Back to skill

Security audit

Passive Income Claw

Security checks for vulnerabilities and agentic risk

Overview

This Binance yield skill is disclosed as useful, but it can automatically make account-changing Earn and margin-borrowing actions without strong enforced safeguards.

Read this carefully before installing. Use a Binance API key with withdrawals, futures, and spot trading disabled, avoid enabling margin unless you deliberately want leveraged debt exposure, and keep confirmation-first mode until the transaction scripts enforce authorization internally. Do not enable auto mode or the cron workflow unless you are comfortable with recurring account-changing actions under the configured limits.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
bin/earn-api.ts:22
Finding

State-Changing Binance Clients Do Not Enforce Authorization Controls

Content
View full analysis
{ if (typeof args.productId !== "string") die("Missing --productId"); if (typeof args.amount !== "string") die("Missing --amount"); out(await signedRequest("POST", "/sapi/v1/simple-earn/flexible/subscribe", { productId: args.productId, amount: args.amount, })); }, "redeem-flexible": async (args) => { if (typeof args.productId !== "string") die("Missing --productId"); const params: Record = { productId: args.productId }; if (args.all === true) params.redeemAll = "true"; else if (typeof args.amount === "string") params.amount = args.amount; else die("Missing --amount or --all"); out(await signedRequest("POST", "/sapi/v1/simple-earn/flexible/redeem", params)); }, "subscribe-locked": async (args) => { if (typeof args.projectId !== "string") die("Missing --projectId"); if (typeof args.amount !== "string") die("Missing --amount"); out(await signedRequest("POST", "/sapi/v1/simple-earn/locked/subscribe", { projectId: args.projectId, amount: args.amount, })); }, "redeem-locked": async (args) => { if (typeof args.positionId !== "string") die("Missing --positionId"); out(await signedRequest("POST", "/sapi/v1/simple-earn/locked/redeem", { positionId: args.positionId, })); }, ``` `bin/margin-api.ts:33-53`: ```ts borrow: async (args) => { if (typeof args.asset !== "string") die("Missing --asset"); if (typeof args.amount !== "string") die("Missing --amount"); out(await signedRequest("POST", "/sapi/v1/margin/borrow-repay", { asset: args.asset, ...[truncated 4011 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scan.md:74
Finding

API-Derived JSON Is Unsafely Interpolated into Shell Commands

Content
View full analysis
' | node {baseDir}/bin/snapshot.ts diff --threshold 0.5 ``` `scan.md:129-131`: ```bash echo '' | node {baseDir}/bin/snapshot.ts update ``` ### Technical Analysis The scan workflow instructs the Agent to place generated candidate JSON directly inside a single-quoted shell argument. Candidate objects can contain product names and other metadata originating from Binance API responses. JSON escaping does not make a string safe for shell interpolation. A single quote contained in any interpolated value terminates the shell's quoted argument. Subsequent shell metacharacters can then be interpreted as command syntax rather than data. For example, a generated value containing a sequence conceptually equivalent to: ```text '; attacker-command; echo ' ``` would break the intended quoting if inserted verbatim into the documented command. The shell could execute the injected command before piping the remaining output into `snapshot.ts`. This is distinct from JSON parser safety: the unsafe interpretation occurs in the shell before `snapshot.ts` receives stdin. The eventual `JSON.parse()` call therefore does not mitigate the injection. Exploitation requires attacker-influenced metadata to reach the generated candidates or another untrusted value to be included in that JSON. The audited code does not demonstrate direct attacker control over Binance's official product metadata, so practical exploitability depends on the upstream data path or compromised API responses. The command construction remains unsafe and should not be used with network-derived content. ### Attack Path 1. The scan retrieves Earn product data and uses remote metadata to build a candidate JSON array. 2. An attacker-contr ...[truncated 1347 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (49)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The auto-mode row states the system may act when the user says nothing, implying background execution without a fresh, explicit invocation. For a skill connected to Binance Earn and margin-related workflows, ambiguous autonomous activation can lead to unintended subscriptions or financial exposure based on stale preferences.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 119)May include surrounding context.

bash
clawhub update passive-income-claw --remove
rm -rf ~/passive-income-claw  # 可选:删除数据文件

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 119)May include surrounding context.

bash
clawhub update passive-income-claw --remove
rm -rf ~/passive-income-claw  # 可选:删除数据文件

