T09 · Insecure Skill Coding Practices
- Location
SKILL.md:63- Finding
Long-Lived Bearer Token Used for Financially Privileged MCP Operations
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:63-93; duplicated inREADME.md:11-31
Vulnerability Type: Long-lived, insufficiently scoped bearer-token configuration
Risk Level: MediumVulnerable Code
SKILL.md:63-85:markdown ## Quick Start 1. Sign in at [askgina.ai](https://askgina.ai) and open **Agent Setup** (sidebar or `https://askgina.ai/agent-setup`). 2. Give your token a name (e.g. "OpenClaw on MacBook") and click **Generate Token**. 3. Copy the connection config immediately — the token is only shown once. 4. Paste the config into your MCP client: ```json { "mcpServers": { "gina-predictions": { "transport": "http", "url": "https://askgina.ai/ai/predictions/mcp", "headers": { "Authorization": "Bearer <PASTE_TOKEN_HERE>" } } } }- Restart your MCP client and ask:
"What can you do with gina".
text `SKILL.md:87-93`: ```markdown ## How It Works - **Auth**: Long-lived JWT token generated at `https://askgina.ai/agent-setup`. Tokens expire after 90 days. You can have up to 5 active tokens and revoke any of them from the Agent Setup page. - **Wallets**: Self-custodial via [Privy](https://privy.io). You own your keys. - **Trades**: Execute on-chain on Polymarket (Polygon / USDC). - **Gas**: Gina provides gas sponsorship to help cover transaction fees. - **Safety**: Large trades require explicit confirmation before executing.The same persistent bearer-token configuration and 90-day expiration period are documented in
README.md:11-31.Technical Analysis
The Skill instructs users to place a long-lived bearer JWT directly in persistent MCP client configuration. The token is then transmitted to the declared third-party endpoint,
https://askgina.ai/ai/predictions/mcp, whenever the MCP service is accessed.Network transmission is necessary for the Skill's declared remote-service functional ...[truncated 2591 chars]
- Restart your MCP client and ask:
- Remediation
View remediation
Remediation Suggestions
- Introduce granular token scopes. Provide separate permissions for market discovery, portfolio reads, trading, order cancellation, redemption, and automation management.
- Default to read-only access. Newly generated tokens should be read-only unless the user explicitly enables each fund-affecting capability.
- Reduce token lifetime. Prefer short-lived access tokens backed by narrowly protected refresh credentials or an interactive reauthorization flow.
- Avoid literal secret storage in configuration. Document integrations with operating-system keychains, MCP secret providers, or environment-variable references rather than requiring the JWT value directly in a configuration file.
- Require transaction authorization. Require explicit, transaction-bound confirmation for every trade, cancellation, redemption, and automation that can move or commit funds—not only transactions categorized as large.
- Support enforceable financial limits. Add per-transaction, daily cumulative, market-specific, and automation spending limits enforced by the server.
- Constrain automation authority. Automation tokens should have independent scopes, expiration times, allowed markets, maximum order sizes, and maximum cumulative expenditure.
- Improve credential monitoring. Expose token last-use information, source metadata, security notifications, rapid revocation, and automatic revocation when suspicious access is detected.
- Harden the documentation. Explicitly warn users not to commit, synchronize, log, or share MCP configuration files containing bearer tokens, and document secure file-permission requirements.
