Back to skill

Security audit

gate-news-listing

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only exchange listing announcement skill with disclosed MCP data lookups and no evidence of credential access, persistence, file writes, or hidden execution.

Install this only if you want an agent to query Gate News/Gate Info MCP tools for exchange announcements and public market context. Treat outputs as informational, verify the MCP server source, and do not use the report as trading or investment advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description includes broad trigger phrases like new listings and delisted without clear scope boundaries, which may cause the skill to intercept vague requests that should be handled elsewhere. In agent systems, ambiguous activation broadens operational scope and can lead to misrouting, unnecessary tool calls, and reduced predictability of security controls.

Content

No source excerpt is available for this finding.

Scope Creep

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest's required_permissions: [] provides a baseline of no declared permissions, yet the skill body explicitly instructs the agent to call MCP tools at L37-L40. This is a scope expansion relative to the declared permissions metadata, especially because the description at L5 names only three tools while the body adds info_coin_get_coin_rankings as an allowed tool.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
## General Rules

⚠️ STOP — You MUST read and strictly follow the shared runtime rules before proceeding.
Do NOT select or call any tool until all rules are read. These rules have the highest priority.
→ Read `./references/gate-runtime-rules.md`
→ Also read `./references/info-news-runtime-rules.md` for gate-info / gate-news shared rules (tool degradation, report standards, security, routing, and graceful fallback behavior).
- **Only call MCP tools explicitly listed in this skill.** Tools not documented here must NOT be called, even if they

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase what happened recently is overly broad and can cause this skill to activate for general news queries outside its intended listing/delisting scope. Over-broad routing increases the chance of incorrect tool use, accidental data exposure across domains, and confusion in multi-skill environments where least-privilege routing matters.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The listed trigger examples such as "Any new coins listed recently" and "What did Binance list this week" are natural conversational phrases without clear invocation boundaries or exclusion conditions. In a markdown scenario file, this can make activation scope overly broad and increase the chance of unintended matching with ordinary user requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description at L5 says the skill uses news_feed_get_exchange_announcements, info_coin_get_coin_info, and info_marketsnapshot_get_market_snapshot. The body later lists info_coin_get_coin_rankings among tools used, which broadens the documented behavior beyond what the manifest claims even though the main workflow does not clearly require it.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The examples "What did Binance list" and "What did Gate list recently" are understandable but still broad, and the file does not specify how the skill distinguishes listing-announcement requests from other exchange-related queries. Without explicit boundaries, the trigger scope remains ambiguous for markdown-based invocation guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.