Back to skill

Security audit

币安 AI 交易员驾照局

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent trading-risk review purpose, but it can send sensitive trading and behavioral details to a third-party service without a clear consent step, and it allows implicit invocation.

Review before installing. Use this skill only when you intentionally want a third-party service to evaluate an AI trading agent. Do not include API keys, account identifiers, wallet addresses, contact details, or private financial information in the request. Treat generated license results and share-image links as shareable artifacts that may expose the agent name and assessment summary.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:31
Finding

Behavioral and Trading Context Sent to a Third-Party Service Without an Explicit Consent Gate

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:126
Finding

Trading Assessment Data Embedded in a Share-Image URL Query Parameter

Content
View full analysis
``` ``` ### Technical Analysis The documented sharing mechanism serializes the agent name and assessment results into a `payload` query parameter. URL encoding only makes data safe for transport; it does not encrypt or conceal the content. Query strings may be retained or exposed through: - Web server, CDN, reverse-proxy, and monitoring logs - Browser history and synchronized browser profiles - Analytics platforms - Copied or forwarded links - Screenshots and support records - Referrer information, depending on browser and response policy - Caches and intermediary infrastructure The payload contains an agent name, license level, board decision, headline, and summary. These fields may reveal trading-risk judgments or behavioral conclusions and may become identity-linked if `agentName` identifies a person or account. ### Attack Path 1. The agent serializes `agentName`, `currentLevel`, `headline`, `boardDecision`, and `summary` into JSON. 2. The serialized data is URL-encoded and appended to the `payload` query parameter. 3. The user or agent requests, displays, copies, or shares the resulting URL. 4. The complete URL is recorded in one or more histories, logs, monitoring systems, or communications. 5. A party with access to those records extracts and URL-decodes the payload. 6. The party recovers the assessment content without needing access to the original conversation. ### Impact Assessment This issue does not provide code execution, account control, or elevated system privileges. The scope is disclosure and per ...[truncated 316 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Enabling implicit invocation without a narrowly bounded activation description creates a strong risk that the skill will be auto-selected in adjacent finance or trading conversations. In a high-sensitivity domain like trading qualification and risk controls, unintended activation can cause unauthorized profiling, confusing recommendations, or policy-sensitive outputs without deliberate user selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions and usage guidance are entirely in Chinese, which effectively imposes a single language on users. Under the policy, locale or language constraints should be optional, user-selected, or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill instructs the agent to send user-provided trading-related data to an external third-party endpoint. Even though the data appears operational rather than highly sensitive, fields like psychological state, sleep hours, loss streak, and strategy details can reveal sensitive personal or proprietary information and may be transmitted without explicit user consent or minimization.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

推荐调用方式

bash
curl -sS -X POST https://binance-agent-license-bureau.vercel.app/api/license-bureau \
  -H 'Content-Type: application/json' \
  -d '{
    "agentName": "Night Fury",

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default prompt requests a wide bundle of outputs and implicitly steers the model to perform a full adjudication workflow whenever the skill is invoked. Because the activation scope is not tightly constrained to explicit user intent, this increases the chance of unintended triggering and over-collection or over-generation of trading-evaluation content in contexts where the user did not clearly ask for it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt hard-codes Chinese output for the Binance Square record without indicating that language choice follows user preference. This can override user expectations, reduce transparency, and cause unintended disclosure or miscommunication if the conversation is in another language or requires locale-sensitive compliance wording.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.