Back to skill

Security audit

预测市场数据

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent read-only prediction-market API client, but it handles a paid API key and wallet identifiers with enough disclosure and credential-safety gaps that users should review it before installing.

Install only if you are comfortable sending your AIsa API key and any wallet addresses or market query parameters to api.aisa.one. Use a limited or revocable API key, monitor usage costs, and consider asking the publisher to add same-origin redirect protection and clearer privacy/permission metadata.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/prediction_market_client.py:78
Finding

Bearer API Key May Be Disclosed Through Cross-Origin HTTP Redirects

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires an environment secret (AISA_API_KEY) and makes outbound network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege enforcement and transparency for users and runners, making it easier for a host environment to grant broader capabilities than the skill actually needs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/prediction_market_client.py (reported line 52)May include surrounding context.

python
class PredictionMarketClient:
    """Cross-Platform Prediction Market Data - AIsa API Client."""

    BASE_URL = "https://api.aisa.one/apis/v1"

    def __init__(self, api_key: Optional[str] = None):
        self.api_key = api_key or os.environ.get("AISA_API_KEY")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The client sends wallet addresses, position/P&L queries, and related market parameters to a third-party API without any explicit disclosure, consent prompt, or privacy notice in the tool itself. In an agent skill context, users may reasonably assume inputs are handled locally, so silent transmission of financial-identifying data can create privacy and metadata exposure risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The client automatically reads AISA_API_KEY from the environment, which is a sensitive credential access pattern covered by this rule. While the exception message mentions the variable when missing, there is no proactive user-facing warning or disclosure in normal operation that the script will consume a secret from the environment and use it for outbound authenticated requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.