terms are broad and can appear in ordinary financial discussion without a clear request for this specific skill, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## General Rules

⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read [gate-runtime-rules.md](https://github.com/gate/gate-skills/blob/master/skills/gate-runtime-rules.md)
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they
  exist in the MCP server.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Several cases are activated by short generic keywords such as 'liquidity', 'arbitrage', 'basis', 'portfolio', or 'current level', and some overlap across cases. The file does not provide negative examples or a deterministic tie-breaker for overlapping intents, which can cause inconsistent or unintended routing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough to match ordinary market discussion, which increases the chance of unintended invocation. Overbroad routing can expose users to actions or analyses they did not request and makes it easier for adjacent prompts to activate the skill outside its narrow intended scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The liquidation monitoring triggers are vague and do not sufficiently constrain market, timeframe, or instrument type. This can cause accidental invocation on general market commentary and produce potentially alarming outputs without a precise user request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Phrases like 'Any arbitrage opportunities?' are highly general and could capture broad trading-conversation prompts. Because arbitrage scanning can lead directly to trade suggestions, ambiguous activation raises the risk of unsolicited or context-inappropriate financial guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manipulation-risk triggers are broad and can match generic questions about a coin, leading to speculative conclusions about manipulation without strong user intent. This is especially sensitive because the output may label assets as manipulated based on heuristic signals.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata frames this as a market-metrics tool, but the scenarios expand into trading recommendations, portfolio allocation, and portfolio adjustment advice. That scope drift can cause the orchestrator to invoke the skill for higher-risk financial-advice tasks that were not clearly declared, weakening user expectations and policy controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The technical-analysis trigger includes generic advice-seeking phrases such as 'what should I do' and 'should I go long or short,' which are broad enough to capture ordinary investment-advice requests. In this skill, that broad trigger is more dangerous because the content already extends into prescriptive trading recommendations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The technical-analysis section provides directional recommendations such as long/short/wait without a mandatory upfront financial-risk warning. This is dangerous because users may treat the output as actionable trading advice, especially when the skill presents structured recommendations and timeframe-specific actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The portfolio review and allocation recommendation sections go beyond exchange market analysis and directly influence real-money investment decisions. In skill-routing contexts, this creates unsafe capability expansion: a user asking for metrics may receive prescriptive allocation guidance without a separately authorized advisory tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The multi-asset allocation trigger is open-ended and invites broad investment-advice interactions well outside narrow market-metric analysis. Because it can lead to budget allocation recommendations, ambiguous invocation materially increases financial-decision influence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The allocation-analysis workflow suggests portfolio weights for a specified budget but lacks a consistent mandated warning about financial risk. That omission increases the chance that users will rely on the output as personalized investment advice without understanding the limits and risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The portfolio review trigger overlaps with common portfolio-advice requests and can activate on broad, high-stakes financial conversations. Given the skill’s ability to suggest adjustments, this creates meaningful risk of unscoped personalized investment guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The portfolio review and adjustment workflow can recommend changing allocations, yet it does not mandate a clear warning about the risk of acting on those changes. Because this resembles personalized financial guidance, the missing warning materially raises user-harm risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example trigger "Evaluate ETH liquidity on the exchange and compare weekend vs weekday" is phrased as a general natural-language request rather than a tightly bounded invocation pattern. In a markdown skill description, this can make activation scope less explicit and increase the chance of unintended invocation from similar everyday analysis requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The basis trigger phrase is somewhat underspecified and may overlap with normal trading discussion, but the resulting behavior remains relatively bounded to spread analysis. The risk is mainly accidental invocation rather than direct harmful action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.