T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_crypto_data.py:39- Finding
TLS Certificate and Hostname Verification Disabled for Market Data Requests
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This crypto strategy skill is mostly coherent, but it should be reviewed because its market-data script disables HTTPS certificate checks for data used in trading recommendations.
Review before installing. The main issue is not hidden theft or destructive behavior; it is that live market data used for trading recommendations can be tampered with because HTTPS certificate checks are disabled. Treat outputs as informational only, avoid the --break-system-packages install path, use an isolated virtual environment, and enable snapshot logging or output files only if you are comfortable storing trade-analysis history locally.
scripts/fetch_crypto_data.py:39TLS Certificate and Hostname Verification Disabled for Market Data Requests
README.md:51Unpinned Dependency Installation with Python Environment Protection Bypass
Reading local logs and invoking separate scripts to fetch live data introduces additional data-flow and subprocess surfaces that are not transparently reflected in the skill’s stated purpose. In a financial skill, hidden persistence and subprocess/network behavior can mislead users and expand the attack surface, especially if historical logs contain sensitive trading decisions.
Reading local logs and invoking separate scripts to fetch live data introduces additional data-flow and subprocess surfaces that are not transparently reflected in the skill’s stated purpose. In a financial skill, hidden persistence and subprocess/network behavior can mislead users and expand the attack surface, especially if historical logs contain sensitive trading decisions.
Reading local logs and invoking separate scripts to fetch live data introduces additional data-flow and subprocess surfaces that are not transparently reflected in the skill’s stated purpose. In a financial skill, hidden persistence and subprocess/network behavior can mislead users and expand the attack surface, especially if historical logs contain sensitive trading decisions.
Reading local logs and invoking separate scripts to fetch live data introduces additional data-flow and subprocess surfaces that are not transparently reflected in the skill’s stated purpose. In a financial skill, hidden persistence and subprocess/network behavior can mislead users and expand the attack surface, especially if historical logs contain sensitive trading decisions.
The skill gives actionable buy/sell/hold, leverage, allocation, and execution-plan guidance without an explicit warning that outputs are not financial advice and can lead to monetary loss. In this domain, omission of a strong caution materially increases user harm because users may over-trust prescriptive trading recommendations.
The code explicitly disables TLS hostname checking and certificate verification for all outbound HTTPS requests. This allows a machine-in-the-middle attacker to intercept or tamper with crypto market data responses, which is especially dangerous in an investment/trading skill because manipulated prices, candles, or funding data could directly influence financial decisions.
Outbound API requests are performed with TLS verification disabled and without any user-facing warning or consent. In this context, the skill consumes external market data from exchanges and aggregators, so an active network attacker could supply forged responses that appear legitimate and skew analysis, portfolio decisions, or leverage recommendations.
The README presents actionable crypto investment execution, leverage planning, and portfolio allocation guidance without a prominent warning that outputs can be wrong, stale, or financially harmful if acted upon directly. In a high-volatility financial context, users may reasonably treat the skill as decision-ready advice, increasing the chance of loss from overreliance on automated recommendations.
The quick-start commands encourage one-command ranking, allocation, and execution planning based on live market inputs, but do not warn that market data may be delayed, incomplete, or unsuitable for immediate trading decisions. Because the workflow is positioned as practical and executable, users may assume operational safety and place trades with insufficient validation, leading to direct financial harm.
The skill instructs the agent to use shell commands, network access, and file read/write behaviors, but it does not declare any explicit tool scope or permission boundaries. That increases the risk of over-broad execution, unintended data access, or misuse of external/networked tooling if the hosting agent auto-enables capabilities.
The invocation language is so broad that the skill could be triggered for many general investment questions, causing it to activate in contexts where the user did not explicitly request high-risk crypto trading guidance. Over-broad routing is especially dangerous here because the outputs can influence real financial behavior.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
3. **Range**
- Price rotates between support and resistance
- Buy near support, reduce near resistance
- Avoid breakout chasing without confirmation
4. **Event-driven volatility**
- News, ETF headlines, macro releases, exchange incidents
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_json(cmd):
result = subprocess.run(cmd, capture_output=True, text=True)
if result.returncode != 0:
raise RuntimeError(result.stderr.strip() or result.stdout.strip() or 'Command failed')
return json.loads(result.stdout)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_json(cmd):
result = subprocess.run(cmd, capture_output=True, text=True)
if result.returncode != 0:
raise RuntimeError(result.stderr.strip() or result.stdout.strip() or 'Command failed')
return json.loads(result.stdout)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
class CoinGeckoAPI(DataSource):
"""CoinGecko API - Fallback with no geo-blocking"""
BASE_URL = "https://api.coingecko.com/api/v3"
SYMBOL_MAP = {
# Major cryptocurrencies
The manifest describes an investment strategy analysis capability centered on market assessment and planning, while this file includes a generic '--output' option that writes retrieved data to any user-specified filesystem path. Local file write behavior is not an obvious requirement of crypto strategy analysis itself and expands the behavior beyond pure data retrieval/analysis.
The script writes detailed analysis decisions, trading theses, and notes to a persistent local JSONL file under the repository data directory. While not overtly malicious, this creates undisclosed data retention beyond the stated advisory behavior and can expose sensitive user or strategy information to later users, other processes, backups, or accidental publication if the workspace is shared or committed.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def current_price(symbol: str):
result = subprocess.run(
['python3', str(FETCH_SCRIPT), '--symbol', symbol, '--mode', 'ticker'],
capture_output=True,
text=True,
This helper runs subprocess commands, and the script uses it to invoke fetch, indicator, and scoring scripts. Although subprocess execution is part of the implementation, there is no explicit user-facing warning, log, or comment indicating that external script execution occurs.
The script writes fetched summary-derived candle data to a named temporary file with delete=False and gives no user-facing notice that intermediate data is being persisted to disk. There is no confirmation prompt, print/log disclosure, or cleanup handling for this file, so users may not realize the script leaves artifacts behind.
When --output is provided, the script writes results directly to the specified path, but there is no confirmation prompt or visible disclosure that a file will be created or overwritten. This is a file write operation that lacks any user warning beyond the argument name itself.
This code writes results to a user-specified path, which can modify or overwrite filesystem contents. Although the script documents the --output option and prints a message after writing, it does not provide a prior warning or confirmation about the file write operation.
The manifest describes a crypto investment strategy skill focused on analysis, allocation, and trading decisions. This script additionally supports saving a top-pick snapshot via a separate logging script and writing the full workflow output to a user-specified file, which are side-effecting persistence behaviors not reflected in the manifest description.
This code file performs a data-persisting operation when --log-top-pick is used, and the only disclosure is the brief help text 'Save a snapshot for the top ranked asset'. The implementation forwards symbol, action, price, confidence, thesis, and notes to a logging script, but there is no stronger warning in comments, output, or prompts about what analysis data will be recorded.
This code writes results to a filesystem path provided by the user, but there is no confirmation prompt, visible log/print message, or inline warning around the write behavior. For code files, file writes should have some form of user disclosure unless clearly communicated elsewhere; this script's module docstring mentions input usage but does not mention output-file creation.
No suspicious patterns detected.