Back to skill

Security audit

Binance Official Spot

Security checks for vulnerabilities and agentic risk

Overview

This Binance Spot skill is mostly coherent, but it tells the agent to store live Binance API keys and secrets in a plaintext TOOLS.md file while enabling real trading actions.

Review before installing. Use this only with tightly scoped Binance API keys, preferably testnet first, with withdrawals disabled and IP allowlisting enabled. Do not let the agent store full API keys or secrets in TOOLS.md or any synced/repository file; use a dedicated secret manager or rotate keys after testing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:277
Finding

Plaintext Persistence of Binance API Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:277-296, 311-315
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: High

The skill explicitly instructs the agent to store newly supplied Binance API credentials in TOOLS.md. The prescribed file structure includes complete API keys and secrets:

markdown
### TOOLS.md Structure

```bash
## Binance Accounts

### main
- API Key: abc123...xyz
- Secret: secret123...key
- Testnet: false
- Description: Primary trading account

### testnet-dev
- API Key: test456...abc
- Secret: testsecret...xyz
- Testnet: true
- Description: Development/testing

### futures-keys
- API Key: futures789...def
- Secret: futuressecret...uvw
- Testnet: false
- Description: Futures trading account
text

The storage instruction is:

```markdown
## Adding New Accounts

When user provides new credentials:

* Ask for account name
* Ask: Mainnet, Testnet or Demo
* Store in `TOOLS.md` with masked display confirmation

Technical Analysis

The documented masking requirement applies only to displaying credentials. It does not protect the credentials stored in TOOLS.md. The skill does not require encryption, an operating-system keychain, a dedicated secret manager, restrictive file permissions, repository exclusion, or access auditing.

Consequently, the credential file could be exposed to other local users or processes, backups, synchronization systems, diagnostic collection, or accidental source-control commits. Because Binance signatures are generated using the stored secret, disclosure of both the API key and secret enables an attacker to authenticate independently of the skill.

Attack Path

  1. A user supplies a Binance API key and secret to the agent.
  2. Following SKILL.md, the agent writes the complete credentials into TOOLS.md.
  3. The file is read through local compromise, excessive filesystem permissions, backup or synchronization exposure, or accidental repository publication.
  4. The ...[truncated 839 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not store API keys or signing secrets directly in TOOLS.md.
  2. Store secrets in an operating-system keychain, hardware-backed keystore, or dedicated secret manager. Keep only account aliases and opaque secret references in Markdown configuration.
  3. If file-based storage is unavoidable:
    • Encrypt credentials at rest with a key stored separately.
    • Create the file with owner-only permissions, such as mode 0600.
    • Explicitly exclude the file from source control and packaging.
    • Prevent inclusion in logs, backups, diagnostics, and synchronization systems where possible.
  4. Validate that imported Binance keys have only the minimum required permissions. Reject or prominently warn about withdrawal-enabled credentials.
  5. Recommend and verify Binance IP allowlisting where operationally possible.
  6. Separate testnet, demo, and mainnet credentials and make mainnet use explicit.
  7. Ensure masking is applied to all output, logs, errors, traces, and tool-call records—not merely user-facing confirmation messages.
  8. Document a credential-rotation and revocation procedure for suspected exposure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes authenticated order-placement and order-cancellation endpoints, including mainnet, without a clear up-front warning that these actions can execute real trades and affect funds. Although there is a confirmation requirement for mainnet transactions later in the file, the overall presentation still makes destructive financial actions readily available and under-warns users about irreversible or costly outcomes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly tells the agent to store Binance API keys and secrets in TOOLS.md, creating a plaintext local credential store unrelated to the minimum functionality required to make API requests. Because these are live trading credentials, compromise of the file could enable account takeover, order placement, fund loss, and unauthorized access to account data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs users or the agent to persist Binance API key material in TOOLS.md without any warning about plaintext storage risk or access controls. In the context of a trading skill, these secrets grant access to sensitive financial operations, so storing them in documentation materially increases the chance of leakage through repo sync, backups, logs, sharing, or later prompt exposure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation explicitly states that full secrets should never be displayed, yet later sections present account records with full API Key and Secret fields as plain values/templates. This creates an intent contradiction in the skill documentation about whether secrets should be exposed in the skill's working files.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/authentication.md (reported line 70)May include surrounding context.

Request:

bash
curl -X POST "https://api.binance.com/api/v3/order" \
  -H "X-MBX-APIKEY: your_api_key" \
  -H "User-Agent: binance-spot/1.0.1 (Skill)" \
  -d "symbol=BTCUSDT&side=BUY&type=MARKET&quantity=0.001&timestamp=1234567890123&signature=..."

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/authentication.md (reported line 70)May include surrounding context.

Request:

bash
curl -X POST "https://api.binance.com/api/v3/order" \
  -H "X-MBX-APIKEY: your_api_key" \
  -H "User-Agent: binance-spot/1.0.1 (Skill)" \
  -d "symbol=BTCUSDT&side=BUY&type=MARKET&quantity=0.001&timestamp=1234567890123&signature=..."

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.md (reported line 9)May include surrounding context.

md
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:295