Back to skill

Security audit

Kol Tracker

Security checks for vulnerabilities and agentic risk

Overview

The skill looks like a crypto wallet tracking demo but presents itself as a live alerting product, which could mislead users about financial signals.

Review this carefully before installing. It does not appear to contain malware or persistence, but it should not be relied on for trading or wallet intelligence unless the publisher clearly labels it as a demo or adds real, verifiable data sources and alert logic. Do not provide Telegram or Etherscan credentials to this version unless the implementation is updated to actually use them for the advertised purpose.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill markets itself as a live crypto wallet tracker with buy/sell alerts, but the file content does not define any real monitoring, alerting, or blockchain-querying behavior. In a financial context, this can mislead users into relying on nonexistent signals or simulated data, creating operational and financial risk even if there is no direct code execution issue in this file.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This manifest description explains what the skill does but does not specify when it should be invoked, what exact phrases should trigger it, or any exclusion conditions. For a manifest file, the absence of trigger specificity can lead to unintended activation from broad wallet- or crypto-related requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill metadata includes user-facing pricing and feature descriptions in Chinese while the rest of the skill is primarily in English, with no indication that users can choose their preferred language. This can impose a locale/language experience without user opt-in and conflicts with the requirement to avoid forced language selection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description promises real KOL wallet tracking and buy/sell alerts, but the implementation only prints hard-coded sample wallets, trades, and portfolio data. In a crypto context, this is dangerous because users may rely on fabricated or stale information for trading decisions, creating financial risk and undermining trust in the agent's outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains multiple user-facing strings in Chinese such as wallet labels, trade timing, and portfolio headings, while the module docstring and some other text are in English. The skill does not offer a language selection mechanism or state that it is intentionally Chinese-only, which can violate a language/locale policy requiring user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.