Back to skill

Security audit

Coingecko

Security checks for vulnerabilities and agentic risk

Overview

The skill is a mostly coherent read-only crypto price tool, but its credential handling is under-scoped and unsafe enough to require review before installation.

Review before installing. Use only a dedicated CoinGecko key, do not keep unrelated API_KEY values in the working .env, remove or rotate the published CG-looking key, and avoid running the documented echo commands that reveal the full key. The skill does not show trading, wallet access, persistence, or destructive behavior, but its credential examples and generic secret fallback need correction.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_price.py:31
Finding

Generic API_KEY Secret Is Unnecessarily Read and Transmitted to CoinGecko

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:127
Finding

Repository Documentation Contains a Credential-Like Fixed API Key

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/DESCRIPTION.md:487
Finding

Troubleshooting Instructions Print the Full API Key to the Terminal

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch further indicates the skill performs diagnostics and status reporting, accesses Kraken, and handles key-tier behavior differently from what is advertised. When security review is based on the declared purpose, hidden or inaccurate behavior can bypass user consent and lead to broader data exposure or network activity than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This mismatch further indicates the skill performs diagnostics and status reporting, accesses Kraken, and handles key-tier behavior differently from what is advertised. When security review is based on the declared purpose, hidden or inaccurate behavior can bypass user consent and lead to broader data exposure or network activity than intended.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: coingecko
description: "Live Bitcoin & crypto price data via CoinGecko API. Fetch BTC/USD, ETH/USD, multi-asset quotes. Supports both Demo (free) and Pro API keys. No credentials in prompts—only .env isolation."
version: 1.0.0
author: "bronoman & Hermes local (May 2026)"
license: MIT

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
---
name: coingecko
description: "Live Bitcoin & crypto price data via CoinGecko API. Fetch BTC/USD, ETH/USD, multi-asset quotes. Supports both Demo (free) and Pro API keys. No credentials in prompts—only .env isolation."
version: 1.0.0
author: "bronoman & Hermes local (May 2026)"
license: MIT

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/DESCRIPTION.md (reported line 492)May include surrounding context.

md
---
name: coingecko
description: "Live Bitcoin & crypto price data via CoinGecko API. Fetch BTC/USD, ETH/USD, multi-asset quotes. Supports both Demo (free) and Pro API keys. No credentials in prompts—only .env isolation."
version: 1.0.0
author: "bronoman & Hermes local (May 2026)"
license: MIT

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/DESCRIPTION.md (reported line 608)May include surrounding context.

md
---
name: coingecko
description: "Live Bitcoin & crypto price data via CoinGecko API. Fetch BTC/USD, ETH/USD, multi-asset quotes. Supports both Demo (free) and Pro API keys. No credentials in prompts—only .env isolation."
version: 1.0.0
author: "bronoman & Hermes local (May 2026)"
license: MIT

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file instructs users to configure their environment using a concrete API key value, which constitutes credential disclosure and encourages unsafe copying of a potentially live secret. In a skill whose stated security model depends on '.env isolation' and not exposing credentials, this contradiction makes the exposure more dangerous, not less.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

A hardcoded API credential appears directly in the reference documentation as an environment variable example. Hardcoded secrets in repository content are routinely harvested by automated scanners and can be abused to consume service quotas or access associated API features.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · README.md (reported line 153)May include surrounding context.

md
### Option 3: Paid Pro API (For High-Volume Use)

If you run many agents or need unlimited queries:
1. **Visit:** https://www.coingecko.com/en/api/pricing
2. **Choose tier:** $10/month = most use cases
3. **Add key to .env** (same as Demo)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to environment variables and performs network operations, but it does not define an explicit tool scope such as permissions or allowed-tools. This creates an authorization gap where the runtime may grant broader capabilities than users expect, increasing the chance of unintended credential reads or outbound requests.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
### Pro Key (Paid 💰)
- **Where to get:** https://www.coingecko.com/en/api/pricing
- **Signup:** 5 minutes via API dashboard
- **Limits:** Unlimited calls (enterprise tier available)
- **Endpoint:** Same as Demo, with `x_cg_pro_api_key` param
- **Cost:** $10-50/month depending on tier
- **Best for:** High-volume data pipelines, trading bots, critical services

