Back to skill

Security audit

Crypto Portfolio Tracker Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill appears domain-related but overstates its capabilities and uses a plaintext credential-style configuration for sensitive crypto integrations.

Review this carefully before installing. Do not put live exchange API keys, API secrets, Telegram bot tokens, wallet addresses, or other sensitive financial metadata into the included config unless you first move secrets to a safer storage method and understand which external services will be contacted. Expect only basic sample price lookup and local alert recording from the shipped code.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/config.json:3
Finding

Plaintext Storage Schema for Exchange and Telegram Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a comprehensive crypto portfolio tracking and analysis system with monitoring, analytics, and alerting across multiple platforms. The provided code only implements a narrow subset: setting a price alert by writing alert data to a local file. It does not connect to wallets or exchanges, calculate portfolio metrics, monitor prices in real time, generate alerts when conditions are met, or produce reports/analysis. While price alerts are mentioned in the description, this code chunk alone is materially narrower than the declared primary purpose, so the description does not accurately represent the actual behavior of the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is related to cryptocurrency portfolio tracking, so the general domain matches. However, the declared description substantially overstates the implemented functionality. The script only performs a single run, querying CoinGecko for spot prices and 24h change for a fixed set of assets defined in code. It does not connect to wallets or exchanges, aggregate holdings across platforms, compute historical performance/P&L/ROI, emit alerts, or produce richer analysis such as allocation/diversification. Because the description claims several major capabilities that are not present, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
node scripts/track_portfolio.js

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Overly broad activation language can cause the skill to trigger for generic crypto-related requests beyond the user's intent. In this context, that is risky because the skill claims wallet/exchange aggregation and may prompt unnecessary use of external services or disclosure of sensitive portfolio data when a simpler, non-sensitive response would suffice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation names external APIs, blockchain explorers, wallet addresses, and exchange integrations but does not warn users that portfolio data may be sent to third-party services. In a crypto context, even wallet addresses and exchange-linked holdings are sensitive financial metadata that can expose balances, behavior, and identity correlations if disclosed unexpectedly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/track_portfolio.js (reported line 11)May include surrounding context.

js
const https = require('https');

// Free CoinGecko API - no key required
const COINGECKO_API = 'https://api.coingecko.com/api/v3';

// Sample portfolio (users should customize)
const PORTFOLIO = {

Static analysis

No suspicious patterns detected.