Back to skill

Security audit

binance-spot-trader

Security checks for vulnerabilities and agentic risk

Overview

This is a live automated crypto-trading skill whose documented safety controls do not match the code, creating a real risk of unintended trades or losses.

Review this carefully before installing. Use only withdrawal-disabled, IP-restricted Binance keys on a limited sub-account, and do not enable cron or live trading until the code enforces DCA intervals, position limits, stop-loss, and take-profit behavior. Consider disabling USE_LLM unless you are comfortable sending trading prompts to SkillBoss.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/trader.py:17
Finding

Documented Position Limits, Stop-Loss, and Take-Profit Controls Are Not Enforced

Content
View full analysis
= 10: # Binance minimum place_order(symbol, "BUY", qty) else: log.info(f" Skip: trade size ${trade_usdt:.2f} below $10 minimum") elif signal == "SELL": # Check if we hold this asset base_asset = symbol.replace("USDT", "") held = get_balance(base_asset) if held * current_price > 10: place_order(symbol, "SELL", held) else: log.info(f" No {base_asset} position to sell") ``` ### Technical Analysis The application parses configuration values for maximum concurrent positions, take-profit percentage, and stop-loss percentage, but those values are never used in the trading decision or order-placement paths. Buy orders are submitted as unprotected market orders. No check counts existing positions before a purchase, and no linked protective orders are created after execution. This conflicts with the controls documented in `SKILL.md`, where `MAX_POSITIONS`, `TAKE_PROFIT_PCT`, and `STOP_LOSS_PCT` are presented ...[truncated 1376 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/trader.py:149
Finding

DCA Interval Is Ignored, Allowing a Purchase on Every Invocation

Content
View full analysis
= 10: # Binance minimum place_order(symbol, "BUY", qty) ``` ### Technical Analysis `SKILL.md` documents `DCA_INTERVAL` with supported values such as `hourly`, `daily`, and `weekly`. However, `scripts/trader.py` does not read that environment variable, track the time of the last purchase, or otherwise enforce an interval. Under the documented five-minute cron example, DCA mode generates a buy signal on each invocation. A setting intended to purchase once per day could therefore attempt approximately 288 purchases per day for each configured pair, subject to available funds and Binance acceptance. There is also no cross-process lock or idempotency state. Concurrent or overlapping invocations can independently decide to purchase, increasing the chance of duplicate orders. ### Attack Path 1. The operator selects `STRATEGY=dca`, configures a daily or weekly DCA expectation, and supplies `DCA_AMOUNT_USDT`. 2. The operator follows the documented cron example, which launches the program every five minutes. 3. Each invocation reaches the DCA branch and unconditionally sets `signal = "BUY"`. 4. Each run submits another market purchase when the configured amount meets the minimum-order check. 5. The process repeats until funds become insufficient or the operator intervenes. 6. If ...[truncated 716 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:4
Finding

Python Dependencies Are Installed Without Artifact Integrity Verification or Environment Isolation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 5)May include surrounding context.

sh
set -e
echo "=== Binance Spot Trader Setup ==="
pip install httpx==0.27.0 python-dotenv==1.0.1
echo "Done. Create .env with BINANCE_API_KEY, BINANCE_SECRET_KEY, and SKILLBOSS_API_KEY"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The bot places live Binance market orders automatically based on strategy signals and optional LLM output, with no interactive confirmation, dry-run default, kill switch, or explicit in-code safeguard before execution. In the context of an autonomous trading skill connected to a real exchange account, this can immediately cause unintended financial loss from misconfiguration, prompt/model errors, bad market conditions, or compromised inputs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires sensitive environment secrets, writes files, and performs networked trading actions, but it does not declare any explicit tool scope or allowed-tools boundary. In an autonomous trading context, this increases the risk of the agent invoking the skill in broader-than-intended situations and handling high-impact actions without clear permission constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description contains broad activation phrases like 'use when user wants to trade on Binance' and 'automate DCA buying,' which can cause the skill to be selected for a wide range of common finance requests. Because this skill can drive real-money trading with API keys, overbroad triggering materially raises the chance of unintended activation in ambiguous conversations.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
- Start with tiny amounts ($50-100) and paper trade first
- Monitor actively during first 24 hours
- Set up Binance email alerts for all trades
- **API keys on disk** — secure your server (SSH keys only, firewall, chmod 600)

## References

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reference explicitly documents authenticated endpoints for placing, listing, and canceling live Binance orders without any safety framing, testnet guidance, or warning that these actions affect real funds and may be irreversible once executed. In the context of an autonomous trading bot skill, this omission materially increases the chance that downstream agent logic or users will invoke dangerous live-trading actions unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill sends trading-related market analysis data to an external LLM service without any explicit consent flow, disclosure, or privacy boundary. Although the transmitted prompt shown here contains market data rather than API secrets, using a third-party service in a live trading loop introduces confidentiality, compliance, and integrity risks, especially because its output directly influences buy decisions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This code makes a network call to a third-party API endpoint, which is a real external transmission surface in a trading bot. By itself, external communication is expected functionality, but in this context it becomes security-relevant because the remote service affects trading decisions and receives strategy inputs without strong trust controls or explicit consent handling.

Content

Scanner excerpt · scripts/trader.py (reported line 86)May include surrounding context.

python
Reply ONLY a number."""

    with httpx.Client(timeout=30) as c:
        resp = c.post("https://api.heybossai.com/v1/pilot",
            headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
            json={"type": "chat", "inputs": {"messages": [{"role": "user", "content": prompt}]}, "prefer": "balanced"})
        text = resp.json()["result"]["choices"][0]["message"]["content"].strip()

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code accesses sensitive credentials via BINANCE_API_KEY and BINANCE_SECRET_KEY, but there is no confirmation prompt, logging, comment, or other user-facing disclosure explaining that credential material will be used. Under the code-file warning criteria, sensitive environment variable access should have some visible disclosure unless clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.