Back to skill

Security audit

Token Risk Explainer

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does token-risk reporting, but normal use can trigger live billing calls without a clear per-use confirmation step.

Install only if you expect this skill to contact Binance Web3 services and, when SkillPay is configured, charge for explain/compare/watchlist runs. Use noop or skip-billing mode unless billing is intentionally enabled, restrict SKILLPAY_* environment variables to trusted deployment configuration, and do not rely on a low-risk result when audit data may be unavailable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/billing.py:37
Finding

Unrestricted Billing Endpoint Can Expose the SkillPay API Credential

Content
View full analysis
None: self.api_key = api_key self.base_url = (base_url or os.getenv("SKILLPAY_BASE_URL") or "https://skillpay.me").rstrip("/") self.charge_url = charge_url or os.getenv("SKILLPAY_CHARGE_URL") if not self.charge_url: charge_path = os.getenv("SKILLPAY_CHARGE_PATH", "/charges") self.charge_url = f"{self.base_url}{charge_path}" self.session = requests.Session() def charge(self, call_name: str, amount_usdt: str, user_ref: str, idempotency_key: str) -> BillingResult: payload = { "call_name": call_name, "amount": amount_usdt, "currency": "USDT", "user_ref": user_ref, "idempotency_key": idempotency_key, "timestamp": int(time.time()), } headers = { "Authorization": f"Bearer {self.api_key}", "Content-Type": "application/json", "Idempotency-Key": idempotency_key, } delay = 0.8 for attempt in range(3): try: resp = self.session.post(self.charge_url, json=payload, headers=headers, timeout=12) ``` ### Technical Analysis The billing destination is taken directly from `SKILLPAY_CHARGE_URL` or assembled from `SKILLPAY_BASE_URL` and `SKILLPAY_CHARGE_PATH`. The resulting URL is not validated before the SkillPay API key is placed in the `Authorization` header and transmitted. There is no enforcement of: - HTTPS transport. - An approved SkillPay hostname. - A safe destination port. - The absence of embedded URL credentials. - A canonical and exp ...[truncated 1921 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/token_risk_explainer.py:215
Finding

