Back to skill

Security audit

Crypto Market Intel

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public market data and writes local JSON files as documented, with no evidence of hidden credential access, exfiltration, destructive behavior, or automatic persistence.

Install only if you want an agent to make outbound requests to public market-data APIs and save fetched prices to local JSON files. Avoid enabling the cron example unless you want recurring background network activity and know how to remove the schedule later.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents network access and file-writing behavior but does not declare any explicit tool scope or permissions boundary. In an agent environment, this can cause the skill to be invoked with broader capabilities than users expect, increasing the chance of unintended outbound requests or writes to arbitrary locations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description contains broad trigger phrases like market data, market analysis, stock prices, macro data, and trading signals, which can match many ordinary finance-related prompts. Over-broad activation increases the risk that the agent selects this skill in contexts where external fetching or file writes are unnecessary or inappropriate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The "When to Use" section lists many activation scenarios but gives no boundaries for when the skill should not run. Without negative guidance, an agent may over-invoke the skill, causing unnecessary network calls, persistence, or use in sensitive portfolio-decision contexts where users did not request live data gathering.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The cron example introduces persistent scheduled execution that continues beyond the current session. In agent settings, session persistence can create ongoing network activity and file writes without renewed user awareness, which is risky if the schedule is installed automatically or copied into workflows without clear consent.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

Schedule hourly market data fetches:

bash
crontab -e

# Fetch market data every hour
0 * * * * cd ~/.openclaw/skills/crypto-market-intel/scripts && python3 market-data-fetcher.py all --output ~/market-data

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-sources.md (reported line 16)May include surrounding context.

md
# ── Top coins from CoinGecko (free, no key) ─────────────
    coins = fetch_json(
        "https://api.coingecko.com/api/v3/coins/markets?"
        "vs_currency=usd&order=market_cap_desc&per_page=30&page=1"
        "&sparkline=false&price_change_percentage=1h,24h,7d"
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-sources.md (reported line 50)May include surrounding context.

md
# ── Top coins from CoinGecko (free, no key) ─────────────
    coins = fetch_json(
        "https://api.coingecko.com/api/v3/coins/markets?"
        "vs_currency=usd&order=market_cap_desc&per_page=30&page=1"
        "&sparkline=false&price_change_percentage=1h,24h,7d"
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-sources.md (reported line 68)May include surrounding context.

md
# ── Top coins from CoinGecko (free, no key) ─────────────
    coins = fetch_json(
        "https://api.coingecko.com/api/v3/coins/markets?"
        "vs_currency=usd&order=market_cap_desc&per_page=30&page=1"
        "&sparkline=false&price_change_percentage=1h,24h,7d"
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-sources.md (reported line 84)May include surrounding context.

md
# ── Top coins from CoinGecko (free, no key) ─────────────
    coins = fetch_json(
        "https://api.coingecko.com/api/v3/coins/markets?"
        "vs_currency=usd&order=market_cap_desc&per_page=30&page=1"
        "&sparkline=false&price_change_percentage=1h,24h,7d"
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-sources.md (reported line 329)May include surrounding context.

md
# ── Top coins from CoinGecko (free, no key) ─────────────
    coins = fetch_json(
        "https://api.coingecko.com/api/v3/coins/markets?"
        "vs_currency=usd&order=market_cap_desc&per_page=30&page=1"
        "&sparkline=false&price_change_percentage=1h,24h,7d"
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/market-data-fetcher.py (reported line 43)May include surrounding context.

python
# ── Top coins from CoinGecko (free, no key) ─────────────
    coins = fetch_json(
        "https://api.coingecko.com/api/v3/coins/markets?"
        "vs_currency=usd&order=market_cap_desc&per_page=30&page=1"
        "&sparkline=false&price_change_percentage=1h,24h,7d"
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/market-data-fetcher.py (reported line 64)May include surrounding context.

python
# ── Top coins from CoinGecko (free, no key) ─────────────
    coins = fetch_json(
        "https://api.coingecko.com/api/v3/coins/markets?"
        "vs_currency=usd&order=market_cap_desc&per_page=30&page=1"
        "&sparkline=false&price_change_percentage=1h,24h,7d"
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/market-data-fetcher.py (reported line 89)May include surrounding context.

python
# ── Top coins from CoinGecko (free, no key) ─────────────
    coins = fetch_json(
        "https://api.coingecko.com/api/v3/coins/markets?"
        "vs_currency=usd&order=market_cap_desc&per_page=30&page=1"
        "&sparkline=false&price_change_percentage=1h,24h,7d"
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-sources.md (reported line 137)May include surrounding context.

md
print(f"  ✅ Global: ${data['global']['total_market_cap_usd']/1e12:.2f}T mcap, BTC dom {data['global']['btc_dominance']:.1f}%", flush=True)

    # ── Fear & Greed Index ───────────────────────────────────
    fng = fetch_json("https://api.alternative.me/fng/?limit=7")
    if fng and "data" in fng:
        data["fear_greed"] = [{
            "value": int(d["value"]),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-sources.md (reported line 332)May include surrounding context.

md
print(f"  ✅ Global: ${data['global']['total_market_cap_usd']/1e12:.2f}T mcap, BTC dom {data['global']['btc_dominance']:.1f}%", flush=True)

    # ── Fear & Greed Index ───────────────────────────────────
    fng = fetch_json("https://api.alternative.me/fng/?limit=7")
    if fng and "data" in fng:
        data["fear_greed"] = [{
            "value": int(d["value"]),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/market-data-fetcher.py (reported line 78)May include surrounding context.

python
print(f"  ✅ Global: ${data['global']['total_market_cap_usd']/1e12:.2f}T mcap, BTC dom {data['global']['btc_dominance']:.1f}%", flush=True)

    # ── Fear & Greed Index ───────────────────────────────────
    fng = fetch_json("https://api.alternative.me/fng/?limit=7")
    if fng and "data" in fng:
        data["fear_greed"] = [{
            "value": int(d["value"]),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-sources.md (reported line 189)May include surrounding context.

md
print(f"  ✅ {len(data['trending'])} trending coins", flush=True)

    # ── DeFi TVL from DeFi Llama ─────────────────────────────
    defi = fetch_json("https://api.llama.fi/v2/historicalChainTvl")
    if defi and len(defi) > 0:
        latest = defi[-1] if defi else None
        prev_day = defi[-2] if len(defi) > 1 else None

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-sources.md (reported line 335)May include surrounding context.

md
print(f"  ✅ {len(data['trending'])} trending coins", flush=True)

    # ── DeFi TVL from DeFi Llama ─────────────────────────────
    defi = fetch_json("https://api.llama.fi/v2/historicalChainTvl")
    if defi and len(defi) > 0:
        latest = defi[-1] if defi else None
        prev_day = defi[-2] if len(defi) > 1 else None

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/market-data-fetcher.py (reported line 100)May include surrounding context.

python
print(f"  ✅ {len(data['trending'])} trending coins", flush=True)

    # ── DeFi TVL from DeFi Llama ─────────────────────────────
    defi = fetch_json("https://api.llama.fi/v2/historicalChainTvl")
    if defi and len(defi) > 0:
        latest = defi[-1] if defi else None
        prev_day = defi[-2] if len(defi) > 1 else None

Static analysis

No suspicious patterns detected.