fiat
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to use system tools including
curl,openssl,grep,sed, anddateto interact with Binance APIs, sign requests, and retrieve credentials from the filesystem. - [DATA_EXFILTRATION]: The instructions guide the agent to automatically search for and read sensitive files such as
~/.openclaw/secrets.envand.envin the home or workspace directories. This behavior is intended for retrieving API credentials but grants the agent the capability to access sensitive local data. - [DYNAMIC_EXECUTION]: The agent is instructed to dynamically construct and execute shell scripts at runtime for cryptographic signature generation (HMAC, RSA, Ed25519) and for automated credential extraction using computed file paths.
- [INDIRECT_PROMPT_INJECTION]: A vulnerability surface is identified where user-supplied inputs like country codes and currency symbols are interpolated directly into shell commands (
curl). While the skill recommends RFC 3986 encoding, the lack of robust boundary markers or pre-invocation validation for all capability tiers presents a risk factor. - Ingestion points: User input for fiat currencies, cryptocurrencies, and country codes in
SKILL.md. - Boundary markers: Absent for interpolated parameters.
- Capability inventory: Use of
curl,openssl,grep, andsedinreferences/sapi-endpoints.md. - Sanitization: Explicit instruction to percent-encode parameters according to RFC 3986 before transmission.
Audit Metadata