Back to skill

Security audit

Coinank Openapi Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently provides read-only CoinAnk market-data queries using a user-supplied API key, with no evidence of persistence or hidden behavior.

Install only if you intend to let the agent query CoinAnk with your CoinAnk API key. Treat that key as sensitive, expect requests to go to open-api.coinank.com, and review the mostly Chinese documentation if you need to understand every endpoint before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (42)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The top-level skill description is written as a directive in Chinese and the README overall assumes Chinese as the operating language, while no opt-in or alternative language guidance is provided. The policy specifically flags language or locale constraints when the skill forces a specific language without user choice.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The skill's operative instructions are entirely in Chinese and do not offer a language choice or require user opt-in, which can prevent users and reviewers from understanding what actions the skill will take. In a security-sensitive skill that reads local reference files and makes authenticated network requests, this reduces transparency and informed consent, increasing the risk of misuse or unnoticed dangerous behavior.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This manifest-like OpenAPI file uses Chinese natural-language metadata throughout, including the API title, operation summaries, and schema descriptions, with no indication that the locale is optional or region-specific. That can violate a language/locale policy when skills are expected to be language-neutral or to respect user language preferences.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This manifest contains user-facing natural-language fields such as the API title, tag, summary, and descriptions primarily in Chinese, but does not indicate that the skill is intentionally China/Chinese-locale specific or provide an alternative language option. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
Natural-language policy review applies to all file types, including OpenAPI specs. The title, tag, summary, and descriptions are primarily in Chinese, which can impose a language constraint on users or downstream agents without any opt-in, fallback language, or documented reason for limiting the interface to that locale.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The OpenAPI spec requires an `apikey` header to be sent to `https://open-api.coinank.com`, but it provides no explicit user-facing notice that the skill will transmit credentials to an external third-party service. In an agent/tooling context, this can lead users to unknowingly disclose sensitive API credentials, increasing the risk of misuse, unexpected billing, or account abuse if the external service or integration is not fully trusted.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The specification requires an apikey header on operations, yet both the operation-level and top-level security declarations are empty. In agent and tool ecosystems that infer auth behavior from OpenAPI security metadata, this can cause credentials to be handled outside normal protected auth flows, omitted from security reviews, or injected manually in unsafe ways, increasing risk of accidental disclosure or misuse.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
This manifest requires an `apikey` header for the request, which means the skill will transmit user credentials to a remote service. The file documents how to supply the key but does not include any user-facing warning about sending credentials to `open-api.coinank.com` or any privacy/security notice around that transmission.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Like the earlier endpoint, this operation requires an `apikey` header and therefore transmits credentials to an external API. The specification states that an API key is required but does not warn users that their credential will be sent off-platform or describe the associated privacy/security impact.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The OpenAPI spec requires an `apikey` header for calls to `https://open-api.coinank.com`, but it does not provide any user-facing notice that credentials will be sent to a third-party external service. In an agent skill context, this can cause users or calling systems to forward secrets without clear consent or handling guidance, increasing the risk of inadvertent credential exposure or misuse.

Session Persistence

Medium
Category
Rogue Agent
Content
"type": "integer"
                          }
                        },
                        "marketCapList": {
                          "type": "array",
                          "items": {
                            "oneOf": [
Confidence
75% confidence
Finding
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Session Persistence

Medium
Category
Rogue Agent
Content
"type": "integer"
                          }
                        },
                        "marketCapList": {
                          "type": "array",
                          "items": {
                            "oneOf": [
Confidence
75% confidence
Finding
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Session Persistence

Medium
Category
Rogue Agent
Content
"type": "integer"
                          }
                        },
                        "marketCapList": {
                          "type": "array",
                          "items": {
                            "oneOf": [
Confidence
75% confidence
Finding
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Session Persistence

Medium
Category
Rogue Agent
Content
"type": "integer"
                          }
                        },
                        "marketCapList": {
                          "type": "array",
                          "items": {
                            "oneOf": [
Confidence
75% confidence
Finding
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
This manifest uses Chinese-only titles, tags, summaries, and parameter descriptions such as "默认模块", "新闻快讯", and "语言", while providing no indication that users can opt into another language or that the skill is intentionally region-locked. Under the language/locale policy rule, forcing a single locale without user choice or clear justification is a natural-language policy concern.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The spec requires callers to send an API key to an external service via request headers, but it provides no user-facing warning, consent cue, or trust information about that credential transfer. In an agent-skill context, this increases the risk that users or orchestrators will unknowingly disclose reusable secrets to a third-party endpoint, enabling unauthorized API usage or billing abuse if the key is mishandled.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
Like the earlier endpoint, this operation requires an API key header without any user-facing disclosure that a secret will be sent to an external service. Within a reusable skill, repeated undocumented credential transmission across endpoints broadens the chance of accidental secret exposure, misuse of a paid account, or unsafe automatic invocation by agents.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The `/api/instruments/longShortRank` endpoint summary identifies it as a long/short position ratio ranking, but the description says it returns a market trading-volume-change ranking. That is an active contradiction in the inline documentation, not merely missing detail, and could mislead agents about what data they are retrieving.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
This manifest/openapi file contains user-facing titles, summaries, and descriptions primarily in Chinese, but does not indicate that the skill is region-specific or provide any opt-in for language/locale selection. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The operation declares `security: []`, which tells tooling that no authentication is required, yet it also defines a required `apikey` header parameter. This mismatch can cause client generators, gateways, or agent frameworks to mishandle authentication, leading to accidental unauthenticated calls, broken policy enforcement, or unsafe logging/handling of API keys as ordinary headers rather than a formal security scheme.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
This endpoint has the same authentication inconsistency: the spec says no security is used while simultaneously requiring an `apikey` header. In agent or integration contexts, inconsistent security metadata can bypass expected auth handling paths, weaken enforcement in downstream tooling, and increase the chance of credential exposure through generic header processing.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
For multiple endpoints, the specification says an `apikey` header is required, but the operation-level `security` field is set to an empty array, which explicitly indicates no security requirements. This is an active contradiction in the skill's own interface documentation and can mislead callers and auditors about authentication needs.

Natural-Language Policy Violations

Low
Confidence
66% confidence
Finding
Natural-language policy checks apply to all file types. The file contains Chinese titles and field descriptions alongside English endpoint text, but there is no statement about intended language, locale scope, or user choice, which can create an implicit language constraint without opt-in.

Vague Triggers

Low
Confidence
79% confidence
Finding
This is a manifest-style OpenAPI file, so vague-trigger checks apply. The description explains what data the endpoint returns and mentions API level requirements, but it provides no explicit trigger phrases, invocation boundaries, or exclusion conditions that would help prevent overly broad or unintended activation in a skill-selection context.

Vague Triggers

Low
Confidence
83% confidence
Finding
This is a manifest-like OpenAPI JSON file, so vague-trigger review applies. The file describes the skill's operations but does not state when the skill should activate, what exact user requests should invoke it, or any negative examples to avoid accidental invocation for broadly related crypto queries.

Static analysis

No suspicious patterns detected.