Back to skill

Security audit

Crypto Price Pro

Security checks for vulnerabilities and agentic risk

Overview

This crypto price skill is mostly purpose-aligned, but it asks users to persist email credentials and set up recurring outbound emails in ways that need careful review.

Install only if you are comfortable with a skill that can send email using SMTP credentials and can be scheduled to run daily. Avoid putting the SMTP password in ~/.zshrc; use a scoped app password and a safer secret store, and review any cron job so you know how to disable it. Prefer installing chart dependencies in an isolated virtual environment with pinned versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:76
Finding

Plaintext SMTP Credential Persistence in Shell Startup Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 76–81
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

bash
**Permanent configuration (add to ~/.zshrc):**
```bash
echo 'export EMAIL_SENDER="your_email@126.com"' >> ~/.zshrc
echo 'export EMAIL_SENDER_NAME="Your Name"' >> ~/.zshrc
echo 'export EMAIL_PASSWORD="your_smtp_password"' >> ~/.zshrc
echo 'export EMAIL_RECIPIENT="recipient@example.com"' >> ~/.zshrc
source ~/.zshrc
text

### Technical Analysis

The documented configuration procedure instructs users to persist an SMTP password as plaintext in `~/.zshrc`. Shell startup files are not dedicated secret stores and may be read by other processes operating under the same account, included in backups, copied during troubleshooting, or accidentally committed or shared.

Loading the value from an environment variable in the Python script prevents hardcoding it in source code, but it does not protect the secret when the instructions persist that variable in an ordinary plaintext file. Sourcing the file also exports the credential into the environment of subsequently launched child processes.

### Attack Path

1. A user follows the documented permanent configuration procedure.
2. The SMTP password is written verbatim to `~/.zshrc`.
3. An attacker, malicious local process, compromised development tool, backup reader, or diagnostic collector obtains read access to the file.
4. The attacker extracts `EMAIL_SENDER` and `EMAIL_PASSWORD`.
5. The attacker authenticates to the configured SMTP account and sends email as the victim, subject to the account's permissions and provider controls.

### Impact Assessment

Successful exploitation exposes the SMTP credential and associated sender identity. An attacker may send unauthorized messages, distribute spam or phishing email, damage sender reputation, and potentially cause account suspension. The issue does not directly grant e
...[truncated 139 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not recommend storing passwords in ~/.zshrc, ~/.bashrc, or other general-purpose shell startup files.
  • Store the SMTP credential in an operating-system keychain, credential manager, or managed secret service and retrieve it only when the report is sent.
  • Prefer provider-issued, narrowly scoped application passwords over the primary email account password.
  • If file-based storage is unavoidable, use a dedicated secrets file outside the repository, restrict it to mode 0600, and ensure it is excluded from version control and backups where appropriate.
  • Avoid globally exporting the credential to every child process in the interactive shell.
  • Document credential rotation and immediate revocation procedures.
  • Replace the permanent configuration example with a secure wrapper that reads the secret from a keychain at runtime.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:151
Finding

Unpinned Package Installation Bypasses Python Environment Protections

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 151–156
Vulnerability Type: Unsafe and unpinned third-party dependency installation
Risk Level: Medium

bash
# Install matplotlib (chart generation)
pip3 install matplotlib --break-system-packages --user

# Or
brew install python-matplotlib

Technical Analysis

The installation command does not pin a reviewed matplotlib version or verify package hashes. Consequently, the package and its transitive dependencies may change between installations. Python package installation can execute package build or installation logic with the invoking user's privileges.

The --break-system-packages option explicitly bypasses the externally managed environment safeguard intended to prevent pip from modifying or conflicting with a platform-managed Python installation. Combining this bypass with an unpinned dependency increases supply-chain exposure and the risk of dependency conflicts or environment corruption.

The Homebrew alternative is safer than invoking an unknown source directly, but it also lacks an explicit reviewed version in the documentation.

Attack Path

  1. A user follows the documented dependency installation command.
  2. pip resolves the current matplotlib release and mutable transitive dependencies from its configured package index.
  3. A compromised package release, compromised index, maliciously configured mirror, or unsafe dependency update is selected.
  4. Package build or installation code executes with the user's privileges.
  5. Malicious code can access files and credentials available to that user or establish user-level persistence.
  6. Independently of malicious package compromise, bypassing the externally managed environment protection may introduce conflicting packages and destabilize other Python applications.

Impact Assessment

A compromised dependency could execute arbitrary code with the privileges of the user r ...[truncated 338 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove --break-system-packages from the installation instructions.
  • Create and use an isolated virtual environment for the Skill.
  • Pin reviewed direct and transitive dependency versions in a lock file.
  • Record and verify cryptographic hashes, such as by installing from a hash-locked requirements file with pip install --require-hashes.
  • Use a trusted, explicitly configured package index over HTTPS.
  • Regularly scan pinned dependencies for known vulnerabilities and update them through a controlled review process.
  • Provide reproducible setup instructions, for example:
bash
python3 -m venv .venv
. .venv/bin/activate
python3 -m pip install --require-hashes -r requirements.txt
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documentation claims weekly report generation, email delivery, and scheduled push behavior that static analysis says are not actually implemented. This mismatch is dangerous because operators may approve or trust the skill based on inaccurate documentation, while hidden or future code paths could perform actions that were not properly reviewed, or users could be misled into configuring sensitive SMTP credentials unnecessarily.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

💴 人民币价格: ¥505,100.00 📈 24h 涨跌: +1.97% 🏦 市值: $1.46T

text

### 历史价格

📈 BTC 3 天历史价格

03-14: $70,965.28 03-15: $71,217.10 03-16: $72,681.91

text

## 定时任务配置

### 每天上午 10 点发送周报