Audit Service Failures Produce Misleading Low-Risk Assessments

Content
View full analysis
Dict[str, Any]: chain_id = CHAIN_ALIASES[chain] resolved = client.resolve_token(chain_id, query) contract = str(resolved.get("contractAddress") or query).strip() if not contract: raise AppError("missing_contract") token = resolved if resolved.get("symbol") else {"symbol": "", "name": "", "contractAddress": contract} try: meta = client.token_meta(chain_id, contract) except BinanceWeb3Error: meta = {} try: audit = client.token_audit(chain_id, contract) except BinanceWeb3Error: audit = {"hasResult": False, "isSupported": False, "riskItems": [], "extraInfo": {}} symbol = str(token.get("symbol") or meta.get("symbol") or meta.get("name") or query) display = f"{symbol} | {contract}" factors = build_risk_factors(token, audit, meta) score = calculate_risk_score(factors) bucket = risk_bucket(score) continue_research = score < 60 drafts = build_drafts(display, TEXT["en"][bucket], continue_research) hits = flatten_audit_hits(audit) risk_summary_zh = f"{display} 当前风险级别为 {TEXT['zh'][bucket]}。主要风险数量:{len(factors)}。" risk_summary_en = f"{display} is currently rated {TEXT['en'][bucket]}. Visible risk factors: {len(factors)}." ``` ### Technical Analysis When the contract-audit request fails, the exception is converted into a synthetic audit object containing no findings: ```python {"hasResult": False, "isSupported": False, "riskItems": [], "extraInfo": {}} ``` The program subsequently evaluates this object as though it were a valid audit response. Because `build_risk_factors()` only adds risk factors for affirmative findings, unava ...[truncated 2500 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented Billing Hook confirms that this skill includes payment-related behavior despite being marketed primarily as a token risk explainer. Combining financial charging logic with user-facing analysis without clear boundaries raises the risk of unauthorized billing, secret misuse, and trust violations if the skill is auto-invoked based on broad prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented Billing Hook confirms that this skill includes payment-related behavior despite being marketed primarily as a token risk explainer. Combining financial charging logic with user-facing analysis without clear boundaries raises the risk of unauthorized billing, secret misuse, and trust violations if the skill is auto-invoked based on broad prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented Billing Hook confirms that this skill includes payment-related behavior despite being marketed primarily as a token risk explainer. Combining financial charging logic with user-facing analysis without clear boundaries raises the risk of unauthorized billing, secret misuse, and trust violations if the skill is auto-invoked based on broad prompts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements live billing and charging logic even though the skill is described as a token-risk explainer, creating a significant capability mismatch. That mismatch is dangerous because users or operators may invoke the skill expecting analysis-only behavior while the code can trigger real external payment actions, enabling unauthorized or unexpected charges if wired into agent execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The SkillPay client can send charge requests to an external payment endpoint with amount, user reference, and idempotency data, which is unjustified for a token-risk explainer skill. In this context, the hidden ability to bill an external service is especially risky because it is unrelated to the stated purpose, increasing the chance of deceptive monetization, accidental charging, or abuse through prompt/tool orchestration.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill metadata does not declare any tool scope or allowed tools, yet the documented and inferred behavior indicates access to environment variables, file reads, and network activity. In an agent ecosystem, missing explicit capability boundaries can let the skill run with broader privileges than users expect, increasing the risk of unintended secret access or external communication.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description uses broad trigger language that could cause the agent to select this skill for many generic token-analysis or community-content tasks. Over-broad invocation increases the chance that a skill with network access, file access, or billing hooks is run in contexts where the user did not intend those capabilities to be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language description states the skill provides "Bilingual token risk explanations" and "generate bilingual community warning copy" as a default behavior. This imposes a language/locale behavior without documenting user choice, opt-in, or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code transmits charge metadata and a bearer API key to an external service without any in-file disclosure, transparency mechanism, or evidence of user consent. While sending an API key to the provider via Authorization is normal for authenticated APIs, in this skill context the undisclosed outbound payment request is dangerous because it performs sensitive external actions and shares user-linked billing data unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes a billing path that charges a user via client.charge(...) as part of normal command execution, even though the advertised capability is token risk explanation. In an agent setting, hidden or implicit charging is security-relevant because invoking the skill can trigger a financial side effect that is not inherent to the analysis task and may occur without explicit per-use consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code reads payment-related context from --user-id, SKILLPAY_USER_REF, and pricing from SKILLPAY_PRICE_USDT, then uses that context to perform a charge. Accessing and acting on billing identity/payment metadata is beyond simple token explanation and can enable unauthorized attribution or charging if the agent environment populates these values automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command handlers perform external token lookups and billing as soon as they run, with no user-facing warning, approval gate, or clear disclosure in this file. In an agent/tool ecosystem, this creates a side-effect risk: a simple request for analysis can silently contact third parties and incur charges, which is dangerous even if the underlying APIs are legitimate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The client allows its base URL to be overridden by an environment variable, so any caller controlling deployment configuration can redirect requests for token audits and metadata to an arbitrary external service. In an agent skill context, this can exfiltrate user-supplied token queries and contract addresses, return attacker-controlled JSON that influences downstream explanations, and break the trust boundary implied by a Binance-only analysis tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says the skill explains token risk from Binance Web3 token audit and market metadata, which implies looking up a provided token and analyzing its audit/metadata. This code also queries Binance unified rank lists for trending, top-search, and alpha tokens to resolve arbitrary names, expanding behavior into market discovery/ranking rather than just audit-and-metadata-based explanation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill documents use of SKILLPAY_APIKEY and external billing-related configuration but does not provide a user-facing warning that credentials may be accessed and that external network calls may occur. This weakens informed consent and can lead to accidental secret exposure or unexpected third-party communication during invocation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency is specified as requests>=2.31.0, which allows any future release and does not guarantee a reproducible or reviewed version set. This increases supply-chain risk because a vulnerable or incompatible release could be installed later without any manifest change, and the current file gives no assurance that a known-safe version is used.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The manifest references requests without pinning an exact version, while multiple known advisories exist for that package. Because the installed version is not fixed, deployments may resolve to an affected release, making it impossible to verify from this file alone whether the environment is exposed to known requests issues such as credential leakage or TLS/request-handling flaws.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function reads SKILLPAY_APIKEY from environment variables to authenticate billing requests, which is sensitive credential access. There is no comment, docstring, or user-facing message in this file explaining that the skill requires and uses this secret.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Watchlist mode reads an arbitrary user-supplied path via Path(args.input).read_text(...) with no restriction or disclosure. In an agent context, local file access is sensitive because a prompt or upstream tool input could cause unintended reading of local files, including secrets or unrelated workspace data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends chain IDs and contract addresses to an external Binance Web3 service via HTTP, and similar outbound requests occur in other methods as well. The file contains no confirmation prompt, print/log disclosure, or explanatory comment/docstring warning that user-provided blockchain identifiers will be transmitted to a third-party endpoint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Line L59 passes lang="zh" to explain_token, and the test asserts Chinese output on L62. This suggests a fixed locale expectation in natural-language behavior, which can conflict with language/locale choice policies when no opt-in or justification is shown in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.