T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:10- Finding
Unnecessary Access to Exchange API Credentials for Public Market Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:10-11, with related declarations inimpl/binance.md:13-14andimpl/okx.md:11-12
Vulnerability Type: Excessive credential access and violation of least privilege
Risk Level: MediumVulnerable Code Snippets
SKILL.md:10-11:yaml "requires": { "env": ["BINANCE_API_KEY"] }, "primaryEnv": "BINANCE_API_KEY",impl/binance.md:13-14:text Authentication: API Key header (read-only endpoints do not require signing) API key environment variable: BINANCE_API_KEYimpl/okx.md:11-12:text Authentication: Public market endpoints require no signature; private endpoints require OK-ACCESS-KEY and a signature API key environment variables: OKX_API_KEY, OKX_API_SECRET, OKX_PASSPHRASETechnical Analysis
The skill only documents calls to public market-data endpoints:
- Binance
/api/v3/ticker/24hr - Binance
/api/v3/klines - OKX
/api/v5/market/ticker - OKX
/api/v5/market/candles
These endpoints do not require account credentials. Nevertheless, the skill metadata requires
BINANCE_API_KEY, while the implementation documents access to Binance and OKX credential variables. This violates least privilege because sensitive financial-account credentials are made available for a task that can be completed anonymously.No direct exfiltration mechanism was found. The risk arises from unnecessarily exposing credentials to the skill or agent execution context, where they may subsequently be included in headers, gateway logs, debugging output, generated responses, or other tool calls.
Attack Path
- A user installs or activates the market-monitor skill.
- The runtime observes the declared
BINANCE_API_KEYrequirement and exposes or requests that credential. - If the OKX implementation is used, an operator may also configure the documented OKX key, secret, and passphrase.
- The skill invokes public market end ...[truncated 1001 chars]
- Binance
- Remediation
View remediation
Remediation Suggestions
- Remove
BINANCE_API_KEYfrom the skill's required environment variables and removeprimaryEnv. - Remove the Binance and OKX credential-variable declarations from the public market-data implementations.
- Do not attach authentication headers to any of the documented public endpoints.
- If private account functionality is added later, place it in a separate, explicitly enabled skill with a distinct trust boundary.
- For any future authenticated functionality, require exchange keys with the minimum possible permissions, disable withdrawals, apply IP restrictions, and use a dedicated credential rather than a user's general trading key.
- Redact API keys, signatures, passphrases, and authentication headers from gateway and application logs.
- Add automated tests verifying that public market-data requests contain no authorization or exchange-key headers.
- Remove
