T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned and Unused Third-Party Dependencies Increase Supply-Chain Exposure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This trading skill is being sent to Review because it markets advanced financial analytics that the bundled code does not actually implement.
Before installing, treat this as a basic crypto market-data helper, not professional or statistically validated trading advice. Be aware it can send selected assets and a CoinGecko API key to external services, and its unused unpinned dependencies should be removed or pinned before use in a sensitive environment.
SKILL.md:15Unpinned and Unused Third-Party Dependencies Increase Supply-Chain Exposure
The skill advertises sophisticated probabilistic analytics, backtesting, regime-adjusted thresholds, and whale/on-chain correlation, but the static finding indicates the implemented behavior does not actually provide those controls or computations. This is dangerous because users may place financial trust in outputs that appear quantitatively rigorous when they are in fact based on much simpler heuristics, creating a deception and unsafe-decision risk amplified by the financial trading context.
The skill description advertises institutional-grade probabilistic analytics, confidence intervals, historical win rates, market-regime thresholds, and whale-flow correlation, but the implementation only performs basic heuristic RSI/VWAP/price-change checks and DeFi pool listing. In a trading context, this discrepancy can materially mislead users into relying on outputs as sophisticated decision support, increasing the risk of financial loss through false trust and unsafe automation.
The skill declares access to an environment variable and external Python/network dependencies but does not define any explicit tool scope such as permissions or allowed-tools. That creates unnecessary ambiguity about what runtime capabilities the skill may exercise, which increases the risk of overbroad network use or accidental secret exposure in systems that rely on manifest scoping for enforcement.
The skill provides concrete trading actions, invalidation levels, and position-sizing guidance without a clear warning that the content is not financial advice and can result in losses. In a trading skill, this context makes the omission more dangerous because users may interpret the guidance as reliable professional advice and take real-money actions without understanding risk, uncertainty, or model limitations.
This hardcoded CoinGecko endpoint confirms outbound network communication to a third-party service. In this skill, the request includes asset identifiers and may include an API key header, so the main risk is undisclosed external data transmission rather than code execution or direct compromise.
from datetime import datetime, timezone
# ── Constants ─────────────────────────────────────────────────────────────────
COINGECKO_BASE = "https://api.coingecko.com/api/v3"
DEFILLAMA_POOLS = "https://yields.llama.fi/pools"
SAUCER_POOLS = "https://api.saucerswap.finance/pools"
BINANCE_OHLCV = "https://api.binance.com/api/v3/klines"
This hardcoded SaucerSwap API endpoint also represents outbound third-party communication without any explicit runtime notice to the user. The danger is limited to privacy/transparency concerns and dependency on an external service, but in a finance-related skill that still matters because users may not expect portfolio-interest queries to be transmitted.
# ── Constants ─────────────────────────────────────────────────────────────────
COINGECKO_BASE = "https://api.coingecko.com/api/v3"
DEFILLAMA_POOLS = "https://yields.llama.fi/pools"
SAUCER_POOLS = "https://api.saucerswap.finance/pools"
BINANCE_OHLCV = "https://api.binance.com/api/v3/klines"
SYMBOL_MAP = {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
COINGECKO_BASE = "https://api.coingecko.com/api/v3"
DEFILLAMA_POOLS = "https://yields.llama.fi/pools"
SAUCER_POOLS = "https://api.saucerswap.finance/pools"
BINANCE_OHLCV = "https://api.binance.com/api/v3/klines"
SYMBOL_MAP = {
"btc": "bitcoin", "eth": "ethereum", "xrp": "ripple",
The code sends user-selected asset queries and optional API-authenticated requests to third-party services without any user-facing notice or consent flow. While the transmitted data is limited, silent outbound requests can expose usage patterns and API key use to external providers, which is a privacy and transparency issue in agent skills.
No suspicious patterns detected.