Back to skill

Security audit

Researcher Alpha Copilot

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does the advertised crypto research workflow, but billing and proxy diagnostics need Review because they can expose credentials or create charges through broad configuration.

Review this before installing in a paid or shared environment. Only run rank when you intend to be billed, prefer --skip-billing or SKILLPAY_BILLING_MODE=noop for testing, lock SkillPay endpoints to the real HTTPS service, and avoid running proxy-check with credential-bearing proxy URLs unless output is kept private.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/billing.py:36
Finding

SkillPay bearer API key can be transmitted to an arbitrary configured endpoint

Content
View full analysis
None: self.api_key = api_key self.base_url = (base_url or os.getenv("SKILLPAY_BASE_URL") or "https://skillpay.me").rstrip("/") self.charge_url = charge_url or os.getenv("SKILLPAY_CHARGE_URL") if not self.charge_url: charge_path = os.getenv("SKILLPAY_CHARGE_PATH", "/charges") self.charge_url = f"{self.base_url}{charge_path}" self.session = requests.Session() def charge(self, call_name: str, amount_usdt: str, user_ref: str, idempotency_key: str) -> BillingResult: payload = { "call_name": call_name, "amount": amount_usdt, "currency": "USDT", "user_ref": user_ref, "idempotency_key": idempotency_key, "timestamp": int(time.time()), } headers = { "Authorization": f"Bearer {self.api_key}", "Content-Type": "application/json", "Idempotency-Key": idempotency_key, } delay = 0.8 for attempt in range(3): try: resp = self.session.post(self.charge_url, json=payload, headers=headers, timeout=12) ``` ### Technical Analysis The billing client accepts `SKILLPAY_BASE_URL` and `SKILLPAY_CHARGE_URL` without validating the URL scheme, hostname, port, or intended service identity. The resulting destination receives an `Authorization: Bearer` header containing the SkillPay API key. A process that can influence the environment or launch configuration can therefore redirect billing requests to an attacker-controlled host. The implementation also permits a plain HTTP destination, which cou ...[truncated 1758 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/alpha_copilot.py:103
Finding

