Back to skill

Security audit

Miraix Binance Agent Firewall

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent Binance prompt-audit purpose, but it sends raw financial trading prompts to a third-party service and can be invoked implicitly without clear consent or data-minimization safeguards.

Review before installing. Use this only when you are comfortable sending the trading prompt and symbol list to Miraix, and do not include API keys, account identifiers, private portfolio details, or proprietary strategies unless the service's privacy and retention terms are acceptable. Treat its permission plans and rewrites as advisory, not as independent authorization to enable trading permissions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:24
Finding

Unrestricted Transmission of Raw Trading Prompts to a Third-Party Service

Content
View full analysis
","symbols":["",""]}' ``` ``` ### Technical Analysis The workflow instructs the agent to copy the complete raw trading prompt into an HTTP request sent to `app.miraix.fun`, a third-party service. It does not require: - Explicit user consent before external transmission. - Disclosure of the external recipient. - Detection or redaction of API keys, credentials, account identifiers, strategy details, or other confidential information. - Data minimization. - A local-only alternative for sensitive prompts. - Verification of the service's retention and privacy practices. Although HTTPS protects the request in transit, it does not prevent the receiving service from storing, processing, or disclosing the submitted data. A user may reasonably believe that a prompt provided to the agent remains within the current interaction and may not expect it to be copied verbatim to an unrelated external service. The shell example also directly interpolates the raw prompt into a single-quoted JSON body. If an implementation constructs this command through textual substitution rather than a structured HTTP client or safe argument passing, quotation characters in the prompt could corrupt the JSON or potentially create command-injection risk. The reviewed package does not contain an executable implementation proving command injection, so that aspect is a secondary implementation risk rathe ...[truncated 1356 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:34
Finding

Untrusted External API Content Is Used as Authoritative Agent Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs sending the user's raw trading prompt directly to a third-party Miraix API, but it does not require explicit user consent or warn that potentially sensitive strategy, account-behavior, or proprietary trading information will leave the local agent boundary. In a trading context, prompts may contain confidential alpha, operational rules, symbols of interest, or risk preferences, so undisclosed transmission creates a real privacy and data-governance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This curl example performs external transmission of user-supplied content to a remote service. While external calls are core to the skill's design, the security issue is that the skill operationalizes exfiltration of raw user input without guardrails such as consent, minimization, or warnings against including API keys, account IDs, or proprietary strategies.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

  1. Run:
bash
curl -sS -X POST https://app.miraix.fun/api/binance-agent-firewall \
  -H 'Content-Type: application/json' \
  -d '{"prompt":"<raw-trading-prompt>","symbols":["<symbol-1>","<symbol-2>"]}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill enables implicit invocation but does not define narrow activation constraints in this file, which increases the chance it will be triggered in broader contexts than intended. Because this skill influences decisions about Binance trading prompt audits and account permissions, an unintended invocation could cause incorrect trust decisions, overly permissive guidance, or unsafe rewrites in financially sensitive workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.