Back to skill

Security audit

Binance Trade Hunter

Security checks for vulnerabilities and agentic risk

Overview

This skill is Review-worthy because it can place real Binance trades, reuse local Telegram credentials, and run background alert processes with weak safeguards.

Install only if you are comfortable giving this skill live Binance trading authority and Telegram notification access. Use a restricted Binance sub-account, keep trade limits small, avoid relying on automatic Telegram credential discovery, and review/lock dependencies before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Note
Location
src/skill_api.py:113
Finding

Hardcoded Promotional Content Injected into User-Facing Analysis

Content
View full analysis
{i}. {r['base_asset']} 总分 {r['score']}" f"\n 流动性: {r['liquidity_score']}/40 | 趋势: {r['trend_score']}/35 | 量: {r['volume_score']}/25" f"\n 风险: {stars} | {r['suggestion']}" ) lines.append("\n🌊 用 AI 建设加密,和币安一起逐浪 Web3!") send_message(token, chat_id, "\n".join(lines)) ``` ### Technical Analysis The Skill unconditionally appends promotional Binance/Web3 messaging to ordinary coin-analysis results. The content is not necessary to calculate or communicate the requested market analysis. Because it is inserted by executable code rather than being optional attribution, the Agent cannot return an unmodified result without separately filtering the Skill output. This behavior affects both immediate analysis responses and recurring Telegram notifications. It therefore modifies the content the Agent delivers and can repeatedly distribute unrelated promotional material. ### Attack Path 1. The user loads the Skill and requests a top-coin analysis, or starts the scheduled coin-push service. 2. The Skill obtains and formats public market-analysis results. 3. The implementation unconditionally appends the promotional message. 4. The Agent ...[truncated 363 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/tg_config.py:37
Finding

Automatic Reuse of OpenClaw Telegram Credentials and Private-Chat Discovery

Content
View full analysis
dict | None: """Read TG bot token + chat_id from OpenClaw config""" oc_path = Path.home() / ".openclaw" / "openclaw.json" if not oc_path.exists(): return None try: data = json.loads(oc_path.read_text(encoding="utf-8")) bot_token = (data.get("channels", {}) .get("telegram", {}) .get("botToken", "")) chat_id = os.environ.get("OPENCLAW_TG_CHAT_ID", "") if bot_token: return {"bot_token": bot_token, "chat_id": chat_id} except Exception: pass return None ``` ```python def _discover_chat_id(bot_token: str) -> str: """Use getUpdates to find the most recent private chat_id""" try: url = f"https://api.telegram.org/bot{bot_token}/getUpdates" resp = requests.get(url, params={"limit": 10, "offset": -10}, timeout=10) data = resp.json() if not data.get("ok"): return "" # Find the most recent private chat for update in reversed(data.get("result", [])): msg = update.get("message", {}) chat = msg.get("chat", {}) if chat.get("type") == "private": cid = str(chat.get("id", ...[truncated 2420 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/pump_alert.py:463
Finding

Binance WebSocket TLS Certificate Verification Is Disabled

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
src/requirements.txt:1
Finding

Mandatory Installation Uses Broad, Unpinned, and Unused Dependencies

Content
View full analysis
=1.0.19 ccxt>=4.0.0 # WebSocket real-time data websocket-client>=1.6.0 requests>=2.31.0 urllib3>=2.0.0 # Data processing pandas>=2.0.0 numpy>=1.24.0 # Configuration PyYAML>=6.0 # Telegram Bot python-telegram-bot>=20.0 # Logging colorlog>=6.7.0 ``` The setup instructions direct installation of the entire list: ```text pip install -r src/requirements.txt ``` ### Technical Analysis Every dependency is specified with an open-ended minimum version rather than an exact reviewed version. Future releases satisfying these constraints can therefore be installed without any change to the audited Skill package. No lock file or package hashes are provided to verify artifact integrity or make installation reproducible. The audited implementation directly uses only a smaller subset, including `requests`, `urllib3`, `websocket-client`, `PyYAML`, and `cryptography`. Packages such as `python-binance`, `ccxt`, `pandas`, `numpy`, `python-telegram-bot`, and `colorlog` are not imported by the reviewed source files. Installing these unnecessary packages and their transitive dependencies expands the supply-chain attack surface beyond the minimum privileges and components needed for the declared functionality. The requirements file also omits the directly imported `cryptography` package, making successful installation dependent on preexisting environment state. ### Attack Path 1. The mandatory setup process runs `pip install -r src/requirements.txt`. 2. The package index resolves the newest versions satisfying the open-ended constraints. 3. A compromised, malicious, or incompatible current or future package release may be selected. 4. Package build or installation logic exe ...[truncated 876 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (60)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
97% confidence
Finding

The YARA match is substantiated by the actual code path: the skill harvests Telegram bot credentials from unrelated local config and environment state, then uses them to send messages to Telegram. Even if intended for convenience rather than theft, this pattern is dangerous because it enables unauthorized use of host credentials and covert external communication channels.

