T09 · Insecure Skill Coding Practices
- Location
binance_cli.py:19- Finding
Plaintext Binance Credential File Without Permission Enforcement
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Binance skill can execute real financial trades without strong confirmations and asks users to store powerful API keys, so it should be reviewed carefully before use.
Install only if you intentionally want an agent-accessible Binance trading helper. Use a dedicated Binance API key with withdrawals disabled, minimal permissions, and IP restrictions; avoid funding keys with broad trading authority unless you add confirmation or dry-run safeguards and secure credential storage yourself.
binance_cli.py:19Plaintext Binance Credential File Without Permission Enforcement
binance_cli.py:44API Key Is Unnecessarily Loaded and Transmitted for Public Binance Requests
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
req.data = query_string.encode()
try:
with urllib.request.urlopen(req, timeout=30) as response:
return json.loads(response.read().decode())
except urllib.error.HTTPError as e:
error_body = e.read().decode()
The code is genuinely related to Binance and does perform some of the declared core functions: checking balances, viewing futures positions/PnL, opening/closing futures positions, and setting stop loss/take profit. However, the description materially overstates the scope. It advertises a complete Binance integration with spot trading, staking, portfolio management, leverage support, and any Binance operation. In reality, the implementation is a limited CLI focused mostly on futures account inspection and market order management, with spot trading explicitly unimplemented. This is a description-behavior mismatch due to significant missing advertised capabilities, even though there are no major undeclared malicious or unrelated behaviors.
The skill provides ready-to-run examples for leveraged futures orders, stop-loss/take-profit placement, cancellations, and leverage changes without strong pre-execution warnings or mandatory confirmations. Because these commands target real Binance endpoints and can directly affect funds, insufficient safety interlocks materially raise the risk of accidental or impulsive destructive trading actions.
The buy/sell futures commands place live market orders immediately with no confirmation, preview, dry-run mode, or explicit risk acknowledgment. In an agent-skill context tied to natural-language automation, this materially increases the chance of accidental or prompt-induced trades causing direct financial loss, especially given leveraged futures trading.
The close-position command automatically submits a reduce-only market order as soon as it finds a nonzero position, with no user confirmation. Closing positions is an irreversible account-impacting action that can realize losses or disrupt hedges, and the risk is amplified here because the skill is designed to operate directly against a live exchange account.
The skill performs sensitive operations requiring environment access, credential file access, and outbound network calls, but it declares no explicit tool scope or permission boundary. In a trading skill that can access API keys and place live orders, missing scope declarations increases the chance the agent can invoke it in broader contexts than intended and handle secrets or external actions without clear user consent controls.
The description is broad enough to match almost any Binance-related request, which can cause the skill to be selected for both harmless queries and high-risk trading actions. In this context, overbroad activation is dangerous because the skill includes live account access and market-order examples, increasing the chance of unintended use in situations where the user only wanted information or analysis.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
QUERY="timestamp=${TIMESTAMP}" SIGNATURE=$(echo -n "$QUERY" | openssl dgst -sha256 -hmac "$SECRET" | cut -d' ' -f2)
curl -s "https://api.binance.com/api/v3/account?${QUERY}&signature=${SIGNATURE}"
-H "X-MBX-APIKEY: ${API_KEY}" | jq '[.balances[] | select(.free != "0.00000000")]'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
QUERY="timestamp=${TIMESTAMP}" SIGNATURE=$(echo -n "$QUERY" | openssl dgst -sha256 -hmac "$SECRET" | cut -d' ' -f2)
curl -s "https://api.binance.com/api/v3/account?${QUERY}&signature=${SIGNATURE}"
-H "X-MBX-APIKEY: ${API_KEY}" | jq '[.balances[] | select(.free != "0.00000000")]'
This example submits a live market buy order to the real Binance spot trading endpoint, causing an irreversible state-changing financial action. In the context of an agent skill, exposing direct execution commands without stronger guardrails can lead to accidental purchases, misuse from ambiguous prompts, or unsafe automation against a funded account.
QUERY="symbol=${SYMBOL}&side=BUY&type=MARKET&quantity=${QUANTITY}×tamp=${TIMESTAMP}" SIGNATURE=$(echo -n "$QUERY" | openssl dgst -sha256 -hmac "$SECRET" | cut -d' ' -f2)
curl -s -X POST "https://api.binance.com/api/v3/order?${QUERY}&signature=${SIGNATURE}"
-H "X-MBX-APIKEY: ${API_KEY}" | jq '.'
This example submits a live market sell order to the real Binance spot endpoint, which can liquidate holdings immediately at market price. Given that the skill is broadly scoped and lacks strong permission and confirmation boundaries, this creates meaningful risk of unintended asset disposal or financial loss.
QUERY="symbol=${SYMBOL}&side=SELL&type=MARKET&quantity=${QUANTITY}×tamp=${TIMESTAMP}" SIGNATURE=$(echo -n "$QUERY" | openssl dgst -sha256 -hmac "$SECRET" | cut -d' ' -f2)
curl -s -X POST "https://api.binance.com/api/v3/order?${QUERY}&signature=${SIGNATURE}"
-H "X-MBX-APIKEY: ${API_KEY}" | jq '.'
Stop-loss and take-profit commands submit live conditional orders without a clear warning, order preview, or validation against current position context beyond minimal side inference. Misplaced protective orders can prematurely close positions or fail to protect them, producing financial harm; in an automated assistant setting, silent execution makes accidental misuse more dangerous.
The manifest describes a 'complete Binance integration' that can 'trade spot' and perform 'any Binance operation.' However, the CLI help advertises spot-buy and spot-sell commands while the actual handlers only print that spot trading is not yet implemented, so the implemented behavior materially falls short of the stated capability.
The inline command documentation lists 'spot-buy' and 'spot-sell' as available commands, implying functioning spot market trading support. The corresponding branches explicitly state 'Spot trading not yet implemented,' which directly contradicts that documentation.
The skill encourages persistence of exchange API credentials in a local file under ~/.openclaw/credentials/binance.json, but the code does not enforce secure permissions, encryption, or use of a dedicated secret store. If that file is readable by other local users, malware, backups, or agent tooling, an attacker could steal Binance API keys and perform unauthorized account actions.
Credentials:
Set BINANCE_API_KEY and BINANCE_SECRET env vars
Or create ~/.openclaw/credentials/binance.json
Examples:
./binance_cli.py balance
No suspicious patterns detected.