Back to skill

Security audit

APEX IA Scanner

Security checks for vulnerabilities and agentic risk

Overview

This Binance trading scanner is purpose-aligned in parts, but the package contains materially inconsistent and under-disclosed behavior that users should review before installing.

Review this skill carefully before installing. Do not use its outputs for real or automated trades unless the author removes or clearly separates the randomized mock scanner, aligns all documentation with the actual calculations, documents local files and web server exposure, removes runtime package installation, and updates vulnerable dependencies. Treat all signals as analysis hints only, not trading instructions.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
skills/apex-ia/src/scanner.ts:19
Finding

The apex-scan tool fabricates randomized financial signals instead of scanning market data

Content
View full analysis
{ const { symbolLimit = 10 } = options; console.log(`🔍 Escaneando ${symbolLimit} pares...`); const symbols = ['BTCUSDT', 'ETHUSDT', 'SOLUSDT', 'BNBUSDT', 'XRPUSDT'].slice(0, symbolLimit); const results = symbols.map(symbol => ({ symbol, direction: 'BUY', quality: 'CONFIRMADO', score: 7 + Math.random() * 3, timeframe: '15m', rsi: 25 + Math.random() * 10, volumeRatio: 1.5 + Math.random(), targets: { t1: 68000, t2: 68500, t3: 69500 }, stop: 67800, riskReward: 2.5, intensity: 'FORTE', confluence: 2, matchingTFs: ['1h', '4h'] })); return results; } ``` The same behavior is present in the compiled artifact: ```javascript async function scanAll(options = {}) { const { symbolLimit = 10 } = options; console.log(`🔍 Escaneando ${symbolLimit} pares...`); const symbols = ['BTCUSDT', 'ETHUSDT', 'SOLUSDT', 'BNBUSDT', 'XRPUSDT'].slice(0, symbolLimit); const results = symbols.map(symbol => ({ symbol, direction: 'BUY', quality: 'CONFIRMADO', score: 7 + Math.random() * 3, timeframe: '15m', rsi: 25 + Math.random() * 10, volumeRatio: 1.5 + Math.random(), targets: { t1: 68000, t2: 68500, t3: 69500 }, stop: 67800, riskReward: 2.5, intensity: 'FORTE', confluence: 2, matchingTFs: ['1h', '4h'] })); return results; } ``` ### Technical Analysis The packaged `apex-scan` tool claims to scan Binance Futures pairs across multiple timeframes and calculate indicators such as SMA, RSI, volume, SuperTrend, and confluence. However, the packaged ...[truncated 2511 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
webapp/server.js:10
Finding

Unauthenticated network-accessible web API permits signal disclosure and request-driven resource exhaustion

