Back to skill

Security audit

money-toolkit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed finance-data toolkit that uses public market and blockchain endpoints, with some quality and dependency cautions but no evidence of hidden persistence, credential access, or malicious behavior.

Install only if you are comfortable with a Chinese-language finance helper that contacts public crypto, DeFi, and blockchain RPC services. Treat outputs as informational, verify market and protocol data independently, and install web3 in a dedicated environment with pinned dependencies if you use the gas-fee script.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/gas-fee.py:21
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: scripts/gas-fee.py:21
Vulnerability Type: Unpinned package installation
Risk Level: Medium

Vulnerable Code:

text
pip install web3

Technical Analysis

The script directs users to install the latest available release of the third-party web3 package without specifying an audited version, verifying package hashes, or providing a dependency lock file. The installed package and its transitive dependencies can therefore change independently of the reviewed Skill.

Although the script does not automatically execute the installation command, users following its displayed remediation instruction may install code that was not part of the audit. If the package index, a future package release, or a transitive dependency is compromised, malicious installation or import-time code could execute in the user's environment.

Attack Path

  1. A user runs scripts/gas-fee.py in an environment where web3 is unavailable.
  2. The script displays an instruction to run pip install web3.
  3. The user executes that command without a pinned version or hash verification.
  4. The package manager resolves the current web3 release and its transitive dependencies from the configured package index.
  5. If any resolved package or package source has been compromised, attacker-controlled code executes during installation or when the script imports the package.
  6. The malicious code runs with the permissions of the user performing the installation or invoking the script.

Impact Assessment

A compromised dependency could execute arbitrary code with the installing user's privileges. Depending on those privileges and the host environment, the resulting access could include reading or modifying user files, accessing environment variables and locally available credentials, making network requests, or altering the Python environment. The Skill itself does not request elevated privileges ...[truncated 93 chars]

Remediation
View remediation

Remediation Suggestions

  • Add a reviewed dependency manifest that pins web3 and all transitive dependencies to exact versions.
  • Generate and verify cryptographic hashes for dependency artifacts, such as by using a hash-locked requirements file and pip install --require-hashes.
  • Replace the unpinned installation instruction with a command referencing the reviewed dependency manifest.
  • Recommend installation inside a dedicated virtual environment rather than the system Python environment.
  • Use automated dependency scanning and controlled update reviews before changing pinned versions.
  • Document the trusted package index and avoid unverified alternative indexes or direct package URLs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the skill uses live blockchain RPC or other network access not clearly disclosed by its description, users may trigger external calls and data exposure they did not reasonably expect from a generic finance toolbox. In a financial context, hidden live network interactions increase risk because users may rely on outputs for money decisions without understanding provenance, latency, or external dependencies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill uses live blockchain RPC or other network access not clearly disclosed by its description, users may trigger external calls and data exposure they did not reasonably expect from a generic finance toolbox. In a financial context, hidden live network interactions increase risk because users may rely on outputs for money decisions without understanding provenance, latency, or external dependencies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill uses live blockchain RPC or other network access not clearly disclosed by its description, users may trigger external calls and data exposure they did not reasonably expect from a generic finance toolbox. In a financial context, hidden live network interactions increase risk because users may rely on outputs for money decisions without understanding provenance, latency, or external dependencies.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly requires internet access and lists scripts that appear to fetch external financial and blockchain data, but it does not declare any tool scope such as permissions or allowed-tools. That makes network-capable behavior under-specified and reduces enforceability and user visibility into what the skill may access externally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad terms like 赚钱, 理财, 收益, 省钱, and yield, which overlap with ordinary conversation and can cause the skill to activate in contexts the user did not intend. Overbroad activation is risky here because the skill claims financial and internet-dependent functionality, so accidental invocation could lead to unsolicited financial guidance or external data access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and trigger conditions are written entirely in Chinese, while also including some English trigger words, but there is no statement offering a language choice or explaining that the skill is intentionally Chinese-only. This can amount to a language-policy issue because the user is not given an opt-in or explicit notice of the locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill presents financial, yield, arbitrage, and airdrop functionality but does not warn users about investment risk, scams, volatility, data staleness, or the fact that results may depend on live internet sources. In a money-related context, missing risk disclosures can materially increase harm because users may treat outputs as trustworthy investment guidance and act on them.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger conditions are phrased broadly, such as any question about making money, finance, or yield, without precise criteria for activation. In a finance-focused skill, ambiguous invocation increases the chance of unintended engagement, misleading assistance, or network-backed behavior in routine discussions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/arbitrage.py (reported line 17)May include surrounding context.

python
def fetch_price(coin_id):
    """Fetch price from CoinGecko."""
    url = f"https://api.coingecko.com/api/v3/simple/price?ids={coin_id}&vs_currencies=usd"
    try:
        with urllib.request.urlopen(url, timeout=10) as r:
            data = json.loads(r.read())

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/arbitrage.py (reported line 26)May include surrounding context.

python
return 0

def check_binance(symbol):
    url = f"https://api.binance.com/api/v3/ticker/price?symbol={symbol}USDT"
    try:
        with urllib.request.urlopen(url, timeout=10) as r:
            return float(json.loads(r.read()).get('price', 0))

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/arbitrage.py (reported line 43)May include surrounding context.

python
return 0

def check_bybit(symbol):
    url = f"https://api.bybit.com/v5/market/tickers?category=spot&symbol={symbol}USDT"
    try:
        with urllib.request.urlopen(url, timeout=10) as r:
            data = json.loads(r.read())

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language strings, including the module description and all user-facing output, are hard-coded in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's title and all user-facing messages are written in Chinese, which imposes a specific language on users without any opt-in or explanation of a region-specific requirement. This matches the policy concern for language or locale constraints that are not optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing skill description and feature list are presented entirely in Chinese, with no indication that users can choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate language/locale policy expectations for broader users because it implicitly imposes a language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s docstring and all user-facing output strings are in Chinese, which imposes a specific language/locale on users without any opt-in or alternative. The policy allows locale constraints only when documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing natural-language strings entirely in Chinese, including the tool description and command-line usage text. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code connects to multiple third-party blockchain RPC endpoints and retrieves gas price data, which is a network operation that transmits the user's IP and request metadata. The script prints results but does not disclose beforehand that it will contact external services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.