Content

Scanner excerpt · src/skill_api.py (reported line 66)May include surrounding context.

python
w 配置自动获取 TG bot token + chat_id"""
    import json
    oc_path = Path.home() / ".openclaw" / "openclaw.json"
    if not oc_path.exists():
        return None
    try:
        oc = json.loads(oc_path.read_text(encoding="utf-8"))
        bot_token = oc.get("channels", {}).get("telegram", {}).get("botToken", "")
        # chat_id from env or auto-discover via getUpdates
        chat_id = os.environ.get("OPENCLAW_TG_CHAT_ID", "")
        if bot_token and not chat_id:
            from tg_config import _discover_chat_id
            chat_id = _discover_chat_id(bot_token)
        if bot_token:
            return {"bot_token": bot_token, "chat_id": chat_id}
    except Exception:
        pass
    return None


def _send_tg(token: str, chat_id: str, text: str, parse_mode: str = None):
    """发送 Telegram 消息"""
    url = f"https://api.telegram.org/bot{token}/sendMessage"
    payload = {"chat_id": chat_id, "text": text}
    if parse_mode:
        payload["parse_mode"] = parse_mod

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This mismatch indicates undisclosed access to local OpenClaw Telegram configuration, auto-discovery of chat IDs, and direct outbound messaging to Telegram. Hidden config harvesting and autonomous message delivery expand the skill's effective privilege surface and can expose local secrets or enable unauthorized notifications/data exfiltration beyond the stated Binance-trading purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This mismatch indicates undisclosed access to local OpenClaw Telegram configuration, auto-discovery of chat IDs, and direct outbound messaging to Telegram. Hidden config harvesting and autonomous message delivery expand the skill's effective privilege surface and can expose local secrets or enable unauthorized notifications/data exfiltration beyond the stated Binance-trading purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This mismatch indicates undisclosed access to local OpenClaw Telegram configuration, auto-discovery of chat IDs, and direct outbound messaging to Telegram. Hidden config harvesting and autonomous message delivery expand the skill's effective privilege surface and can expose local secrets or enable unauthorized notifications/data exfiltration beyond the stated Binance-trading purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch indicates undisclosed access to local OpenClaw Telegram configuration, auto-discovery of chat IDs, and direct outbound messaging to Telegram. Hidden config harvesting and autonomous message delivery expand the skill's effective privilege surface and can expose local secrets or enable unauthorized notifications/data exfiltration beyond the stated Binance-trading purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
5. Run: `pip install -r src/requirements.txt` (if dependencies not installed)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
5. Run: `pip install -r src/requirements.txt` (if dependencies not installed)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The WebSocket client disables TLS certificate verification via sslopt={"cert_reqs": ssl.CERT_NONE}, allowing man-in-the-middle interception or tampering of Binance market data. In a trading skill, forged price feeds can directly trigger false pump alerts and induce unsafe buy/sell decisions, making this more dangerous than a generic monitoring bug.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The buy, sell_all, and sell_half functions perform live market orders directly from agent-accessible APIs with no confirmation, no preview, no policy checks, and no transaction safety rails. In the context of a Binance trading skill, this is highly dangerous because a mistaken prompt, prompt injection, or unauthorized invocation can immediately cause irreversible financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module provides immediate market_sell_all and market_sell_half execution paths that place live market orders with no in-function confirmation, dry-run mode, warning banner, or secondary authorization. In a trading skill context, accidental invocation, prompt misparse, or upstream agent misuse could liquidate assets instantly and irreversibly at market price.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language parser converts free-form user text into actionable trade intents such as BUY, SELL_ALL, and SELL_HALF without embedding any safety interlocks or requiring explicit confirmation semantics. In a skill designed for one-click Binance trading, this increases the risk that ambiguous language, prompt injection through surrounding agent context, or accidental user phrasing results in live order placement.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill exposes sensitive capabilities including shell execution, file read/write, network access, and likely environment access, yet declares no explicit tool scope or permission boundaries. In a trading skill that handles API credentials and can execute real-money actions, this materially increases the risk of unintended command execution, secret exposure, or filesystem access beyond what users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very generic phrases such as 'buy', 'sell', 'balance', and 'positions', which can cause accidental invocation in unrelated conversations. In a skill capable of handling credentials, running shell commands, and performing real-money trading flows, unintended activation raises the chance of unsafe prompts, confusing context switches, or execution of sensitive operations without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code opens and loads a PEM private key from disk, which is a sensitive credential operation. Although the class constructor names the parameter clearly, there is no confirmation prompt, user-facing log, or warning comment/docstring explaining that the skill will access private key material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This client exposes live market_buy and market_sell methods that directly submit Binance orders with no built-in confirmation, dry-run mode, policy guardrails, or user-consent checkpoint. In the context of a Telegram-triggered trading skill, this is more dangerous because natural-language or automated agent actions could translate into irreversible real-money trades with minimal friction, increasing the risk of accidental or unauthorized execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and all user-facing strings are written in Chinese, and the skill does not indicate that language is selectable or intentionally restricted to a Chinese-speaking context. This can violate language/locale policy when a skill imposes a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This function sends text to the Telegram Bot API, transmitting analyzed results and configured chat metadata over the network. While errors are logged, there is no user-facing prompt, warning comment/docstring, or other disclosure near the operation indicating that data will be sent to an external messaging service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/coin_analyzer.py (reported line 33)May include surrounding context.