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup example uses an environment variable name that contradicts the documented required variable, which can cause users to misconfigure the skill and accidentally place secrets in the wrong location or troubleshooting channels. Misleading credential guidance often leads to ad hoc fixes, copy-pasting secrets, and unintended exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Including a real-looking API key value in documentation normalizes pasting secrets into files and may result in users reusing or exposing live credentials. Even if the sample is not valid, it increases the risk of accidental secret handling mistakes and can trigger unsafe copy-paste behavior into repos or logs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

A hardcoded-looking key in natural-language guidance can be mistaken for a usable credential or copied into persistent configuration, encouraging insecure secret management. This is especially risky in agent ecosystems where users may mirror documentation verbatim into shared files or automation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation explicitly claims API keys are never shown, yet it includes a concrete CoinGecko API key value in plaintext. Even if the key is intended as an example, publishing a real-looking credential creates immediate risk of unauthorized use, rate-limit exhaustion, and undermines trust in the skill's credential-handling guarantees.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
try:
        api_key = get_coingecko_api_key()
        
        url = "https://api.coingecko.com/api/v3/simple/price"
        params = {
            "ids": ",".join(assets),
            "vs_currencies": "usd",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

md
try:
        api_key = get_coingecko_api_key()
        
        url = "https://api.coingecko.com/api/v3/simple/price"
        params = {
            "ids": ",".join(assets),
            "vs_currencies": "usd",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/DESCRIPTION.md (reported line 107)May include surrounding context.

md
try:
        api_key = get_coingecko_api_key()
        
        url = "https://api.coingecko.com/api/v3/simple/price"
        params = {
            "ids": ",".join(assets),
            "vs_currencies": "usd",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_multi_asset.py (reported line 37)May include surrounding context.

python
try:
        api_key = get_coingecko_api_key()
        
        url = "https://api.coingecko.com/api/v3/simple/price"
        params = {
            "ids": ",".join(assets),
            "vs_currencies": "usd",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_price.py (reported line 44)May include surrounding context.

python
try:
        api_key = get_coingecko_api_key()
        
        url = "https://api.coingecko.com/api/v3/simple/price"
        params = {
            "ids": ",".join(assets),
            "vs_currencies": "usd",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/health_check.py (reported line 48)May include surrounding context.

python
try:
        api_key = get_coingecko_api_key()
        
        url = "https://api.coingecko.com/api/v3/simple/price"
        params = {
            "ids": ",".join(assets),
            "vs_currencies": "usd",

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module advertises BTC/USD pricing, but the Kraken fallback requests XBTUSDT, which is a different market. This can mislead downstream consumers into treating USDT-quoted data as USD, causing incorrect financial decisions or integrity issues in any automation that assumes the documented asset pair is returned.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/DESCRIPTION.md (reported line 170)May include surrounding context.

md
Fallback: Fetch BTC/USD price from Kraken (public API, no auth).
    """
    try:
        url = "https://api.kraken.com/0/public/Ticker"
        params = {"pair": "XBTUSDT"}
        
        response = requests.get(url, params=params, timeout=timeout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_price.py (reported line 99)May include surrounding context.

python
Fallback: Fetch BTC/USD price from Kraken (public API, no auth).
    """
    try:
        url = "https://api.kraken.com/0/public/Ticker"
        params = {"pair": "XBTUSDT"}
        
        response = requests.get(url, params=params, timeout=timeout)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes this skill as providing live crypto price data via the CoinGecko API, including Demo and Pro API key support. This script additionally probes Kraken as a fallback provider, introducing a second external data source and behavior not reflected in the stated skill description.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/DESCRIPTION.md:381

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:127