fiat

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to use system tools including curl, openssl, grep, sed, and date to interact with Binance APIs, sign requests, and retrieve credentials from the filesystem.
  • [DATA_EXFILTRATION]: The instructions guide the agent to automatically search for and read sensitive files such as ~/.openclaw/secrets.env and .env in the home or workspace directories. This behavior is intended for retrieving API credentials but grants the agent the capability to access sensitive local data.
  • [DYNAMIC_EXECUTION]: The agent is instructed to dynamically construct and execute shell scripts at runtime for cryptographic signature generation (HMAC, RSA, Ed25519) and for automated credential extraction using computed file paths.
  • [INDIRECT_PROMPT_INJECTION]: A vulnerability surface is identified where user-supplied inputs like country codes and currency symbols are interpolated directly into shell commands (curl). While the skill recommends RFC 3986 encoding, the lack of robust boundary markers or pre-invocation validation for all capability tiers presents a risk factor.
  • Ingestion points: User input for fiat currencies, cryptocurrencies, and country codes in SKILL.md.
  • Boundary markers: Absent for interpolated parameters.
  • Capability inventory: Use of curl, openssl, grep, and sed in references/sapi-endpoints.md.
  • Sanitization: Explicit instruction to percent-encode parameters according to RFC 3986 before transmission.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 08:07 PM
Security Audit — agent-trust-hub — fiat