Back to skill

Security audit

Coinbase

Security checks for vulnerabilities and agentic risk

Overview

This Coinbase skill does what it claims, but it can place real crypto trades using stored credentials without built-in confirmation or safety limits.

Review this skill carefully before installing. Use it only with a Coinbase API key whose permissions you understand, preferably a separate least-privilege key. Do not allow an agent to call create_order automatically without a manual confirmation step, order-size limits, and product allowlists. Store the private key outside the skill directory or lock the file down with owner-only permissions, keep it out of source control and backups, and pin dependencies before installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:14
Finding

Unpinned Security-Sensitive Runtime Dependencies

Content
View full analysis
Remediation
View remediation
PyJWT== ``` 2. Generate and verify cryptographic hashes for every package and transitive dependency. 3. Document installation using hash enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Use an explicitly trusted package index or an internally controlled artifact repository. 5. Add automated dependency vulnerability and integrity scanning to release workflows. 6. Review and update pinned versions on a controlled schedule rather than automatically accepting the newest releases. 7. Run the Skill in a constrained environment that cannot access unrelated user files or credentials. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/coinbase.py:12
Finding

Plaintext Trading Private Key Stored Without File-Permission Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation provides ready-to-use examples for placing Coinbase market and limit orders against a live trading API without any warning that these calls can execute real trades using real funds. In an agent-skill context, this materially increases the risk of unintended financial loss because users or downstream agents may treat the examples as harmless test actions rather than irreversible production operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The create_order function can place live Coinbase buy or sell orders immediately with no confirmation, no dry-run mode, no policy checks, and no safety guardrails around asset, size, or destination behavior. In an agent skill context, this is especially dangerous because any upstream prompt injection, logic error, or unintended invocation could trigger irreversible financial trades using the loaded credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README instructs users to place sensitive Coinbase API credentials in local plaintext files but does not warn about secret handling, file permissions, accidental commits, or key scope. In a trading skill, exposed credentials can enable unauthorized account access and potentially permit trading or other account actions depending on granted permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README encourages immediate use of a live trading function (create_order) against a Coinbase account without any warning that it can execute real trades and spend account funds. In an agent-skill context, this is more dangerous because users may copy example code directly into automated workflows and trigger unintended financial transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code reads Coinbase API credentials from local secret files and later uses them to authenticate outbound requests, but the only disclosure is an internal docstring. There is no confirmation prompt, visible logging, or user-facing warning that sensitive credentials will be accessed and used for network calls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.