Back to skill

Security audit

Binance Pro (Hybrid Labs)

Security checks for vulnerabilities and agentic risk

Overview

This Binance skill can execute real financial trades without strong confirmations and asks users to store powerful API keys, so it should be reviewed carefully before use.

Install only if you intentionally want an agent-accessible Binance trading helper. Use a dedicated Binance API key with withdrawals disabled, minimal permissions, and IP restrictions; avoid funding keys with broad trading authority unless you add confirmation or dry-run safeguards and secure credential storage yourself.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
binance_cli.py:19
Finding

Plaintext Binance Credential File Without Permission Enforcement

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
binance_cli.py:44
Finding

API Key Is Unnecessarily Loaded and Transmitted for Public Binance Requests

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · binance_cli.py (reported line 79)May include surrounding context.

python
req.data = query_string.encode()
    
    try:
        with urllib.request.urlopen(req, timeout=30) as response:
            return json.loads(response.read().decode())
    except urllib.error.HTTPError as e:
        error_body = e.read().decode()

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code is genuinely related to Binance and does perform some of the declared core functions: checking balances, viewing futures positions/PnL, opening/closing futures positions, and setting stop loss/take profit. However, the description materially overstates the scope. It advertises a complete Binance integration with spot trading, staking, portfolio management, leverage support, and any Binance operation. In reality, the implementation is a limited CLI focused mostly on futures account inspection and market order management, with spot trading explicitly unimplemented. This is a description-behavior mismatch due to significant missing advertised capabilities, even though there are no major undeclared malicious or unrelated behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides ready-to-run examples for leveraged futures orders, stop-loss/take-profit placement, cancellations, and leverage changes without strong pre-execution warnings or mandatory confirmations. Because these commands target real Binance endpoints and can directly affect funds, insufficient safety interlocks materially raise the risk of accidental or impulsive destructive trading actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The buy/sell futures commands place live market orders immediately with no confirmation, preview, dry-run mode, or explicit risk acknowledgment. In an agent-skill context tied to natural-language automation, this materially increases the chance of accidental or prompt-induced trades causing direct financial loss, especially given leveraged futures trading.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The close-position command automatically submits a reduce-only market order as soon as it finds a nonzero position, with no user confirmation. Closing positions is an irreversible account-impacting action that can realize losses or disrupt hedges, and the risk is amplified here because the skill is designed to operate directly against a live exchange account.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill performs sensitive operations requiring environment access, credential file access, and outbound network calls, but it declares no explicit tool scope or permission boundary. In a trading skill that can access API keys and place live orders, missing scope declarations increases the chance the agent can invoke it in broader contexts than intended and handle secrets or external actions without clear user consent controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description is broad enough to match almost any Binance-related request, which can cause the skill to be selected for both harmless queries and high-risk trading actions. In this context, overbroad activation is dangerous because the skill includes live account access and market-order examples, increasing the chance of unintended use in situations where the user only wanted information or analysis.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

QUERY="timestamp=${TIMESTAMP}" SIGNATURE=$(echo -n "$QUERY" | openssl dgst -sha256 -hmac "$SECRET" | cut -d' ' -f2)

curl -s "https://api.binance.com/api/v3/account?${QUERY}&signature=${SIGNATURE}"
-H "X-MBX-APIKEY: ${API_KEY}" | jq '[.balances[] | select(.free != "0.00000000")]'

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

QUERY="timestamp=${TIMESTAMP}" SIGNATURE=$(echo -n "$QUERY" | openssl dgst -sha256 -hmac "$SECRET" | cut -d' ' -f2)

curl -s "https://api.binance.com/api/v3/account?${QUERY}&signature=${SIGNATURE}"
-H "X-MBX-APIKEY: ${API_KEY}" | jq '[.balances[] | select(.free != "0.00000000")]'

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example submits a live market buy order to the real Binance spot trading endpoint, causing an irreversible state-changing financial action. In the context of an agent skill, exposing direct execution commands without stronger guardrails can lead to accidental purchases, misuse from ambiguous prompts, or unsafe automation against a funded account.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

QUERY="symbol=${SYMBOL}&side=BUY&type=MARKET&quantity=${QUANTITY}&timestamp=${TIMESTAMP}" SIGNATURE=$(echo -n "$QUERY" | openssl dgst -sha256 -hmac "$SECRET" | cut -d' ' -f2)

curl -s -X POST "https://api.binance.com/api/v3/order?${QUERY}&signature=${SIGNATURE}"
-H "X-MBX-APIKEY: ${API_KEY}" | jq '.'

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example submits a live market sell order to the real Binance spot endpoint, which can liquidate holdings immediately at market price. Given that the skill is broadly scoped and lacks strong permission and confirmation boundaries, this creates meaningful risk of unintended asset disposal or financial loss.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

QUERY="symbol=${SYMBOL}&side=SELL&type=MARKET&quantity=${QUANTITY}&timestamp=${TIMESTAMP}" SIGNATURE=$(echo -n "$QUERY" | openssl dgst -sha256 -hmac "$SECRET" | cut -d' ' -f2)

curl -s -X POST "https://api.binance.com/api/v3/order?${QUERY}&signature=${SIGNATURE}"
-H "X-MBX-APIKEY: ${API_KEY}" | jq '.'

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Stop-loss and take-profit commands submit live conditional orders without a clear warning, order preview, or validation against current position context beyond minimal side inference. Misplaced protective orders can prematurely close positions or fail to protect them, producing financial harm; in an automated assistant setting, silent execution makes accidental misuse more dangerous.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a 'complete Binance integration' that can 'trade spot' and perform 'any Binance operation.' However, the CLI help advertises spot-buy and spot-sell commands while the actual handlers only print that spot trading is not yet implemented, so the implemented behavior materially falls short of the stated capability.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The inline command documentation lists 'spot-buy' and 'spot-sell' as available commands, implying functioning spot market trading support. The corresponding branches explicitly state 'Spot trading not yet implemented,' which directly contradicts that documentation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
74% confidence
Finding

The skill encourages persistence of exchange API credentials in a local file under ~/.openclaw/credentials/binance.json, but the code does not enforce secure permissions, encryption, or use of a dedicated secret store. If that file is readable by other local users, malware, backups, or agent tooling, an attacker could steal Binance API keys and perform unauthorized account actions.

Content

Scanner excerpt · binance_cli.py (reported line 332)May include surrounding context.

python
Credentials:
  Set BINANCE_API_KEY and BINANCE_SECRET env vars
  Or create ~/.openclaw/credentials/binance.json

Examples:
  ./binance_cli.py balance

Static analysis

No suspicious patterns detected.