Back to skill

Security audit

Cutie - Crypto KOL Platform

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Cutie API helper, but it needs review because it includes account-changing actions and tells agents to save trading-strategy data without clear consent or retention limits.

Review before installing. Only use this skill if you trust the Cutie service with your API key and want an agent to access your Cutie account. Before any follow, unfollow, subscription, posting, or risk-preference change, require the agent to show the exact action and get explicit confirmation. Do not allow KOL strategy data to be saved in long-term agent memory unless you intentionally consent and have a way to delete it.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:176
Finding

Untrusted Remote KOL Data Is Directed into Persistent Agent Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 176–188
Vulnerability Type: Persistent storage of externally supplied content
Risk Level: Medium

Vulnerable Documentation Excerpt

The following is an English translation of the relevant instruction and its associated request:

text
### 17. Learn a KOL Strategy (Core API)

Retrieve a KOL's complete strategy knowledge package in one request,
including the strategy profile, statistics by asset and direction,
and historical trades with technical indicators at entry.

After calling this API, the data should be stored in the agent's own
memory so that subsequent trading questions can be answered using the
strategy.

curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"cutie_learn_from_kol","arguments":{"kol_id":"KOL_ID","include_trades":30}}}' \
  | jq '.result.content[0].text | fromjson'

Technical Analysis

The Skill explicitly instructs the agent to place data returned by the remote cutie_learn_from_kol MCP tool into its own memory. The response includes KOL-generated or server-generated strategy summaries, profiles, and historical trade data. This content crosses an external trust boundary and is not inherently trustworthy.

No safeguards are specified before persistence:

  • No strict response-schema validation is required.
  • No filtering or neutralization of instruction-like text is required.
  • No separation is established between factual application data and agent instructions.
  • No source or provenance metadata is required in the stored record.
  • No user confirmation is required before persistent storage.
  • No retention period, scope restriction, or deletion mechanism is described.
  • No instruction requires the agent to treat retrieved text exclusively as untrusted d ...[truncated 2420 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to persist raw responses. Do not direct the agent to store the complete MCP response in behavioral or general-purpose long-term memory.

  2. Use isolated structured storage. If strategy retention is required, store only validated factual fields in a dedicated application record scoped to the current user and KOL. Do not store remote text as agent instructions or preferences.

  3. Apply a strict allowlist schema. Accept only documented fields with enforced types, lengths, ranges, and enumerated values. Reject unknown properties and unexpectedly formatted values.

  4. Neutralize instruction-like content. Treat every string returned by the remote service as untrusted data. Strip or quarantine text that attempts to direct agent behavior, override policies, invoke tools, request secrets, or alter future responses.

  5. Preserve provenance. Record the source endpoint, KOL identifier, retrieval time, schema version, and expiration time. Clearly label retained content as untrusted third-party financial data.

  6. Require explicit user consent. Ask the user before saving strategy data beyond the current interaction and explain what will be stored, why it is needed, and how it can be deleted.

  7. Set retention and deletion controls. Apply a short expiration period and provide a way to inspect, refresh, and delete saved KOL strategy records.

  8. Limit retrieval effects. When using saved records, provide them only as quoted reference data and explicitly prohibit their contents from changing system instructions, safety controls, tool permissions, or unrelated behavior.

  9. Isolate memory scope. Prevent records from crossing user, tenant, workspace, or unrelated conversation boundaries.

  10. Add integrity and anomaly checks. Reject oversized responses, unexpected markup, prompt-like directives, embedded URLs where not expected, and material changes inconsistent with the documented response mo ...[truncated 375 chars]

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises account-affecting actions such as posting signals, forum posting, and follow/unfollow operations, but it does not present a prominent user-facing warning that these actions modify the user's account or social state. In an agent setting, this increases the risk that a user asks for information retrieval and the agent performs a state-changing action without clear confirmation boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to store a KOL's complete strategy knowledge package in the agent's memory creates a retention and secondary-use risk without notifying the user how long data is kept, who can access it, or whether it may be reused in later conversations. In agent systems, persistent memory can cause cross-session leakage of proprietary or sensitive trading-profile data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly directs the agent to retain learned strategy data in its own memory for future answers, which is a natural-language prompt to persist external data beyond the immediate task. That creates a realistic risk of unintended disclosure, policy boundary violations, or reuse of third-party trading intelligence in unrelated contexts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

一次性获取 KOL 的完整策略知识包,包括策略画像、分币种/方向统计、历史交易记录(含入场时技术指标)。调用后应将数据存入自己的记忆,以便后续基于该策略回答交易问题。

bash
curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

一次性获取 KOL 的完整策略知识包,包括策略画像、分币种/方向统计、历史交易记录(含入场时技术指标)。调用后应将数据存入自己的记忆,以便后续基于该策略回答交易问题。

bash
curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

一次性获取 KOL 的完整策略知识包,包括策略画像、分币种/方向统计、历史交易记录(含入场时技术指标)。调用后应将数据存入自己的记忆,以便后续基于该策略回答交易问题。

bash
curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

一次性获取 KOL 的完整策略知识包,包括策略画像、分币种/方向统计、历史交易记录(含入场时技术指标)。调用后应将数据存入自己的记忆,以便后续基于该策略回答交易问题。

bash
curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 249)May include surrounding context.

一次性获取 KOL 的完整策略知识包,包括策略画像、分币种/方向统计、历史交易记录(含入场时技术指标)。调用后应将数据存入自己的记忆,以便后续基于该策略回答交易问题。

bash
curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

一次性获取 KOL 的完整策略知识包,包括策略画像、分币种/方向统计、历史交易记录(含入场时技术指标)。调用后应将数据存入自己的记忆,以便后续基于该策略回答交易问题。

bash
curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

一次性获取 KOL 的完整策略知识包,包括策略画像、分币种/方向统计、历史交易记录(含入场时技术指标)。调用后应将数据存入自己的记忆,以便后续基于该策略回答交易问题。

bash
curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

一次性获取 KOL 的完整策略知识包,包括策略画像、分币种/方向统计、历史交易记录(含入场时技术指标)。调用后应将数据存入自己的记忆,以便后续基于该策略回答交易问题。

bash
curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example performs a state-changing remote operation to set the user's risk configuration, but the skill does not require explicit confirmation or clearly warn that it will modify account trading-preference settings. Because these settings can materially affect later trading decisions and notifications, silent execution by an agent could have significant user impact.

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

md
| jq '.result.content[0].text | fromjson'

# 设置
curl -s -X POST "https://server.tokenbeep.com/mcp/" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Authorization: Bearer $CUTIE_API_KEY" \

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all operational instructions and labels in Chinese, including installation and release guidance, with no indication that the user can choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale limitation is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.