Proxy credentials are exposed in proxy-check diagnostic output

Content
View full analysis
Dict[str, str]: return { "http_proxy": args.http_proxy or os.getenv("HTTP_PROXY") or os.getenv("http_proxy") or "", "https_proxy": args.https_proxy or os.getenv("HTTPS_PROXY") or os.getenv("https_proxy") or "", "all_proxy": args.all_proxy or os.getenv("ALL_PROXY") or os.getenv("all_proxy") or "", } ``` ```python summary = summarize_proxy_diagnostics(diagnostics, proxy_mode=proxy_mode, proxy_inputs=proxy_inputs) return { "status": "ok", "command": "proxy-check", "chain": args.chain, "proxy_mode": proxy_mode, "proxy_inputs": proxy_inputs, "custom_proxies_applied": proxies or {}, "session_trust_env": client.session.trust_env, "summary": summary, "checks": diagnostics, } ``` The returned object is serialized to standard output by `cmd_proxy_check()`. ### Technical Analysis Authenticated proxy URLs commonly include credentials in the URL user-information component: ```text http://username:password@proxy.example:8080 ``` `collect_proxy_inputs()` retrieves proxy URLs from command-line arguments or environment variables without redaction. `run_proxy_check()` then returns those values under both `proxy_inputs` and, for custom proxy mode, `custom_proxies_applied`. Because the command prints the returned object as JSON, any embedded proxy username, password, token, or access key is exposed verbatim. Diagnostic output is likely to be copied into support tickets or captured by terminal transcripts, CI logs, monitoring systems, or agent conversation records. The connectivity diagnostic only needs to report whether a proxy is configured and possibly its non-sensitive host and port. Returning credentials exceeds the min ...[truncated 1325 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a research and content-generation skill focused on daily crypto alpha scanning, with billing hooks as ancillary functionality. However, the supplied code chunk contains no market data access, no token ranking logic, no summarization, and no publishing draft generation. Its sole purpose is to perform billing through SkillPay, including API key use, HTTP POST requests, retries, and idempotency. Because the actual code's primary behavior is billing rather than crypto research/output generation, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for an end-user analytical/content-generation skill focused on crypto token scanning and draft creation. The supplied code does not implement any of that functionality. Instead, it is a deployment helper script whose sole purpose is to publish the skill directory via the clawhub CLI. This is a materially different primary purpose and introduces an undeclared capability: publishing/distributing the skill. Therefore, the description does not accurately represent the actual behavior of the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises an end-user research copilot workflow that produces a daily 5-token leaderboard, analytical summaries, and publish-ready draft content, plus billing integration. The supplied code instead only provides a generic HTTP client for Binance Web3 endpoints: ranking list retrieval, token metadata lookup, token audit lookup, and a root ping. While these calls could support a broader crypto research feature, the chunk itself does not implement the declared primary behavior or outputs. It also performs undeclared external network access to Binance Web3 services. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not implement or exercise crypto research, token ranking, summarization, or content drafting. Its primary purpose is validating billing adapter behavior for SkillPay-related charging logic and environment configuration. While the declared description mentions SkillPay billing hooks, that appears only as a supporting detail in the description, whereas billing is the sole focus of this code chunk. Therefore the code's actual behavior is materially different from the declared primary purpose, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a user-facing crypto research and content-generation skill. The supplied code chunk does not implement or support that functionality. Instead, it is a unit test for a web3 client’s proxy configuration behavior, checking direct, auto, and custom proxy modes. This is a materially different primary purpose and capability set from the declared description. There are no visible features related to token ranking, research summaries, publishing drafts, or billing hooks in this code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares network and environment-dependent behavior, including external Binance and SkillPay access plus proxy/env variable use, but does not declare any explicit tool scope or permissions. That weakens user consent and sandbox review because a caller may not realize the skill can make outbound requests or consume sensitive environment configuration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file says the skill is designed for one fixed output and lists that output entirely in Chinese, while command examples also default to --lang zh. This can be read as forcing a specific language/locale rather than clearly offering user choice, which conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that successful rank calls trigger SkillPay billing, but it does not present a prominent user-facing warning in the command examples or invocation guidance that running the command may charge the user. In agentic contexts, hidden or easy-to-miss billing side effects can cause unauthorized charges or social-engineering-style abuse through seemingly harmless analysis requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default prompt is broad enough to match ordinary crypto research, leaderboard generation, and content drafting requests without strong activation boundaries. In an agent ecosystem, this can cause unintended skill invocation, leading to overreach into financial-analysis and publish-ready content generation in contexts where the user did not explicitly request this specialized behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The proxy-check command is outside the stated research-report purpose and functions as an environment-inspection tool. It collects and returns environment-derived proxy inputs and connectivity diagnostics, which can disclose internal network setup and be abused to map egress paths or harvest proxy endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

This code returns raw proxy settings sourced from CLI arguments or environment variables without redaction. Proxy URLs commonly embed credentials or internal hostnames, so exposing them can directly leak secrets and network details to users or logs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The health command exposes operational configuration such as billing mode, default price, and proxy defaults, which are not necessary for producing token research output. Revealing this runtime metadata helps an attacker profile the deployment, infer monetization hooks, and identify network-routing behavior for follow-on abuse or social engineering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs a network billing request containing user_ref, amount, call metadata, and a bearer API credential, but there is no confirmation prompt, print/log statement, or comment/docstring warning that billing data will be transmitted to an external service. For a code file, outbound transmission of user/system data is in scope for missing-warning review when the file itself gives no user disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code explicitly passes "zh" as the language and then validates Chinese-only content in generated output. Per the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency is specified as requests>=2.31.0, which allows any future version to be installed and makes builds non-reproducible. This increases supply-chain risk and can unexpectedly pull in a vulnerable or breaking release, especially for a network-facing skill that may make outbound HTTP requests to external crypto/data services.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Because requests is not pinned, it is impossible to verify from this manifest whether the installed version includes fixes for known advisories affecting some releases. In a skill that likely fetches remote market data, using an affected requests version could expose credentials, weaken request safety, or introduce other client-side security issues depending on runtime resolution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The rank command reads a billing identifier from CLI or environment and sends it to the billing backend without any user-facing notice in this file. While common in metered systems, undisclosed transmission of identifiers creates a privacy and transparency issue and may surprise users of a research-oriented skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code sends user-provided blockchain identifiers and contract addresses to external Binance Web3 endpoints via HTTP requests. There are no confirmation prompts, user-facing logs, or explanatory comments/docstrings warning that this data will be transmitted off-host.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a research copilot that gathers token rankings, fundamentals, liquidity, and risk summaries for crypto content generation. The ping_root method performs a generic HTTP probe of the configured base URL and returns status/final redirect information, which is not necessary for producing token research outputs and adds a network-diagnostic capability beyond the stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.