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented inclusion of cross-margin borrowing, repayment, liability inspection, and interest lookup materially expands the financial-risk surface beyond a passive-income/earn assistant. Users invoking a seemingly low-risk yield tool could be steered into leveraged or debt-creating operations that are not justified by the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented inclusion of cross-margin borrowing, repayment, liability inspection, and interest lookup materially expands the financial-risk surface beyond a passive-income/earn assistant. Users invoking a seemingly low-risk yield tool could be steered into leveraged or debt-creating operations that are not justified by the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented inclusion of cross-margin borrowing, repayment, liability inspection, and interest lookup materially expands the financial-risk surface beyond a passive-income/earn assistant. Users invoking a seemingly low-risk yield tool could be steered into leveraged or debt-creating operations that are not justified by the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented inclusion of cross-margin borrowing, repayment, liability inspection, and interest lookup materially expands the financial-risk surface beyond a passive-income/earn assistant. Users invoking a seemingly low-risk yield tool could be steered into leveraged or debt-creating operations that are not justified by the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented inclusion of cross-margin borrowing, repayment, liability inspection, and interest lookup materially expands the financial-risk surface beyond a passive-income/earn assistant. Users invoking a seemingly low-risk yield tool could be steered into leveraged or debt-creating operations that are not justified by the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented inclusion of cross-margin borrowing, repayment, liability inspection, and interest lookup materially expands the financial-risk surface beyond a passive-income/earn assistant. Users invoking a seemingly low-risk yield tool could be steered into leveraged or debt-creating operations that are not justified by the stated purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad and overlap with ordinary financial conversation such as 'earn', 'yield', or 'what opportunities suit me'. For a skill that can reach account data and potentially execute subscriptions or interact with margin-related scripts, overbroad invocation materially raises the risk of unintended activation and unsafe action chaining.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
| `bin/earn-api.ts` | Binance Earn API + **账户资产明细查询** (`balance` 命令) |

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Cross-margin borrowing and repayment are debt-creating, account-affecting functions that are substantially more dangerous than passive income subscriptions. In this context, their presence is unjustified and could enable accidental or manipulated leverage usage under the cover of an innocuous earn assistant.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
| `bin/log.ts` | Execution log append & query |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file exposes direct cross-margin borrow and repay operations even though the skill is described as a passive-income/Binance Earn assistant. That scope mismatch is dangerous because a user or calling agent could trigger leveraged debt actions under the guise of a low-risk yield product workflow, causing financial loss and violating user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Cross-margin debt management is unjustified in the context of a passive-income assistant and creates the ability to incur or modify liabilities on the user's account. Because borrowing is an active leveraged trading primitive rather than a passive yield action, its presence materially increases the chance of harmful or unauthorized financial operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill introduces margin borrowing, debt management, and repayment flows that materially expand its authority beyond the stated passive-income earn/subscription purpose in the manifest. This is dangerous because users invoking a low-risk 'passive income' assistant could be routed into leveraged borrowing behavior with liquidation and debt exposure that is not clearly scoped by the skill metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Margin borrowing is not justified by the advertised purpose of helping users find and subscribe to passive-income earn opportunities. In this context, adding borrowing enables leveraged financial actions that can create liabilities, interest costs, and cascading losses, especially because users may reasonably expect only spot balance deployment rather than debt creation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill expands from passive earn recommendations into leveraged margin borrowing to fund subscriptions, which is materially riskier than the stated passive-income scope. This scope drift can cause users or higher-level agents to invoke the skill expecting low-risk earn actions while it performs debt-incurring trading behavior with liquidation exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file permits automatic execution of margin-borrow actions in auto mode when simple thresholds are met, despite the skill being framed as passive-income assistance. Autonomous debt creation and asset subscription without an immediate, transaction-specific user confirmation can expose the user to liquidation risk, variable borrow costs, and losses from market moves or rate changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-mode section authorizes automatic borrow-and-subscribe execution based on internal checks, but it does not require a clear real-time warning that the agent is about to take on debt and lock assets into an earn product. In financial systems, autonomous high-risk actions without conspicuous user-facing notice materially increase the chance of unexpected losses and disputes.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad enough to activate on ordinary discussion such as 'what's available' or 'recommend,' which can unexpectedly launch a financial scan workflow. In combination with push notifications and possible auto-execution, accidental invocation increases the chance of undesired account-impacting behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Adding borrow-to-earn through margin introduces a materially different and riskier capability than passive Binance Earn subscriptions, including leverage, liquidation exposure, and variable borrowing costs. Because this skill is framed as passive-income assistance, expanding into margin borrowing can mislead users and create account-impacting actions outside the expected scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The markdown describes automatic execution of financial actions but does not prominently warn the user that the skill may place subscriptions or invoke borrowing actions affecting their Binance account. Lack of an explicit warning undermines informed consent in a high-risk domain where actions can lock funds, incur interest, or expose collateral.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented trigger examples are broad, natural-language phrases that can plausibly appear in ordinary conversation. In a financial skill that can recommend or initiate earn subscriptions, overly broad activation increases the risk of accidental invocation and unintended account actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares access to sensitive Binance API credentials and appears to require networked scripts, but it does not define an explicit tool/permission scope. That weakens containment and reviewability, making it easier for later-added scripts to use secrets or network access beyond what users and the platform expect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.