Back to skill

Security audit

CoinFound-Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill mainly reads CoinFound RWA API data; it includes opt-in schema-writing helper code, but normal use is scoped to user-directed API reads.

Before installing, be comfortable with the agent making user-directed requests to CoinFound's API. Treat the skill's normal workflow as read-oriented, and avoid running probe_schema.py with --write-snapshot or calling the write helper functions in environments that require strict no-write behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Writing schema snapshot files and actively probing endpoint schemas contradicts the claimed read-only design. In this context, that is more dangerous because the skill is presented as a safe, bundled-data reader; unexpected writes can tamper with trusted local artifacts, and active schema probing can introduce uncontrolled network interactions and persistence of untrusted remote data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

Writing schema snapshot files and actively probing endpoint schemas contradicts the claimed read-only design. In this context, that is more dangerous because the skill is presented as a safe, bundled-data reader; unexpected writes can tamper with trusted local artifacts, and active schema probing can introduce uncontrolled network interactions and persistence of untrusted remote data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Writing schema snapshot files and actively probing endpoint schemas contradicts the claimed read-only design. In this context, that is more dangerous because the skill is presented as a safe, bundled-data reader; unexpected writes can tamper with trusted local artifacts, and active schema probing can introduce uncontrolled network interactions and persistence of untrusted remote data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module exposes write_catalog(), which can modify bundled package data despite the skill being ներկայացված as read-only. This creates an integrity and trust-boundary issue: downstream code or an agent could mutate the local endpoint catalog, causing later reads to consume attacker-influenced endpoint metadata or schemas.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill advertises executable behavior via bundled Python scripts and network-backed data access, but it does not declare any explicit tool scope or permissions. That creates an authorization and review gap: operators cannot reliably constrain file, write, or network capabilities from the manifest, increasing the chance of unintended access or misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shared/coinfound_rwa/catalog.py (reported line 11)May include surrounding context.

python
DATA_DIR = PACKAGE_ROOT / "data"
DEFAULT_CATALOG_PATH = DATA_DIR / "endpoint_catalog.json"
SNAPSHOT_DIR = DATA_DIR / "schema_snapshots"
BASE_URL = "https://api.coinfound.org/api/kakyoin"


def load_catalog(path: Path | None = None) -> list[dict[str, Any]]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shared/coinfound_rwa/data/schema_snapshots/commodity__market-cap__pie.json (reported line 30)May include surrounding context.

json
DATA_DIR = PACKAGE_ROOT / "data"
DEFAULT_CATALOG_PATH = DATA_DIR / "endpoint_catalog.json"
SNAPSHOT_DIR = DATA_DIR / "schema_snapshots"
BASE_URL = "https://api.coinfound.org/api/kakyoin"


def load_catalog(path: Path | None = None) -> list[dict[str, Any]]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shared/coinfound_rwa/data/schema_snapshots/market-overview__asset-classes__list.json (reported line 38)May include surrounding context.

json
DATA_DIR = PACKAGE_ROOT / "data"
DEFAULT_CATALOG_PATH = DATA_DIR / "endpoint_catalog.json"
SNAPSHOT_DIR = DATA_DIR / "schema_snapshots"
BASE_URL = "https://api.coinfound.org/api/kakyoin"


def load_catalog(path: Path | None = None) -> list[dict[str, Any]]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shared/coinfound_rwa/data/schema_snapshots/platforms__detail__asset__dataset.json (reported line 92)May include surrounding context.

json
DATA_DIR = PACKAGE_ROOT / "data"
DEFAULT_CATALOG_PATH = DATA_DIR / "endpoint_catalog.json"
SNAPSHOT_DIR = DATA_DIR / "schema_snapshots"
BASE_URL = "https://api.coinfound.org/api/kakyoin"


def load_catalog(path: Path | None = None) -> list[dict[str, Any]]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shared/coinfound_rwa/data/schema_snapshots/private-credit__aggregates.json (reported line 35)May include surrounding context.

