Back to skill

Security audit

Binance Square Post

Security checks for vulnerabilities and agentic risk

Overview

This skill is for posting to Binance Square, but it asks users to store a live posting API key in the skill file and supports scheduled public posting without clear review controls.

Install only if you are comfortable giving the skill authority to publish under your Binance Square identity. Use a dedicated, least-privilege API key, avoid putting live keys in tracked or shared files, review generated posts before publishing, and enable cron posting only if you accept unattended public posts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:29
Finding

Plaintext Binance API Key Storage in Skill Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:29-38
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

The Skill instructs users to place their Binance Square OpenAPI key directly inside SKILL.md:

yaml
config:
  accounts:
    - name: default
      api_key: 你的API密钥

Technical Analysis

Storing a live API key in a Markdown Skill definition violates secure secret-management practices. Skill directories may be committed to version control, copied between systems, included in backups, submitted for support, indexed by development tools, or exposed to other local processes and agents.

Although the document separately advises users not to disclose the complete key publicly, that warning does not mitigate the risk introduced by directing users to persist the credential in a shareable project document.

An exposed key could be supplied through the documented X-Square-OpenAPI-Key HTTP header to authenticate requests to the Binance Square publishing endpoint.

Attack Path

  1. A user follows the configuration instructions and writes a valid Binance Square OpenAPI key into SKILL.md.
  2. The Skill directory is committed, shared, archived, backed up, or accessed by another user or local component.
  3. An attacker reads and extracts the plaintext API key.
  4. The attacker sends requests to the documented Binance Square content publishing endpoint using the stolen key.
  5. Unauthorized content is published under the affected user's Binance Square identity until the key is revoked, expires, or reaches its posting limit.

Impact Assessment

Exploitation does not grant general operating-system or Binance account privileges based on the reviewed files. The scope is limited to the permissions associated with the exposed Square OpenAPI key. Those permissions may allow unauthorized publication of posts, reputational damage, spam or policy violations, consumption of posting qu ...[truncated 76 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not store API keys in SKILL.md, README.md, or any other version-controlled project document.
  • Retrieve the credential at runtime from a protected secret manager or an environment variable such as BINANCE_SQUARE_API_KEY.
  • If local configuration is required, use a file excluded from version control and restrict its permissions to the owning user.
  • Provide only placeholder values in an example file such as .env.example.
  • Add relevant secret-bearing files to .gitignore.
  • Implement automated secret scanning in source-control and release workflows.
  • Document immediate key revocation and rotation procedures for suspected exposure.
  • Configure the API key with the minimum permissions supported by Binance and monitor it for unauthorized publishing activity.

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:7
Finding

README Repeats Unsafe Plaintext API Key Configuration

Content
View full analysis

Vulnerability Details

File Location: README.md:7-16
Vulnerability Type: Plaintext sensitive credential storage guidance
Risk Level: Medium

The README independently directs users to edit SKILL.md and insert their Binance Square OpenAPI key:

yaml
config:
  accounts:
    - name: default
      api_key: 你的Binance_Square_OpenAPI_Key

Technical Analysis

The quick-start documentation reinforces an insecure deployment pattern by instructing users to persist a live credential in a project document. README-driven setup instructions are likely to be followed directly, making accidental disclosure through source control, package distribution, backups, or directory sharing reasonably foreseeable.

The placeholder itself is not a leaked credential. The vulnerability is the prescribed storage method, which causes users to replace that placeholder with sensitive plaintext in a file not designed as a protected secret store.

Attack Path

  1. A user follows the README and replaces the placeholder with a valid API key.
  2. The modified Skill directory is pushed to a repository, distributed, archived, or exposed to another local principal.
  3. An attacker searches the file for the api_key field and obtains the credential.
  4. The attacker places the key in the X-Square-OpenAPI-Key header of a request to the documented Binance endpoint.
  5. The attacker publishes unauthorized Square posts within the key's granted permissions.

Impact Assessment

A successful attacker may exercise the Binance Square publishing authority represented by the exposed key. Likely consequences include unauthorized posts, impersonation of the account owner on Square, reputational harm, posting-quota exhaustion, and enforcement action against the affected account. No evidence in the reviewed project shows that the key grants broader host-system access or general Binance account control.

Remediation
View remediation

Remediation Suggestions

  • Replace the README instructions with environment-variable or secret-manager configuration.
  • Use a non-secret example such as BINANCE_SQUARE_API_KEY=<set-in-secret-store>.
  • Explicitly warn users never to insert live credentials into SKILL.md or other tracked files.
  • Supply a .gitignore entry for any optional local secret file.
  • Recommend restrictive file permissions and least-privilege API-key settings.
  • Add credential rotation guidance and automated repository secret scanning.
  • Update both README.md and SKILL.md together so users are not presented with conflicting security guidance.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to configure an API key and send post content to Binance Square, but it does not clearly disclose that both user-supplied content and the credential will be transmitted to a third-party service. This creates informed-consent and privacy risks, especially because users may not realize the scope of outbound data handling when enabling the skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The documented behavior explicitly sends user-provided content and an API key in a request to an external Binance endpoint. In the context of a posting skill this transmission is expected, but it is still security-relevant because credentials are handled and user text leaves the local environment, creating exposure if users are not clearly informed or if keys are overprivileged.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

bash
# 测试发帖
curl -X POST 'https://www.binance.com/bapi/composite/v1/public/pgc/openApi/content/add' \
  -H 'X-Square-OpenAPI-Key: 你的API密钥' \
  -H 'Content-Type: application/json' \
  -H 'clienttype: binanceSkill' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

示例

bash
curl -X POST 'https://www.binance.com/bapi/composite/v1/public/pgc/openApi/content/add' \
  -H 'X-Square-OpenAPI-Key: 你的API密钥' \
  -H 'Content-Type: application/json' \
  -H 'clienttype: binanceSkill' \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents an optional cron-based auto-posting feature but does not clearly warn that scheduled runs can publish content to a public social platform without per-post user confirmation. In this context, that is a real safety issue because the action is externally visible and irreversible enough to create reputational, compliance, or spam risks if the generated content is wrong, manipulated by upstream news sources, or triggered unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All natural-language instructions and examples in the file are presented only in Chinese, with no indication that users can choose another language. Per the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.