T09 · Insecure Skill Coding Practices
- Location
auth-signing.md:24- Finding
Unvalidated API Base URL Can Disclose Binance Authentication Material
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Binance skill is mostly coherent, but it needs review because signed API examples can send Binance authentication material to any configured BINANCE_BASE_URL while the skill claims only official Binance endpoints are used.
Install only if you are comfortable giving the skill Binance account or trading API access. Use testnet first, prefer restricted API keys with withdrawals disabled and IP allowlisting, set BINANCE_BASE_URL only to a known Binance production or testnet host, avoid logging secrets or detailed account/order data, and pin or review SDK versions before installing them.
auth-signing.md:24Unvalidated API Base URL Can Disclose Binance Authentication Material
sdk-cli.md:14Unpinned SDK Installation Commands Create Supply-Chain Exposure
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- Send data to undeclared services
- Place production orders without explicit confirmation
- Store API secrets in repository files
- Modify this skill definition file
## Trust
This markdown file includes concrete commands that read BINANCE_API_SECRET and later send BINANCE_API_KEY, but it does not warn users that these are sensitive credentials whose exposure could compromise their account. Under the markdown-specific warning criterion, credential-handling behaviour should be accompanied by an explicit caution about privacy or security impact.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
QS="symbol=BTCUSDT&side=$SIDE&type=$TYPE&timeInForce=$TIF&quantity=$QTY&price=$PRICE×tamp=$TS" SIG=$(printf "%s" "$QS" | openssl dgst -sha256 -hmac "$BINANCE_API_SECRET" | sed 's/^.* //')
curl -s -X POST -H "X-MBX-APIKEY: $BINANCE_API_KEY"
"$BINANCE_BASE_URL/api/v3/order/test?$QS&signature=$SIG" -d ''
The runbook logging advice lacks any warning about sensitive content, creating a real risk that users will store order details, account-related metadata, error traces, or even signing context in plaintext local notes. In a financial API skill, this context makes the issue more serious because seemingly harmless payload and response summaries can reveal trading strategies, balances, counterpart activity, or other private operational information.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
mkdir -p ~/binance/snapshots
touch ~/binance/{memory.md,runbooks.md,incidents.md}
chmod 700 ~/binance ~/binance/snapshots
chmod 600 ~/binance/{memory.md,runbooks.md,incidents.md}
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
mkdir -p ~/binance/snapshots touch ~/binance/{memory.md,runbooks.md,incidents.md} chmod 700 ~/binance ~/binance/snapshots chmod 600 ~/binance/{memory.md,runbooks.md,incidents.md}
5. If `memory.md` is empty, initialize it from `memory-template.md`.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Guardrails
- Never ask the user to paste secrets into chat.
- Never execute production trading flows without explicit confirmation.
- Never present uncertain order status as final without reconciliation.
The guidance recommends logging Binance request payload and response summaries to a persistent file in the user's home directory, which creates unnecessary local retention of potentially sensitive operational data. Even if only 'summaries' are intended, API payloads, symbols, account actions, timestamps, order metadata, and error details can expose trading behavior or be expanded over time into more sensitive logging.
No suspicious patterns detected.