Back to skill

Security audit

btc数据

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only Bitcoin chain-data query helper, but it relies on a hardcoded internal plain-HTTP API that users should understand before using.

Install only if you intend to use the private API at 10.168.1.162:9000 and are comfortable sending BTC query parameters over unauthenticated HTTP. Avoid using it for sensitive or decision-critical financial workflows unless the endpoint is trusted, reachable from your environment, and protected by appropriate network controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
btc_api.py:28
Finding

Unvalidated Path and Query Parameters Permit Request Manipulation

Content
View full analysis
Remediation
View remediation
MAX_LIMIT: raise ValueError("limit is outside the permitted range") query["limit"] = params elif isinstance(params, str): parsed = datetime.datetime.strptime(params, "%Y-%m-%d").date() query["date"] = parsed.isoformat() resp = requests.get(url, params=query, timeout=10) ``` 3. Validate dates with strict date parsing rather than checking whether the value contains a hyphen. 4. Require limits to be positive and impose a reasonable maximum. 5. Reject path separators, traversal sequences, control characters, and URL delimiters in field names. 6. If dynamic path components remain necessary, encode each component using `urllib.parse.quote(value, safe="")`. 7. Validate dictionary parameter keys against a small explicit allowlist before creating the request. 8. Enforce authorization independently on the internal API. The server must not rely on this client-side allowlist as a security boundary. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
btc_api.py:5
Finding

Internal API Requests and Responses Are Transmitted Over Cleartext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents and appears to rely on network access to a remote HTTP API, but the manifest does not declare any tool scope or permissions for that capability. This creates a transparency and governance gap: an agent may invoke network-capable code without explicit least-privilege declaration, making review, sandboxing, and policy enforcement harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs a network request to an internal HTTP service without any transport security, timeout, or user-facing disclosure. In this skill context, users may not realize their query parameters and returned chain-analysis data are being sent to and fetched from a private network host, which creates confidentiality and integrity risks, especially because plain HTTP is susceptible to interception or tampering on the network path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown instructs use of a non-local HTTP endpoint (10.168.1.162:9000) without warning that data will be sent over the network or describing handling of transmitted inputs. Even on a private RFC1918 address, this can expose user queries or agent-supplied parameters to an internal service without informed consent, and plain HTTP provides no transport security.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The function docstring uses Chinese-only parameter descriptions, which imposes a specific language in the skill's natural-language interface without any opt-in or alternative. This can violate language/locale policy when a skill does not provide user choice or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.