Back to skill

Security audit

Crypto Investment Strategist

Security checks for vulnerabilities and agentic risk

Overview

This crypto strategy skill is mostly coherent, but it should be reviewed because its market-data script disables HTTPS certificate checks for data used in trading recommendations.

Review before installing. The main issue is not hidden theft or destructive behavior; it is that live market data used for trading recommendations can be tampered with because HTTPS certificate checks are disabled. Treat outputs as informational only, avoid the --break-system-packages install path, use an isolated virtual environment, and enable snapshot logging or output files only if you are comfortable storing trade-analysis history locally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_crypto_data.py:39
Finding

TLS Certificate and Hostname Verification Disabled for Market Data Requests

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:51
Finding

Unpinned Dependency Installation with Python Environment Protection Bypass

Content
View full analysis
Remediation
View remediation
``` 4. For stronger integrity controls, generate a lock file or requirements file containing hashes and install with: ```bash python3 -m venv .venv . .venv/bin/activate python3 -m pip install --require-hashes -r requirements.txt ``` 5. Document the supported Python and `numpy` versions. 6. Rebuild and review dependency locks through a controlled update process. 7. Use the official Python Package Index or an explicitly trusted internal mirror, and warn users that custom index configuration affects dependency provenance. 8. Keep the English and Chinese setup sections synchronized after applying the changes. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Reading local logs and invoking separate scripts to fetch live data introduces additional data-flow and subprocess surfaces that are not transparently reflected in the skill’s stated purpose. In a financial skill, hidden persistence and subprocess/network behavior can mislead users and expand the attack surface, especially if historical logs contain sensitive trading decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Reading local logs and invoking separate scripts to fetch live data introduces additional data-flow and subprocess surfaces that are not transparently reflected in the skill’s stated purpose. In a financial skill, hidden persistence and subprocess/network behavior can mislead users and expand the attack surface, especially if historical logs contain sensitive trading decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading local logs and invoking separate scripts to fetch live data introduces additional data-flow and subprocess surfaces that are not transparently reflected in the skill’s stated purpose. In a financial skill, hidden persistence and subprocess/network behavior can mislead users and expand the attack surface, especially if historical logs contain sensitive trading decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Reading local logs and invoking separate scripts to fetch live data introduces additional data-flow and subprocess surfaces that are not transparently reflected in the skill’s stated purpose. In a financial skill, hidden persistence and subprocess/network behavior can mislead users and expand the attack surface, especially if historical logs contain sensitive trading decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives actionable buy/sell/hold, leverage, allocation, and execution-plan guidance without an explicit warning that outputs are not financial advice and can lead to monetary loss. In this domain, omission of a strong caution materially increases user harm because users may over-trust prescriptive trading recommendations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly disables TLS hostname checking and certificate verification for all outbound HTTPS requests. This allows a machine-in-the-middle attacker to intercept or tamper with crypto market data responses, which is especially dangerous in an investment/trading skill because manipulated prices, candles, or funding data could directly influence financial decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Outbound API requests are performed with TLS verification disabled and without any user-facing warning or consent. In this context, the skill consumes external market data from exchanges and aggregators, so an active network attacker could supply forged responses that appear legitimate and skew analysis, portfolio decisions, or leverage recommendations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README presents actionable crypto investment execution, leverage planning, and portfolio allocation guidance without a prominent warning that outputs can be wrong, stale, or financially harmful if acted upon directly. In a high-volatility financial context, users may reasonably treat the skill as decision-ready advice, increasing the chance of loss from overreliance on automated recommendations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The quick-start commands encourage one-command ranking, allocation, and execution planning based on live market inputs, but do not warn that market data may be delayed, incomplete, or unsuitable for immediate trading decisions. Because the workflow is positioned as practical and executable, users may assume operational safety and place trades with insufficient validation, leading to direct financial harm.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to use shell commands, network access, and file read/write behaviors, but it does not declare any explicit tool scope or permission boundaries. That increases the risk of over-broad execution, unintended data access, or misuse of external/networked tooling if the hosting agent auto-enables capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation language is so broad that the skill could be triggered for many general investment questions, causing it to activate in contexts where the user did not explicitly request high-risk crypto trading guidance. Over-broad routing is especially dangerous here because the outputs can influence real financial behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/market-regimes.md (reported line 20)May include surrounding context.

