T09 · Insecure Skill Coding Practices
- Location
references/config.json:3- Finding
Plaintext Storage Schema for Exchange and Telegram Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears domain-related but overstates its capabilities and uses a plaintext credential-style configuration for sensitive crypto integrations.
Review this carefully before installing. Do not put live exchange API keys, API secrets, Telegram bot tokens, wallet addresses, or other sensitive financial metadata into the included config unless you first move secrets to a safer storage method and understand which external services will be contacted. Expect only basic sample price lookup and local alert recording from the shipped code.
references/config.json:3Plaintext Storage Schema for Exchange and Telegram Credentials
The declared description presents a comprehensive crypto portfolio tracking and analysis system with monitoring, analytics, and alerting across multiple platforms. The provided code only implements a narrow subset: setting a price alert by writing alert data to a local file. It does not connect to wallets or exchanges, calculate portfolio metrics, monitor prices in real time, generate alerts when conditions are met, or produce reports/analysis. While price alerts are mentioned in the description, this code chunk alone is materially narrower than the declared primary purpose, so the description does not accurately represent the actual behavior of the supplied code.
The code is related to cryptocurrency portfolio tracking, so the general domain matches. However, the declared description substantially overstates the implemented functionality. The script only performs a single run, querying CoinGecko for spot prices and 24h change for a fixed set of assets defined in code. It does not connect to wallets or exchanges, aggregate holdings across platforms, compute historical performance/P&L/ROI, emit alerts, or produce richer analysis such as allocation/diversification. Because the description claims several major capabilities that are not present, this is a description-behavior mismatch.
Referenced artifact was not completely inspected
node scripts/track_portfolio.js
Overly broad activation language can cause the skill to trigger for generic crypto-related requests beyond the user's intent. In this context, that is risky because the skill claims wallet/exchange aggregation and may prompt unnecessary use of external services or disclosure of sensitive portfolio data when a simpler, non-sensitive response would suffice.
The documentation names external APIs, blockchain explorers, wallet addresses, and exchange integrations but does not warn users that portfolio data may be sent to third-party services. In a crypto context, even wallet addresses and exchange-linked holdings are sensitive financial metadata that can expose balances, behavior, and identity correlations if disclosed unexpectedly.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
const https = require('https');
// Free CoinGecko API - no key required
const COINGECKO_API = 'https://api.coingecko.com/api/v3';
// Sample portfolio (users should customize)
const PORTFOLIO = {
No suspicious patterns detected.