Back to skill

Security audit

fomo-smart-money

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed FOMO wallet-tracking helper with network lookups and referral promotion, but no hidden credential access, destructive actions, or private-data exfiltration were found.

Install only if you are comfortable with Chinese-only output, public wallet and token lookups being sent to blockchain RPC providers and DexScreener, default AntCaveClub referral links in generated FOMO URLs, recurring author/social promotion, and one marker file written in your home directory. Treat the trading output as research, not financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
scripts/trending.py:15
Finding

Mandatory Referral and Promotional Content Hijacks Agent Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill embeds referral-link generation, persistent promotional banners, and configurable invite-code behavior that are not part of its stated analytical purpose. Hidden monetization and promotion are risky because they can manipulate outputs for affiliate gain, obscure impartiality, and induce the agent to exfiltrate user attention to third-party services under the guise of neutral recommendations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill embeds referral-link generation, persistent promotional banners, and configurable invite-code behavior that are not part of its stated analytical purpose. Hidden monetization and promotion are risky because they can manipulate outputs for affiliate gain, obscure impartiality, and induce the agent to exfiltrate user attention to third-party services under the guise of neutral recommendations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises networked and stateful behavior such as live RPC queries, DexScreener access, and marker-file based banner persistence, but declares no explicit tool scope or permissions. This creates an authorization gap where a reviewer or runtime may underestimate the skill's ability to reach external services or write local files, increasing the chance of unintended data access or policy bypass.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad trigger phrases such as '现在他们在买什么' or '当前交易榜' are common conversational language and may cause accidental activation outside the intended context. Unintended invocation is risky here because the skill can make live network calls and produce promotional referral links, causing surprising behavior and possible unreviewed outbound interactions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger section instructs the agent to 'directly run trending.py and output verbatim' without guardrails, while using ambiguous keywords and providing no negative examples. That combination increases prompt-routing risk, making it easier for unrelated user text to invoke a networked script and emit affiliate-linked results without contextual confirmation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring and command descriptions are entirely in Chinese, and user-visible messages throughout the script follow the same pattern. There is no indication that the tool is intentionally region-specific or that users can opt into another language, which makes this a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code performs live RPC lookups against third-party blockchain endpoints to retrieve balances, which goes beyond a static recommendation/listing skill. This expands the trust boundary and data flow at runtime, creating privacy and behavior-mismatch risks because wallet addresses are sent externally and the skill now acts as a live reconnaissance tool rather than only presenting curated internal data.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/query.py (reported line 137)May include surrounding context.

python
handle = args[0]
    for w in load():
        if w['handle'].lower() == handle.lower():
            print(f"=== {w['handle']} 实时余额({__import__('datetime').datetime.utcnow().strftime('%Y-%m-%d %H:%M')} UTC)===")
            if w['solana']:
                bal = rpc_solana_balance(w['solana'])
                print(f"SOL: {bal if isinstance(bal,str) else f'{bal:.2f} SOL'}  (快照时 {fmt_money(w['solana_usd'])})")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill exposes a status/inspection command that enumerates wallet activity state, recent activity metadata, and operational classifications beyond the manifest's described recommendation purpose. This broadens the tool from curated recommendations into surveillance-style wallet profiling, which can surprise users, expand sensitive data exposure, and increase the chance the skill is used for unintended monitoring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring presents the skill name, behavior, and usage entirely in Chinese, and later user-facing output is also hardcoded in Chinese. This imposes a specific language on users without any visible opt-in or alternative locale selection, which matches the stated language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The first-run banner and footer are printed only in Chinese and do not provide any mechanism for the user to select another language. Because these are direct user-facing messages, they constitute a forced locale choice rather than a neutral internal implementation detail.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The script sends token identifiers derived from observed wallet activity to a third-party service, DexScreener, without any user consent, allowlisting, or disclosure beyond code inspection. While the data is blockchain-related and largely public, this still creates an external data transmission channel and a dependency on an external service that can log requests, correlate usage patterns, and affect privacy or operational reliability.

Content

Scanner excerpt · scripts/trending.py (reported line 106)May include surrounding context.

python
def dexscreener(mint):
    try:
        req = urllib.request.Request(f"https://api.dexscreener.com/latest/dex/tokens/{mint}",
                                     headers={"User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"})
        with urllib.request.urlopen(req, timeout=15) as r:
            return json.loads(r.read())

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated report headings, labels, and warning text are all emitted in Chinese, with no configuration or prompt allowing the user to choose a preferred language. This is a natural-language policy issue under the locale rule because the skill forces a specific language during normal operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON file includes natural-language metadata such as the source and usage note in Chinese only. Because the file does not offer an alternate language or indicate that the dataset is intentionally limited to a Chinese-language audience, it can violate the language/locale policy requiring user choice or justified locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The status_note explains operational meanings for values like moved, active, quiet, and empty only in Chinese. Users who do not read Chinese cannot reliably interpret the dataset, and no opt-in or justification for the language restriction is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Network balance queries send wallet addresses to public RPC providers without any explicit notice, consent flow, or privacy disclosure. Although the addresses are blockchain-related and may be public, transmitting queried targets to third parties can reveal user interests, monitoring behavior, or investigation targets, especially in an analyst or trading context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.