T05 · Unauthorized Access and Privilege Escalation
- Location
scrape-square.mjs:483- Finding
Chromium Security Sandbox Is Explicitly Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated Binance Square analysis purpose, but it runs Chromium with sandbox protections disabled and uses an unsafe fixed temp file for Telegram reports, so it needs review before installation.
Install only if you are comfortable running a browser scraper against Binance with Chrome sandboxing disabled. Prefer running it in a restricted account or container, avoid scan:tg unless you trust Telegram delivery for the report contents, replace the fixed /tmp Telegram file with stdin or a secure mktemp workflow, and pin dependencies with a lockfile before use.
scrape-square.mjs:483Chromium Security Sandbox Is Explicitly Disabled
SKILL.md:137Predictable Shared Temporary File Enables Symlink and Content-Replacement Attacks
package.json:11Unpinned Dependency Installation Is Not Reproducible
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
node send-telegram.mjs "message text" # send markdown
* echo "..." | node send-telegram.mjs --stdin # read from stdin
* node send-telegram.mjs --file path/to/msg.txt # read from file
* node send-telegram.mjs --test # send a ping
*
* For Markdown safety with $ signs, prefer --stdin or --file modes.
*/
import { readFileSync } from 'fs';
const TOKEN = process.env.TG_BOT_TOKEN;
const CHAT_ID = process.env.TG_CHAT_ID;
if (!TOKEN || !CHAT_ID) {
console.error('ERROR: TG_BOT_TOKEN and TG_CHAT_ID env vars are required.');
console.error(' Set them in your shell, .env file, or pass via cron environment.');
console.error(' Get a bot token from @BotFather, get your chat ID from @userinfobot.');
process.exit(1);
}
const API = `https://api.telegram.org/bot${TOKEN}`;
async function sendMessage(text, parseMode = 'Markdown') {
const truncated = text.length > 4096 ? text.slice(0, 4050) + '\n...(truncated)' : text;
const res = await fetch(`
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if (!TOKEN || !CHAT_ID) {
console.error('ERROR: TG_BOT_TOKEN and TG_CHAT_ID env vars are required.');
console.error(' Set them in your shell, .env file, or pass via cron environment.');
console.error(' Get a bot token from @BotFather, get your chat ID from @userinfobot.');
process.exit(1);
}
The skill metadata and description advertise broad trigger conditions such as crypto narrative tracking and trading signal generation, which can cause the skill to activate outside a narrowly scoped Binance Square use case. Over-broad activation increases the chance of unintended execution of scraping, report generation, or Telegram push behavior in contexts where the user did not explicitly request this skill.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
The skill ships with two Node.js scripts that need puppeteer-core installed once. After ClawHub installs this skill to ~/.claude/skills/binance-square/, run:
cd ~/.claude/skills/binance-square && npm install
The skill instructs persistent storage of detailed trading-analysis reports under a fixed directory in the user's home profile. Persistent local retention can expose sensitive research history, market positions, or behavioral data to other local users, backup systems, or later processes without any retention limit or consent prompt.
### Step 5 — Save full report
Write detailed markdown report to `~/.claude/skills/binance-square/reports/signal-YYYY-MM-DD-HHmm.md` (create the `reports/` dir if needed). Include:
- Candidates table (coin, posts, bot%, sentiment, OI, funding, liq ratio, direction)
- Per-coin direction rationale
The skill includes an optional Telegram exfiltration channel for condensed signal reports, but the user-facing description does not prominently warn that analysis results may be sent to an external service when configured. This can create an unexpected data-sharing path, especially if report contents include sensitive prompts, research, or account-linked trading information.
The browser is launched with --lang=zh-CN, requests Accept-Language: zh-CN,zh;q=0.9, and navigates specifically to https://www.binance.com/zh-CN/square. This hard-codes a locale preference in natural-language-related behavior without any opt-in or justification, which matches the language/locale policy violation criteria.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
process.exit(1);
}
const API = `https://api.telegram.org/bot${TOKEN}`;
async function sendMessage(text, parseMode = 'Markdown') {
const truncated = text.length > 4096 ? text.slice(0, 4050) + '\n...(truncated)' : text;
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"test-tg": "node send-telegram.mjs --test"
},
"dependencies": {
"puppeteer-core": "^23.0.0"
}
}
Detected: suspicious.dangerous_exec, suspicious.env_credential_access