md
3. **Range**
   - Price rotates between support and resistance
   - Buy near support, reduce near resistance
   - Avoid breakout chasing without confirmation

4. **Event-driven volatility**
   - News, ETF headlines, macro releases, exchange incidents

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/auto_rank_assets.py (reported line 27)May include surrounding context.

python
def run_json(cmd):
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        raise RuntimeError(result.stderr.strip() or result.stdout.strip() or 'Command failed')
    return json.loads(result.stdout)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/run_investment_workflow.py (reported line 30)May include surrounding context.

python
def run_json(cmd):
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        raise RuntimeError(result.stderr.strip() or result.stdout.strip() or 'Command failed')
    return json.loads(result.stdout)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_crypto_data.py (reported line 351)May include surrounding context.

python
class CoinGeckoAPI(DataSource):
    """CoinGecko API - Fallback with no geo-blocking"""

    BASE_URL = "https://api.coingecko.com/api/v3"

    SYMBOL_MAP = {
        # Major cryptocurrencies

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes an investment strategy analysis capability centered on market assessment and planning, while this file includes a generic '--output' option that writes retrieved data to any user-specified filesystem path. Local file write behavior is not an obvious requirement of crypto strategy analysis itself and expands the behavior beyond pure data retrieval/analysis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script writes detailed analysis decisions, trading theses, and notes to a persistent local JSONL file under the repository data directory. While not overtly malicious, this creates undisclosed data retention beyond the stated advisory behavior and can expose sensitive user or strategy information to later users, other processes, backups, or accidental publication if the workspace is shared or committed.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/review_snapshots.py (reported line 23)May include surrounding context.

python
def current_price(symbol: str):
    result = subprocess.run(
        ['python3', str(FETCH_SCRIPT), '--symbol', symbol, '--mode', 'ticker'],
        capture_output=True,
        text=True,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This helper runs subprocess commands, and the script uses it to invoke fetch, indicator, and scoring scripts. Although subprocess execution is part of the implementation, there is no explicit user-facing warning, log, or comment indicating that external script execution occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script writes fetched summary-derived candle data to a named temporary file with delete=False and gives no user-facing notice that intermediate data is being persisted to disk. There is no confirmation prompt, print/log disclosure, or cleanup handling for this file, so users may not realize the script leaves artifacts behind.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

When --output is provided, the script writes results directly to the specified path, but there is no confirmation prompt or visible disclosure that a file will be created or overwritten. This is a file write operation that lacks any user warning beyond the argument name itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code writes results to a user-specified path, which can modify or overwrite filesystem contents. Although the script documents the --output option and prints a message after writing, it does not provide a prior warning or confirmation about the file write operation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes a crypto investment strategy skill focused on analysis, allocation, and trading decisions. This script additionally supports saving a top-pick snapshot via a separate logging script and writing the full workflow output to a user-specified file, which are side-effecting persistence behaviors not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code file performs a data-persisting operation when --log-top-pick is used, and the only disclosure is the brief help text 'Save a snapshot for the top ranked asset'. The implementation forwards symbol, action, price, confidence, thesis, and notes to a logging script, but there is no stronger warning in comments, output, or prompts about what analysis data will be recorded.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code writes results to a filesystem path provided by the user, but there is no confirmation prompt, visible log/print message, or inline warning around the write behavior. For code files, file writes should have some form of user disclosure unless clearly communicated elsewhere; this script's module docstring mentions input usage but does not mention output-file creation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.