json
DATA_DIR = PACKAGE_ROOT / "data"
DEFAULT_CATALOG_PATH = DATA_DIR / "endpoint_catalog.json"
SNAPSHOT_DIR = DATA_DIR / "schema_snapshots"
BASE_URL = "https://api.coinfound.org/api/kakyoin"


def load_catalog(path: Path | None = None) -> list[dict[str, Any]]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shared/coinfound_rwa/data/schema_snapshots/stable-coin__aggregates.json (reported line 51)May include surrounding context.

json
DATA_DIR = PACKAGE_ROOT / "data"
DEFAULT_CATALOG_PATH = DATA_DIR / "endpoint_catalog.json"
SNAPSHOT_DIR = DATA_DIR / "schema_snapshots"
BASE_URL = "https://api.coinfound.org/api/kakyoin"


def load_catalog(path: Path | None = None) -> list[dict[str, Any]]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shared/coinfound_rwa/data/schema_snapshots/stable-coin__dataset.json (reported line 96)May include surrounding context.

json
DATA_DIR = PACKAGE_ROOT / "data"
DEFAULT_CATALOG_PATH = DATA_DIR / "endpoint_catalog.json"
SNAPSHOT_DIR = DATA_DIR / "schema_snapshots"
BASE_URL = "https://api.coinfound.org/api/kakyoin"


def load_catalog(path: Path | None = None) -> list[dict[str, Any]]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shared/coinfound_rwa/data/schema_snapshots/stable-coin__market-cap__timeseries.json (reported line 45)May include surrounding context.

json
DATA_DIR = PACKAGE_ROOT / "data"
DEFAULT_CATALOG_PATH = DATA_DIR / "endpoint_catalog.json"
SNAPSHOT_DIR = DATA_DIR / "schema_snapshots"
BASE_URL = "https://api.coinfound.org/api/kakyoin"


def load_catalog(path: Path | None = None) -> list[dict[str, Any]]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · shared/coinfound_rwa/data/schema_snapshots/x-stock__dataset.json (reported line 18)May include surrounding context.

json
DATA_DIR = PACKAGE_ROOT / "data"
DEFAULT_CATALOG_PATH = DATA_DIR / "endpoint_catalog.json"
SNAPSHOT_DIR = DATA_DIR / "schema_snapshots"
BASE_URL = "https://api.coinfound.org/api/kakyoin"


def load_catalog(path: Path | None = None) -> list[dict[str, Any]]:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as read-only, but probe_endpoint_schema can persist snapshot files when write_snapshot_file is enabled. This breaks the advertised trust boundary and can create unintended local side effects, including writing potentially sensitive response excerpts to disk in a predictable path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This function performs live network probing and can optionally write probe results to disk without any visible warning, consent, or disclosure in the code path. In a skill marketed as read-only, undisclosed outbound requests and persistence increase the risk of surprising data exposure, policy violations, and misuse in restricted environments.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes the skill as a read-only CoinFound RWA data skill backed by bundled endpoint catalogs and schema snapshots. However, this module implements write_snapshot, which creates directories and writes JSON snapshot files to disk, introducing a mutating capability inconsistent with a read-only description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

A skill whose stated purpose is to read bundled RWA data and schema snapshots does not obviously require the ability to create directories and write new snapshot files at runtime. This persistence capability goes beyond the justified implementation needs of consuming bundled read-only data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This function performs an outbound HTTP request and reads remote response data, but there is no confirmation prompt, logging, print statement, or explanatory comment/docstring in the file disclosing that network transmission occurs. For a code file, outbound network activity is a safety-relevant operation that should have some visible user disclosure unless documented elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The write_snapshot function creates directories and writes JSON snapshot data to a file, which is a file-write operation covered by the missing-warning rule for code files. This code has no confirmation prompt, logging, print statement, docstring, or comment disclosing that user or system data may be persisted to disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.