T09 · Insecure Skill Coding Practices
- Location
SKILL.md:31- Finding
Behavioral and Trading Context Sent to a Third-Party Service Without an Explicit Consent Gate
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent trading-risk review purpose, but it can send sensitive trading and behavioral details to a third-party service without a clear consent step, and it allows implicit invocation.
Review before installing. Use this skill only when you intentionally want a third-party service to evaluate an AI trading agent. Do not include API keys, account identifiers, wallet addresses, contact details, or private financial information in the request. Treat generated license results and share-image links as shareable artifacts that may expose the agent name and assessment summary.
SKILL.md:31Behavioral and Trading Context Sent to a Third-Party Service Without an Explicit Consent Gate
SKILL.md:126Trading Assessment Data Embedded in a Share-Image URL Query Parameter
Enabling implicit invocation without a narrowly bounded activation description creates a strong risk that the skill will be auto-selected in adjacent finance or trading conversations. In a high-sensitivity domain like trading qualification and risk controls, unintended activation can cause unauthorized profiling, confusing recommendations, or policy-sensitive outputs without deliberate user selection.
The natural-language instructions and usage guidance are entirely in Chinese, which effectively imposes a single language on users. Under the policy, locale or language constraints should be optional, user-selected, or clearly justified as region-specific.
The skill instructs the agent to send user-provided trading-related data to an external third-party endpoint. Even though the data appears operational rather than highly sensitive, fields like psychological state, sleep hours, loss streak, and strategy details can reveal sensitive personal or proprietary information and may be transmitted without explicit user consent or minimization.
curl -sS -X POST https://binance-agent-license-bureau.vercel.app/api/license-bureau \
-H 'Content-Type: application/json' \
-d '{
"agentName": "Night Fury",
The default prompt requests a wide bundle of outputs and implicitly steers the model to perform a full adjudication workflow whenever the skill is invoked. Because the activation scope is not tightly constrained to explicit user intent, this increases the chance of unintended triggering and over-collection or over-generation of trading-evaluation content in contexts where the user did not clearly ask for it.
The default prompt hard-codes Chinese output for the Binance Square record without indicating that language choice follows user preference. This can override user expectations, reduce transparency, and cause unintended disclosure or miscommunication if the conversation is in another language or requires locale-sensitive compliance wording.
No suspicious patterns detected.