python
def send_message(token: str, chat_id: str, text: str):
    url = f"https://api.telegram.org/bot{token}/sendMessage"
    payload = {"chat_id": chat_id, "text": text, "parse_mode": "HTML"}
    try:
        resp = requests.post(url, json=payload, timeout=10)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/pump_alert.py (reported line 599)May include surrounding context.

python
def send_message(token: str, chat_id: str, text: str):
    url = f"https://api.telegram.org/bot{token}/sendMessage"
    payload = {"chat_id": chat_id, "text": text, "parse_mode": "HTML"}
    try:
        resp = requests.post(url, json=payload, timeout=10)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/tg_config.py (reported line 73)May include surrounding context.

python
def send_message(token: str, chat_id: str, text: str):
    url = f"https://api.telegram.org/bot{token}/sendMessage"
    payload = {"chat_id": chat_id, "text": text, "parse_mode": "HTML"}
    try:
        resp = requests.post(url, json=payload, timeout=10)

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The skill transmits generated content to Telegram, an external third party, using a bot token and chat ID from configuration. In a trading skill context, outbound notifications can expose sensitive trading insights, account-related metadata, or future extensions' data to an external service without granular controls, and the use of HTML parse mode can increase message-format injection risk if untrusted text is ever included.

Content

Scanner excerpt · src/coin_analyzer.py (reported line 36)May include surrounding context.

python
url = f"https://api.telegram.org/bot{token}/sendMessage"
    payload = {"chat_id": chat_id, "text": text, "parse_mode": "HTML"}
    try:
        resp = requests.post(url, json=payload, timeout=10)
        if resp.status_code != 200:
            logger.error(f"TG 返回异常: {resp.status_code} {resp.text}")
    except Exception as e:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/coin_analyzer.py (reported line 82)May include surrounding context.

python
self.http.mount("https://", HTTPAdapter(max_retries=retry))

    def get_exchange_info(self) -> dict:
        url = "https://api.binance.com/api/v3/exchangeInfo"
        resp = self.http.get(url, timeout=20)
        resp.raise_for_status()
        return resp.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/coin_analyzer.py (reported line 88)May include surrounding context.

python
self.http.mount("https://", HTTPAdapter(max_retries=retry))

    def get_exchange_info(self) -> dict:
        url = "https://api.binance.com/api/v3/exchangeInfo"
        resp = self.http.get(url, timeout=20)
        resp.raise_for_status()
        return resp.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/pump_alert.py (reported line 260)May include surrounding context.

python
self.http.mount("https://", HTTPAdapter(max_retries=retry))

    def get_exchange_info(self) -> dict:
        url = "https://api.binance.com/api/v3/exchangeInfo"
        resp = self.http.get(url, timeout=20)
        resp.raise_for_status()
        return resp.json()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s docstrings and user-facing output are written in Chinese, including operational instructions and alerts, but there is no indication that the skill is region-specific or that users can opt into another language. This creates a language/locale policy issue because the skill effectively imposes a single language for interaction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.