Back to skill

Security audit

Crypto Sniper Oracle

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated crypto-reporting purpose, but it includes unsafe Telegram token handling guidance and automated trading-style recommendations that users should review carefully.

Install only if you are comfortable with a crypto monitoring tool that writes reports/logs under /workspace, can be scheduled with cron, and can send generated reports to Telegram when credentials are present. Do not store real Telegram bot tokens in ~/.bashrc or ~/.profile, do not paste tokens into browser URLs or shared terminals, and treat the trading suggestions as unverified informational signals rather than financial advice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
CONFIGURATION.md:71
Finding

Plaintext Telegram Bot Credential Persistence and Disclosure

Content
View full analysis

Vulnerability Details

File Location: CONFIGURATION.md:71-75, CONFIGURATION.md:293-300, and README.md:358-361
Vulnerability Type: Plaintext secret storage and unsafe credential disclosure
Risk Level: Medium

The configuration documentation instructs users to persist a Telegram bot token in a plaintext shell initialization file and to print the token during troubleshooting.

bash
**Permanent (add to ~/.bashrc or ~/.profile):**
```bash
echo 'export TELEGRAM_BOT_TOKEN="1234567890:ABCdefGHIjklMNOpqrsTUVwxyz"' >> ~/.bashrc
echo 'export TELEGRAM_CHAT_ID="123456789"' >> ~/.bashrc
source ~/.bashrc
text

It also recommends displaying the token and expanding it into a command-line URL:

```bash
**Checklist:**
1. Verify bot token: `echo $TELEGRAM_BOT_TOKEN`
2. Verify chat ID: `echo $TELEGRAM_CHAT_ID`
3. Test connectivity:
   ```bash
   curl https://api.telegram.org/bot$TELEGRAM_BOT_TOKEN/getMe
text

The README repeats the unsafe terminal disclosure:

```bash
**Check:**
```bash
echo $TELEGRAM_BOT_TOKEN
echo $TELEGRAM_CHAT_ID
text

### Technical Analysis

Telegram bot tokens are bearer credentials. A party possessing a valid token can authenticate to Telegram's Bot API without an additional secret.

Writing the token to `~/.bashrc` or `~/.profile` stores it unencrypted for an indefinite period. The token may consequently be exposed to other processes or users able to read the profile, workstation backups, diagnostic collections, accidental profile sharing, or source-control mistakes.

Running `echo $TELEGRAM_BOT_TOKEN` exposes the complete token in terminal output, where it may be captured by screen sharing, recordings, scrollback, CI logs, support transcripts, or terminal logging. Expanding the token into the `curl` URL can additionally make it temporarily visible in process arguments to local process-monitoring tools. Although the shell commonly records the unexpanded variable expression in history, tooling around command exe
...[truncated 1735 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove instructions that persist bot tokens directly in ~/.bashrc or ~/.profile.
  2. Store credentials in a dedicated secret manager when available. As a local fallback, use a separate file with restrictive permissions:
    bash
    install -m 600 /dev/null ~/.crypto-oracle.env
    printf '%s\n' \
      'TELEGRAM_BOT_TOKEN="replace_with_token"' \
      'TELEGRAM_CHAT_ID="replace_with_chat_id"' \
      > ~/.crypto-oracle.env
    
  3. Ensure any scheduled execution loads secrets from the protected file without placing literal credentials in crontab entries.
  4. Replace token-printing checks with redacted validation, such as reporting only whether the variable is set:
    bash
    if [ -n "${TELEGRAM_BOT_TOKEN:-}" ]; then
        echo "TELEGRAM_BOT_TOKEN is configured"
    else
        echo "TELEGRAM_BOT_TOKEN is not configured"
    fi
    
  5. Avoid placing the token in command-line arguments. Use the application’s test mode or a protected configuration mechanism instead of the documented curl command.
  6. Warn users not to include tokens in screenshots, support logs, shell profiles, source control, or shared diagnostic output.
  7. Document incident response: revoke and regenerate the token through BotFather immediately if disclosure is suspected, then update all authorized secret stores.
  8. Apply least privilege to the Telegram bot by granting it only the group or channel permissions required for report delivery.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (37)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · CONFIGURATION.md (reported line 73)May include surrounding context.

id": 123456789 }

text

**Method 2: Via @userinfobot**
1. Search `@userinfobot` in Telegram
2. Start chat
3. It will show your Chat ID

---

### **Step 3: Set Environment Variables**

**Temporary (current session):**
```bash
export TELEGRAM_BOT_TOKEN="1234567890:ABCdefGHIjklMNOpqrsTUVwxyz-1234567"
export TELEGRAM_CHAT_ID="123456789"

Permanent (add to ~/.bashrc or ~/.profile):

bash
echo 'export TELEGRAM_BOT_TOKEN="1234567890:ABCdefGHIjklMNOpqrsTUVwxyz"' >> ~/.bashrc
echo 'export TELEGRAM_CHAT_ID="123456789"' >> ~/.bashrc
source ~/.bashrc

Step 4: Test Telegram

bash
python3 /workspace/skills/crypto-sniper-oracle/reporter.py --mode test

Expected output:

text
[INFO] Fetching data for 0 symbols...
[OK] Report saved to /workspace/reports/test_2026-02-27.md
[OK] Telegram message sent

Expected in Telegram:

text
✅ Crypto Sniper Oracle - Telegram Test

If you see this, Telegram is configured correctly!

