Back to skill

Security audit

binance-square-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated Binance Square analysis purpose, but it runs Chromium with sandbox protections disabled and uses an unsafe fixed temp file for Telegram reports, so it needs review before installation.

Install only if you are comfortable running a browser scraper against Binance with Chrome sandboxing disabled. Prefer running it in a restricted account or container, avoid scan:tg unless you trust Telegram delivery for the report contents, replace the fixed /tmp Telegram file with stdin or a secure mktemp workflow, and pin dependencies with a lockfile before use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scrape-square.mjs:483
Finding

Chromium Security Sandbox Is Explicitly Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:137
Finding

Predictable Shared Temporary File Enables Symlink and Content-Replacement Attacks

Content
View full analysis
/tmp/tg-signal.txt <<'EOF' *广场信号* YYYY-MM-DD HH:MM *Feed* (N posts, X% bot) COIN: N mentions, BEAR/BULL | ... *Drill Bot%* #COIN: N posts, X% bot, sentiment Y *方向判断* COIN: *LONG/SHORT/AVOID* [emoji] OI +X% | Funding X% | Liq 多M:空M | 广场 BEAR/BULL 理由: [one sentence] *涨幅榜* TOP1 +X% | TOP2 +X% EOF node ~/.claude/skills/binance-square/send-telegram.mjs --file /tmp/tg-signal.txt ``` ### Technical Analysis The Skill instructions direct the Agent to write Telegram report content to the fixed path `/tmp/tg-signal.txt`. Shared temporary directories are commonly writable by multiple local users. The workflow does not: - Create the file atomically. - Reject symbolic links. - Verify ownership or file type. - Set restrictive permissions explicitly. - Keep an already-open file descriptor between writing and sending. - Remove the file after transmission. This creates two related time-of-check/time-of-use risks. First, a local attacker may pre-create the path as a symbolic link, causing shell redirection to overwrite another file writable by the Skill's user. Second, an attacker may replace or modify the temporary file after it is written but before `send-telegram.mjs` reads it, causing attacker-controlled content to be transmitted. The report can also remain on disk after execution and may be readable according to the process umask and temporary-directory access controls. ### Attack Path #### Symlink Overwrite Path 1. A local attacker predicts the constant path `/tmp/tg-signal.txt`. 2. Before the scan reaches the Telegram step, the attacker creates that path as a symbolic link to another file writable by the Skill's user. 3. The Agent executes `cat > /tmp/tg-signal.txt`. 4. Shell redirection follows the symbolic link and truncates or overwrites ...[truncated 1462 chars]
Remediation
View remediation
"$tmp_file" <<'EOF' REPORT CONTENT EOF node ~/.claude/skills/binance-square/send-telegram.mjs --file "$tmp_file" ``` 3. In `send-telegram.mjs`, inspect the file with `lstatSync` and reject symbolic links and non-regular files before reading. 4. Where supported, open temporary files using exclusive creation and no-follow semantics. 5. Verify that the file is owned by the current user and has no group or world permissions. 6. Delete temporary report files in a guaranteed cleanup handler, including error and interruption paths. 7. For stronger protection against replacement races, open the file once and transmit data from the already-open descriptor rather than validating and reopening it by path. ]]>

T08 · Insecure Dependencies

Note
Location
package.json:11
Finding

Unpinned Dependency Installation Is Not Reproducible

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (9)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · send-telegram.mjs (reported line 19)May include surrounding context.

js
node send-telegram.mjs "message text"           # send markdown
 *   echo "..." | node send-telegram.mjs --stdin     # read from stdin
 *   node send-telegram.mjs --file path/to/msg.txt   # read from file
 *   node send-telegram.mjs --test                   # send a ping
 *
 * For Markdown safety with $ signs, prefer --stdin or --file modes.
 */

import { readFileSync } from 'fs';

const TOKEN = process.env.TG_BOT_TOKEN;
const CHAT_ID = process.env.TG_CHAT_ID;

if (!TOKEN || !CHAT_ID) {
  console.error('ERROR: TG_BOT_TOKEN and TG_CHAT_ID env vars are required.');
  console.error('  Set them in your shell, .env file, or pass via cron environment.');
  console.error('  Get a bot token from @BotFather, get your chat ID from @userinfobot.');
  process.exit(1);
}

const API = `https://api.telegram.org/bot${TOKEN}`;

async function sendMessage(text, parseMode = 'Markdown') {
  const truncated = text.length > 4096 ? text.slice(0, 4050) + '\n...(truncated)' : text;
  const res = await fetch(`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · send-telegram.mjs (reported line 24)May include surrounding context.

js
if (!TOKEN || !CHAT_ID) {
  console.error('ERROR: TG_BOT_TOKEN and TG_CHAT_ID env vars are required.');
  console.error('  Set them in your shell, .env file, or pass via cron environment.');
  console.error('  Get a bot token from @BotFather, get your chat ID from @userinfobot.');
  process.exit(1);
}

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata and description advertise broad trigger conditions such as crypto narrative tracking and trading signal generation, which can cause the skill to activate outside a narrowly scoped Binance Square use case. Over-broad activation increases the chance of unintended execution of scraping, report generation, or Telegram push behavior in contexts where the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

First-Time Setup

The skill ships with two Node.js scripts that need puppeteer-core installed once. After ClawHub installs this skill to ~/.claude/skills/binance-square/, run:

bash
cd ~/.claude/skills/binance-square && npm install

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The skill instructs persistent storage of detailed trading-analysis reports under a fixed directory in the user's home profile. Persistent local retention can expose sensitive research history, market positions, or behavioral data to other local users, backup systems, or later processes without any retention limit or consent prompt.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
### Step 5 — Save full report

Write detailed markdown report to `~/.claude/skills/binance-square/reports/signal-YYYY-MM-DD-HHmm.md` (create the `reports/` dir if needed). Include:

- Candidates table (coin, posts, bot%, sentiment, OI, funding, liq ratio, direction)
- Per-coin direction rationale

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill includes an optional Telegram exfiltration channel for condensed signal reports, but the user-facing description does not prominently warn that analysis results may be sent to an external service when configured. This can create an unexpected data-sharing path, especially if report contents include sensitive prompts, research, or account-linked trading information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The browser is launched with --lang=zh-CN, requests Accept-Language: zh-CN,zh;q=0.9, and navigates specifically to https://www.binance.com/zh-CN/square. This hard-codes a locale preference in natural-language-related behavior without any opt-in or justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · send-telegram.mjs (reported line 29)May include surrounding context.

js
process.exit(1);
}

const API = `https://api.telegram.org/bot${TOKEN}`;

async function sendMessage(text, parseMode = 'Markdown') {
  const truncated = text.length > 4096 ? text.slice(0, 4050) + '\n...(truncated)' : text;

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"test-tg": "node send-telegram.mjs --test"
  },
  "dependencies": {
    "puppeteer-core": "^23.0.0"
  }
}

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scrape-square.mjs:63

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scrape-square.mjs:34