T09 · Insecure Skill Coding Practices
- Location
scripts/binance_square.py:9- Finding
Unverified Third-Party API Use with a Hardcoded Tracking Identifier
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly performs the advertised feed fetch, but it needs Review because it sends requests to a non-obvious bmwweb.cc endpoint with a fixed cookie and UUID while presenting the data as Binance Square content.
Install only if you are comfortable with the skill contacting www.bmwweb.cc, sending the embedded bnc-uid/Bnc-Uuid values, and trusting that endpoint for financial social-feed content. Prefer a version that uses a documented official Binance endpoint or clearly discloses the third-party source, removes fixed identifiers, and sanitizes remote text before printing.
scripts/binance_square.py:9Unverified Third-Party API Use with a Hardcoded Tracking Identifier
scripts/binance_square.py:67Terminal Control-Sequence Injection Through Untrusted Feed Content
The skill clearly instructs the agent to perform an external network request but does not declare any tool scope, permissions, or allowed-tools constraints. This creates an over-broad execution surface where a caller or host may not realize the skill transmits data externally, increasing the risk of unintended outbound requests and weak reviewability.
The skill includes concrete request headers and cookie values for an external API but does not warn that invoking it transmits request metadata and cookie-like identifiers off-platform. This is dangerous because users or operators may unknowingly send persistent identifiers or session-related values to a third party, creating privacy, compliance, and possible credential-handling risks.
The usage guidance says to directly invoke the skill, without defining when it should or should not run, what user consent is needed, or what prerequisites apply. That makes accidental or overly broad invocation more likely, especially since the skill performs external requests and handles request metadata including cookies.
This code hard-codes a Chinese locale in natural-language and protocol fields, including the Referer path '/zh-CN' and cookie 'lang=zh-CN'. The file also presents all user-facing text in Chinese, with no opt-in or documented region-specific requirement, which matches the language/locale policy violation criteria.
The script sends outbound requests to a third-party domain using hardcoded headers, including a static cookie and UUID, without validating provenance or making this data flow explicit to the user. This creates privacy and trust risks because using a non-official-looking host to retrieve Binance-related content could expose request metadata and encourage transmission to an unverified external service.
url = "https://www.bmwweb.cc/bapi/composite/v9/friendly/pgc/feed/feed-recommend/list"
payload = {"pageIndex": page, "pageSize": size, "scene": "web-homepage", "contentIds": []}
try:
r = requests.post(url, headers=HEADERS, json=payload, timeout=10)
r.raise_for_status()
d = r.json()
return d.get("data", {}).get("vos", []) if d.get("success") else []
The documented request headers hard-code a Chinese locale via the Referer path '/zh-CN/square' and the cookie value 'lang=zh-CN'. This is a natural-language locale constraint presented without user opt-in or explanation, which can violate language or locale policy expectations.
The manifest description limits the output to 内容、浏览量、评论数到表格, while the actual printed table contains additional fields 作者 and 时间. This is a mild description-behavior mismatch because the code exposes more data than the stated output scope, even though it is related to the same posts.
No suspicious patterns detected.