Cron Jobs Setup (Optional)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch is more serious because the skill text under-describes local file writes, subprocess/script execution, and the fact that this component functions as a reporting wrapper rather than only an oracle. Hidden or insufficiently declared side effects increase the chance of unsafe deployment, especially where file-system integrity and execution boundaries matter.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch is more serious because the skill text under-describes local file writes, subprocess/script execution, and the fact that this component functions as a reporting wrapper rather than only an oracle. Hidden or insufficiently declared side effects increase the chance of unsafe deployment, especially where file-system integrity and execution boundaries matter.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The anomaly alert template goes beyond analysis into actionable advice such as suggesting a LONG entry, without guardrails, suitability checks, or explicit opt-in. In an automated alerting context this is riskier because real-time notifications can prompt immediate financial action by users.

Content

No source excerpt is available for this finding.

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 437)May include surrounding context.

md
self.api_url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
    
    def send_message(self, text):
        """Send message to Telegram."""
        
        # Split if too long (Telegram 4096 char limit)
        if len(text) > 4000:

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · reporter.py (reported line 270)May include surrounding context.

python
self.api_url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
    
    def send_message(self, text):
        """Send message to Telegram."""
        
        # Split if too long (Telegram 4096 char limit)
        if len(text) > 4000:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CONFIGURATION.md (reported line 26)May include surrounding context.

md
## Telegram Setup (Optional)

### **Step 1: Create Telegram Bot**

1. **Open Telegram app**
2. **Search:** `@BotFather`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · CONFIGURATION.md (reported line 47)May include surrounding context.

  1. Send any message to your bot
  2. Visit (replace YOUR_TOKEN):
    text
    https://api.telegram.org/botYOUR_TOKEN/getUpdates
    
  3. Look for:
    json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · CONFIGURATION.md (reported line 299)May include surrounding context.

  1. Send any message to your bot
  2. Visit (replace YOUR_TOKEN):
    text
    https://api.telegram.org/botYOUR_TOKEN/getUpdates
    
  3. Look for:
    json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 223)May include surrounding context.

  1. Send any message to your bot
  2. Visit (replace YOUR_TOKEN):
    text
    https://api.telegram.org/botYOUR_TOKEN/getUpdates
    
  3. Look for:
    json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 438)May include surrounding context.

  1. Send any message to your bot
  2. Visit (replace YOUR_TOKEN):
    text
    https://api.telegram.org/botYOUR_TOKEN/getUpdates
    
  3. Look for:
    json

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

Appending secret-bearing export commands to ~/.bashrc or ~/.profile creates persistent credential exposure in user startup files. While not a malicious persistence mechanism, it leaves sensitive tokens resident in locations commonly backed up, synced, inspected, or accidentally disclosed, making compromise more likely over time.

Content

Scanner excerpt · CONFIGURATION.md (reported line 71)May include surrounding context.

export TELEGRAM_CHAT_ID="123456789"

text

**Permanent (add to ~/.bashrc or ~/.profile):**
```bash
echo 'export TELEGRAM_BOT_TOKEN="1234567890:ABCdefGHIjklMNOpqrsTUVwxyz"' >> ~/.bashrc
echo 'export TELEGRAM_CHAT_ID="123456789"' >> ~/.bashrc

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide tells users to persist a live Telegram bot token in ~/.bashrc or ~/.profile, which increases the chance the credential is exposed through shell history, backups, dotfile syncing, accidental sharing, or overly broad file permissions. This is not malware, but it is unsafe secret-handling guidance because the token enables unauthorized use of the bot and message access within that bot context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CONFIGURATION.md (reported line 107)May include surrounding context.

Editing Crontab

bash
crontab -e

If first time, select editor (nano recommended).

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 249)May include surrounding context.

Editing Crontab

bash
crontab -e

If first time, select editor (nano recommended).

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CONFIGURATION.md (reported line 149)May include surrounding context.

bash
# List all cron jobs
crontab -l

# Check cron logs
grep CRON /var/log/syslog

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CONFIGURATION.md (reported line 332)May include surrounding context.

bash
# List all cron jobs
crontab -l

# Check cron logs
grep CRON /var/log/syslog

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 268)May include surrounding context.

bash
# List all cron jobs
crontab -l

# Check cron logs
grep CRON /var/log/syslog

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · CONFIGURATION.md (reported line 276)May include surrounding context.

bash
mkdir -p /workspace/reports
chmod 755 /workspace/reports

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · CONFIGURATION.md (reported line 361)May include surrounding context.

bash
mkdir -p /workspace/reports
chmod 755 /workspace/reports

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 387)May include surrounding context.

bash
mkdir -p /workspace/reports
chmod 755 /workspace/reports

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README presents anomaly alerts, implications, and suggested trading actions such as considering LONG entry without any financial-risk disclaimer or statement that outputs are informational only. In a trading-oriented skill, this can mislead users into treating heuristic signals as actionable advice, increasing risk of financial harm.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions tell users to place their bot token directly into a Telegram API URL and then use shell commands to inspect related secrets, creating a natural path for credential leakage through browser history, clipboard history, shell history, screen sharing, and logs. Even if intended for setup, the documentation encourages unsafe operational handling of secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README shows credential-shaped Telegram token and chat ID examples in export commands without clearly labeling them as fake placeholders or warning users not to paste real secrets into shared terminals, logs, or screenshots. This increases the chance of accidental secret disclosure and normalizes unsafe secret-handling practices.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill describes capabilities requiring environment access, file reads/writes, network access, and likely shell/subprocess execution, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens containment and reviewability because the effective privilege set is broader than what a policy engine or reviewer can verify from the manifest alone.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.