Back to skill

Security audit

Market Monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only market monitor, but it asks for exchange credentials that its documented public market-data calls do not need.

Review before installing. Use only if you are comfortable with exchange API access, and prefer removing the required BINANCE_API_KEY and any OKX secret/passphrase configuration unless private-account features are added in a separate, clearly scoped skill. Keep any exchange key read-only, restricted, and never withdrawal-enabled.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:10
Finding

Unnecessary Access to Exchange API Credentials for Public Market Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:10-11, with related declarations in impl/binance.md:13-14 and impl/okx.md:11-12
Vulnerability Type: Excessive credential access and violation of least privilege
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:10-11:

yaml
"requires": { "env": ["BINANCE_API_KEY"] },
"primaryEnv": "BINANCE_API_KEY",

impl/binance.md:13-14:

text
Authentication: API Key header (read-only endpoints do not require signing)
API key environment variable: BINANCE_API_KEY

impl/okx.md:11-12:

text
Authentication: Public market endpoints require no signature; private endpoints require OK-ACCESS-KEY and a signature
API key environment variables: OKX_API_KEY, OKX_API_SECRET, OKX_PASSPHRASE

Technical Analysis

The skill only documents calls to public market-data endpoints:

  • Binance /api/v3/ticker/24hr
  • Binance /api/v3/klines
  • OKX /api/v5/market/ticker
  • OKX /api/v5/market/candles

These endpoints do not require account credentials. Nevertheless, the skill metadata requires BINANCE_API_KEY, while the implementation documents access to Binance and OKX credential variables. This violates least privilege because sensitive financial-account credentials are made available for a task that can be completed anonymously.

No direct exfiltration mechanism was found. The risk arises from unnecessarily exposing credentials to the skill or agent execution context, where they may subsequently be included in headers, gateway logs, debugging output, generated responses, or other tool calls.

Attack Path

  1. A user installs or activates the market-monitor skill.
  2. The runtime observes the declared BINANCE_API_KEY requirement and exposes or requests that credential.
  3. If the OKX implementation is used, an operator may also configure the documented OKX key, secret, and passphrase.
  4. The skill invokes public market end ...[truncated 1001 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove BINANCE_API_KEY from the skill's required environment variables and remove primaryEnv.
  2. Remove the Binance and OKX credential-variable declarations from the public market-data implementations.
  3. Do not attach authentication headers to any of the documented public endpoints.
  4. If private account functionality is added later, place it in a separate, explicitly enabled skill with a distinct trust boundary.
  5. For any future authenticated functionality, require exchange keys with the minimum possible permissions, disable withdrawals, apply IP restrictions, and use a dedicated credential rather than a user's general trading key.
  6. Redact API keys, signatures, passphrases, and authentication headers from gateway and application logs.
  7. Add automated tests verifying that public market-data requests contain no authorization or exchange-key headers.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:39
Finding

User-Controlled Exchange Identifier Can Influence a Local Implementation Path

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:39
Vulnerability Type: Insufficient path validation for dynamic implementation loading
Risk Level: Medium

Vulnerable Code Snippet

SKILL.md:39, translated faithfully into English:

text
1. Load the corresponding impl/{exchange}.md according to the exchange parameter

Technical Analysis

The execution procedure directs the agent to interpolate the user-controlled exchange parameter into impl/{exchange}.md. The document does not require exact allowlist validation before loading that path and does not prohibit path separators, parent-directory segments, absolute paths, encoded traversal sequences, or unknown identifiers.

If the host resolves this value as a filesystem path rather than mapping it to a fixed implementation identifier, a value containing traversal segments could escape the intended impl/ directory. This is a documentation-level insecure loading pattern; the project contains no executable loader, so successful exploitation depends on how the hosting agent interprets and implements the instruction.

Attack Path

  1. An attacker submits a market request with a crafted exchange value containing path traversal syntax.
  2. The agent follows the documented impl/{exchange}.md construction rule without first applying an exact allowlist.
  3. The resulting path resolves outside the impl/ directory.
  4. The agent reads an unrelated local Markdown or similarly reachable file.
  5. Contents of that file enter the active model context.
  6. Sensitive contents could be exposed in the response, or instructions in the loaded file could influence later agent behavior.

Impact Assessment

The potential impact is unauthorized read access to files available to the agent's filesystem-reading capability. This could disclose local configuration, internal instructions, or other sensitive textual data. If an attacker can also place a file at a re ...[truncated 378 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace path interpolation with an exact, immutable mapping:

    text
    binance -> impl/binance.md
    okx     -> impl/okx.md
    
  2. Reject every exchange identifier not exactly equal to a supported lowercase identifier.

  3. Reject values containing /, \, ., percent encoding, null bytes, drive prefixes, URI schemes, or Unicode path-separator lookalikes.

  4. Canonicalize the selected path and verify that it remains beneath the canonical project impl directory before reading it.

  5. Do not discover implementations from arbitrary user-supplied filenames.

  6. Add negative tests for parent traversal, absolute paths, encoded traversal, mixed separators, and unsupported exchange names.

  7. Define the accepted exchange values directly in the input schema as an enumeration containing only binance and okx.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill documentation, trigger descriptions, parameters, and operational guidance are entirely presented in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language audience. This can violate language/locale policy when a skill imposes a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition '用户询问行情或价格' is broad enough that ordinary conversation about markets or prices could invoke the skill unintentionally. In an agent system, over-broad activation can cause unintended external API access, consume quotas, and expose user prompts or metadata to third-party services even though the skill is read-only.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · impl/binance.md (reported line 20)May include surrounding context.

24h 行情

text
GET https://api.binance.com/api/v3/ticker/24hr
参数: symbol={pair}(去掉 /,如 BTC/USDT → BTCUSDT)

响应字段映射:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · impl/binance.md (reported line 33)May include surrounding context.

24h 行情

text
GET https://api.binance.com/api/v3/ticker/24hr
参数: symbol={pair}(去掉 /,如 BTC/USDT → BTCUSDT)

响应字段映射:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · impl/okx.md (reported line 19)May include surrounding context.

24h 行情

text
GET https://api.okx.com/api/v5/market/ticker
参数: instId={pair}(格式保持 BTC-USDT,以 - 分隔)

响应字段映射(data[0]):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · impl/okx.md (reported line 32)May include surrounding context.

24h 行情

text
GET https://api.okx.com/api/v5/market/ticker
参数: instId={pair}(格式保持 BTC-USDT,以 - 分隔)

响应字段映射(data[0]):

Static analysis

No suspicious patterns detected.