Content
View full analysis
{ const { symbol = 'BTCUSDT', interval = '1h', limit = 50 } = req.query; try { const response = await axios.get(`https://api.binance.com/api/v3/klines`, { params: { symbol, interval, limit } }); const klines = response.data.map(k => ({ time: k[0], open: parseFloat(k[1]), high: parseFloat(k[2]), low: parseFloat(k[3]), close: parseFloat(k[4]), volume: parseFloat(k[5]) })); res.json(klines); } catch (err) { res.status(500).json({ error: err.message }); } }); ``` The signal-history endpoint exposes locally stored trading signals without authentication: ```javascript app.get('/api/signals', (req, res) => { try { if (fs.existsSync(SIGNALS_FILE)) { const signals = JSON.parse(fs.readFileSync(SIGNALS_FILE, 'utf-8')); res.json(signals.slice(-50).reverse()); } else { res.json([]); } } catch (err) { res.status(500).json({ error: err.message }); } }); ``` The server is started without an explicit loopback host restriction: ```javascript app.listen(PORT, () => { console.log(`\n🦞 APEX IA WebApp rodando em:`); console.log(` 🌐 http://localhost:${ ...[truncated 3064 chars]
Remediation
View remediation
{ console.log(`WebApp available at http://127.0.0.1:${PORT}`); }); ``` 2. If remote access is required, place the service behind an authenticated HTTPS reverse proxy and enforce network access controls. 3. Add authentication and authorization to `/api/signals` and all request-generating endpoints. 4. Replace unrestricted CORS with a strict allowlist of trusted origins. Disable CORS entirely when it is unnecessary. 5. Add rate limiting per client and globally, especially for `/api/prices`, `/api/scan`, and `/api/klines`. 6. Validate `/api/klines` parameters: - Require `symbol` to match an approved Binance symbol or a strict uppercase alphanumeric pattern. - Allow only supported interval values. - Parse `limit` as an integer and enforce a conservative range. - Reject duplicate, array, object, or malformed query values. 7. Configure Axios connection and response timeouts. 8. Add concurrency limits, response caching, and request deduplication for Binance requests. 9. Return generic client-facing errors and log detailed errors only on the server. 10. Apply security headers through middleware such as Helmet. 11. Document the binding address, authentication model, exposed data, and firewall requirements in deployment instructions. 12. Add tests confirming that unauthorized clients cannot access signal history or induce unlimited outbound requests. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (103)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Using Binance spot endpoints while claiming Binance Futures, only scanning a single interval while claiming multi-timeframe support, and reading local files like sinais.json without disclosure are material behavior mismatches. This is dangerous because it combines misleading financial outputs with undeclared filesystem access, undermining informed consent and trust boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Using Binance spot endpoints while claiming Binance Futures, only scanning a single interval while claiming multi-timeframe support, and reading local files like sinais.json without disclosure are material behavior mismatches. This is dangerous because it combines misleading financial outputs with undeclared filesystem access, undermining informed consent and trust boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Using Binance spot endpoints while claiming Binance Futures, only scanning a single interval while claiming multi-timeframe support, and reading local files like sinais.json without disclosure are material behavior mismatches. This is dangerous because it combines misleading financial outputs with undeclared filesystem access, undermining informed consent and trust boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Using Binance spot endpoints while claiming Binance Futures, only scanning a single interval while claiming multi-timeframe support, and reading local files like sinais.json without disclosure are material behavior mismatches. This is dangerous because it combines misleading financial outputs with undeclared filesystem access, undermining informed consent and trust boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description promises confirmations using Pivot SuperTrend, RSI, volume, and confluence, but the implementation only evaluates SMA 8x21 proximity/crossover logic. This mismatch can materially mislead users about how signals are generated, causing unsafe reliance on nonexistent controls and increasing financial risk in a trading context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description advertises Pivot SuperTrend, RSI, volume, and confluence confirmation, but the implementation only evaluates SMA 8/21 cross/touch conditions on price closes. In a trading automation context, this mismatch can cause users to trust materially weaker signals than promised, leading to unsafe financial decisions based on false assumptions about the analysis depth.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a professional multi-timeframe Binance Futures scanner that detects SMA 8x21 crossings with confirmation from Pivot SuperTrend, RSI, volume, and confluence. In contrast, this file loads only 15-minute candles, subscribes to ticker data, and emits signals solely from SMA 8/21 proximity and crossing logic without implementing the claimed confirmation indicators or multi-timeframe behavior.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.16.0 — 10 advisory(ies): CVE-2026-67313 (Axios: Excessive recursion in formDataToJSON can cause denial of service); CVE-2026-67319 (Axios: Nested axios option objects can consume polluted prototype values); CVE-2026-67315 (Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios) +7 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile pins axios to 1.16.0, and the supplied advisory set indicates multiple known flaws including denial of service, prototype-pollution-related option handling, and proxy bypass behavior. In a trading/scanner skill that makes outbound HTTP requests, these issues can directly affect availability, request routing, and trust boundaries if attacker-controlled inputs reach request construction or proxy-dependent environments.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
90% confidence
Finding

form-data 4.0.5 is flagged for CRLF injection via unescaped multipart field names, which can enable malformed multipart requests or header injection when untrusted field names are used. Although a package-lock entry alone does not prove exploitability, this is a real dependency risk because axios depends on form-data and the skill performs network communications where multipart construction may occur now or later.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.20.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
93% confidence
Finding

ws 8.20.0 is reported with memory disclosure and memory exhaustion vulnerabilities, which are especially relevant for a Binance Futures scanner that likely maintains live WebSocket feeds. An attacker or malicious upstream peer could exploit fragmentation/chunk handling to crash the process or expose sensitive process memory, impacting confidentiality and availability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.16.0 — 10 advisory(ies): CVE-2026-67313 (Axios: Excessive recursion in formDataToJSON can cause denial of service); CVE-2026-67319 (Axios: Nested axios option objects can consume polluted prototype values); CVE-2026-67315 (Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios) +7 more

High
Category
Supply Chain
Confidence
92% confidence
Finding

The package declares axios with a permissive range that static analysis maps to a vulnerable resolved version, and axios is a network-facing HTTP client frequently exposed to untrusted responses, redirects, proxy settings, and serialized data. In a trading scanner context that consumes external market/API data, vulnerable axios behavior could enable denial of service, proxy bypass, or other unsafe request-handling paths depending on how the library is used downstream.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.20.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
94% confidence
Finding