```bash
# 添加到 crontab
0 10 * * * cd /Users/admin/.openclaw/workspace && python3 skills/crypto-price/scripts/crypto_weekly_report.py

或使用 OpenClaw cron:

bash
openclaw cron add --schedule "0 10 * * *" --command "python3 skills/crypto-price/scripts/crypto_weekly_report.py"

注意事项

  1. API 限制: CoinGecko 免费 API 有速率限制(10-50 次/分钟)
  2. 数据延迟: 价格数据延迟约 1-5 分钟
  3. matplotlib: 生成图表需要安装 matplotlib
  4. 邮箱配置: 邮件发送需要配置 126 邮箱 SMTP

依赖安装

bash
# 安装 matplotlib(图表生

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/crypto_weekly_report.py (reported line 319)May include surrounding context.

python
print("  export EMAIL_SENDER=\"your_email@126.com\"")
        print("  export EMAIL_PASSWORD=\"your_smtp_password\"")
        print("  export EMAIL_RECIPIENT=\"recipient@example.com\"")
        print("\n或复制 .env.example 为 .env 并填写配置")
        sys.exit(1)
    
    # 1. 获取所有币种数据

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill documents capabilities that require network access and use of environment variables for SMTP credentials, but it does not declare an explicit tool scope such as allowed-tools or permissions. This weakens least-privilege controls and can cause the runtime to grant broader access than users or reviewers expect, especially because the skill also describes outbound email behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger description is broad enough to overlap with ordinary conversation about crypto prices, analysis, or reports, which can cause the skill to activate unexpectedly. In context, that matters because the skill advertises network access and potential outbound email/scheduled actions, so accidental invocation could lead to data fetches or setup flows the user did not intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation describes timed email sending but does not prominently warn that this creates recurring autonomous outbound communication. That omission can cause users to enable persistence and automatic external data transmission without fully understanding the privacy, spam, and operational risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level description is entirely in Chinese and presents the skill as operating in Chinese, with no indication that another language is supported or that the user can choose their preferred locale. This is a natural-language locale policy concern because the file contains user-facing text that implicitly fixes the interaction language without opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto_price.py (reported line 42)May include surrounding context.

python
symbol = symbol.upper()
    coin_id = COIN_MAP.get(symbol, symbol.lower())
    
    api_url = "https://api.coingecko.com/api/v3/simple/price"
    params = {
        "ids": coin_id,
        "vs_currencies": "usd,cny",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto_price.py (reported line 92)May include surrounding context.

python
symbol = symbol.upper()
    coin_id = COIN_MAP.get(symbol, symbol.lower())
    
    api_url = "https://api.coingecko.com/api/v3/simple/price"
    params = {
        "ids": coin_id,
        "vs_currencies": "usd,cny",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto_weekly_report.py (reported line 48)May include surrounding context.

python
symbol = symbol.upper()
    coin_id = COIN_MAP.get(symbol, symbol.lower())
    
    api_url = "https://api.coingecko.com/api/v3/simple/price"
    params = {
        "ids": coin_id,
        "vs_currencies": "usd,cny",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto_weekly_report.py (reported line 76)May include surrounding context.

python
symbol = symbol.upper()
    coin_id = COIN_MAP.get(symbol, symbol.lower())
    
    api_url = "https://api.coingecko.com/api/v3/simple/price"
    params = {
        "ids": coin_id,
        "vs_currencies": "usd,cny",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

技能清单主要描述查询虚拟币实时价格、历史数据,并支持生成趋势图、周报和邮件推送;其中本文件实际实现了将生成的图表持久化到本地磁盘,而不是仅返回查询结果。对最终用户来说这是额外的写文件副作用,和“查询”类技能的预期存在语义差异,尤其这里还默认写入固定路径。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The command-line help and examples shown to users are hard-coded in Chinese, and similar user-facing messages throughout the script also use Chinese only. Because the skill does not offer a language selection mechanism or document a justified locale restriction, this appears to force a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file-level description and user-facing strings indicate the skill is designed to communicate exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

整个 SKILL.md 的描述、用法、输出示例和提示均固定为中文,未说明这是区域限定技能,也未提供用户语言选择或切换方式。按照语言/区域策略,若技能面向通用用户,强制单一语言而无 opt-in 可能构成自然语言层面的策略问题。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

清单描述提到价格查询、历史数据、趋势图、周报和邮件推送,但本文件还提供了多币种对比趋势图和归一化涨跌幅比较分析。这属于额外的分析能力扩展,虽与币价主题相关,但未在技能描述中体现。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.