Back to skill

Security audit

my skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small OKX price lookup helper that only fetches public market data and does not show hidden, destructive, persistent, or credential-seeking behavior.

Install only if you are comfortable with the skill making live HTTPS requests to OKX for the symbols you ask about. For better hygiene, the publisher should pin requests, document the required network host explicitly, and fix the example install path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a Python script that fetches OKX market data, which implies outbound network access, but the manifest does not declare any tool scope such as permissions or allowed-tools. Undeclared network capability weakens policy enforcement and reviewability, making it easier for a skill to perform external communication beyond what operators or users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and README content are written entirely in Chinese, which imposes a language choice on users without any stated opt-in or explanation that the skill is intended only for a Chinese-speaking or region-specific audience. Under the policy, language constraints should either be optional for the user or clearly documented as justified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency is specified as requests>=2.31.0, which allows any newer release to be installed without a tested upper bound or exact pin. This creates a supply-chain and reproducibility risk because future releases could introduce breaking changes or newly exploitable behavior, and the exact installed version cannot be audited reliably.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Because requests is not pinned, it is impossible to verify from the manifest whether the installed version includes fixes for known advisories affecting older or some recent releases. In a skill that performs external HTTP requests to a public crypto price API, using an unresolved version increases uncertainty around transport and credential-handling security, even though this specific skill appears to use only public data and therefore lowers direct exploit impact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.