The ws dependency is identified as resolving to a version with memory disclosure and memory exhaustion denial-of-service advisories. Because this skill is a multi-timeframe Binance Futures scanner and likely maintains live WebSocket connections to external streams, a vulnerable WebSocket library is especially relevant: malformed or adversarial frames from the network could crash the process, exhaust memory, or expose sensitive in-memory data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code presents PivotFlow and SuperTrend as confirmations, but detectSignal only calculates SMA, RSI, volume, and ATR, then hard-codes 'PivotFlow' and 'SuperTrend' into the confirmations list. In a trading skill, this is dangerous because users may trust signals as being validated by multiple indicators that are never actually computed, leading to materially misleading automated trading decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The startup banner states the strategy uses Pivot Flow and SuperTrend and that signals are 'validated automatically,' but the program does not perform those validations. This creates a deceptive trust signal at runtime, which is especially risky in a financial decision-support context where users may act on inaccurate assumptions about signal quality and safety.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script automatically installs the 'ws' package at runtime using child_process.execSync('npm install ws'). This executes a shell command that modifies the local environment without explicit user approval, and it creates supply-chain risk because code from the package registry is fetched and installed during execution. In a trading/scanner skill, runtime package installation is not necessary for core functionality and is especially risky because the file is meant to be run directly on a user's machine.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a professional multi-timeframe Binance Futures scanner with confirmation from Pivot SuperTrend, RSI, volume, and confluence. In the actual detection logic, the signal is generated only from SMA 8/21 crossovers with simple RSI and volume scoring; there is no Pivot SuperTrend or other confluence calculation implemented here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code does not perform any Binance Futures scanning, indicator calculation, or market-data retrieval despite claiming to be a professional multi-timeframe scanner. Instead, it fabricates trading signals with hard-coded fields and random values, which can mislead users into acting on nonexistent analysis and create financial harm in a high-risk trading context.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.16.0 — 10 advisory(ies): CVE-2026-67313 (Axios: Excessive recursion in formDataToJSON can cause denial of service); CVE-2026-67319 (Axios: Nested axios option objects can consume polluted prototype values); CVE-2026-67315 (Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios) +7 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

The lockfile pins axios to 1.16.0, and the finding cites multiple known advisories affecting that exact version, including denial-of-service, prototype-pollution-related behavior, and proxy bypass issues. In a market-scanning skill that likely makes outbound HTTP requests to Binance or other APIs, a vulnerable HTTP client is directly relevant because malformed responses, attacker-controlled configuration, or network environment manipulation could affect availability, request routing, or data integrity.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
89% confidence
Finding

The lockfile includes form-data 4.0.5, which is flagged for CRLF injection in multipart field names/files. This is a real supply-chain risk if the skill ever constructs multipart requests using untrusted field names or filenames, potentially allowing header/body manipulation in downstream HTTP requests; however, in the provided context of a Binance futures scanner, multipart upload behavior is not obviously core functionality, so exploitation depends on actual code paths.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.16.0 — 10 advisory(ies): CVE-2026-67313 (Axios: Excessive recursion in formDataToJSON can cause denial of service); CVE-2026-67319 (Axios: Nested axios option objects can consume polluted prototype values); CVE-2026-67315 (Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios) +7 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The package explicitly depends on axios 1.16.0, which the finding identifies as having multiple known advisories including denial-of-service, proxy bypass, and prototype-pollution-related issues. Because this skill is a scanner that likely performs outbound HTTP requests to third-party services, a vulnerable HTTP client is materially relevant and could expose the agent to request manipulation, local network access bypasses, or service instability.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill claims to scan Binance Futures with multi-timeframe technical analysis, but the implementation returns fabricated values using hard-coded symbols and Math.random() instead of fetching or analyzing market data. In a trading context, this is dangerous because users may rely on false signals for financial decisions, causing direct monetary loss and undermining trust in the agent's outputs.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.16.0 — 10 advisory(ies): CVE-2026-67313 (Axios: Excessive recursion in formDataToJSON can cause denial of service); CVE-2026-67319 (Axios: Nested axios option objects can consume polluted prototype values); CVE-2026-67315 (Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios) +7 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The lockfile pins axios 1.16.0, and the reported advisories include high-risk issues such as denial of service, prototype-pollution-related option handling, and NO_PROXY bypass behavior. Because this is a dependency manifest, the vulnerable package is definitely present in the shipped dependency graph even though exploitability depends on how the application uses axios for outbound requests and request data handling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
94% confidence
Finding

form-data 4.0.5 is present as a dependency of axios and is flagged for CRLF injection via unescaped multipart field names and filenames. If the application builds multipart requests using attacker-controlled names or metadata, this can lead to header injection or request smuggling effects against downstream services.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.16.0 — 10 advisory(ies): CVE-2026-67313 (Axios: Excessive recursion in formDataToJSON can cause denial of service); CVE-2026-67319 (Axios: Nested axios option objects can consume polluted prototype values); CVE-2026-67315 (Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios) +7 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises network use to Binance and .env-based configuration, but the manifest does not declare any tool scope such as allowed tools or permissions. Missing explicit scope weakens least-privilege controls and can let a skill use environment or network capabilities without clear user visibility or policy enforcement.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
realtime-scanner.js:155