Back to skill

Security audit

trongrid-token-list

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only TRON token lookup skill, but it advertises price, volume, and market-cap rankings that its own instructions say TronGrid cannot provide.

Review this skill carefully before installing if you expect financial market rankings. It appears suitable for TronGrid-backed token metadata and on-chain activity summaries, but not for price, trading volume, market-cap comparisons, or investment decisions unless paired with a separate trusted market-data source.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest claims the skill can browse and rank tokens by price, volume, and market cap, but the implementation explicitly lacks those data sources and instead uses holder counts, supply, and transaction activity. This can mislead users or downstream agents into presenting fabricated or inferred financial rankings as if they were real market data, causing poor investment decisions and trust erosion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description uses broad activation language like discovering tokens, seeing rankings, and exploring categories, which overlaps with many generic crypto-information requests. In an agent environment, this can cause over-triggering and route user queries into a skill that provides incomplete or mismatched data, especially given the unsupported market-data claims.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Advertising an example for 'Top TRON tokens by market cap' contradicts the documented limitation that TronGrid does not provide market-cap data. This creates a strong risk that an agent will improvise or hallucinate unsupported market-cap results, which is dangerous in a financial context because users may treat the output as authoritative.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for browsing and ranking TRC-20 and TRC-10 tokens using price, volume, market cap, holder count, and category filters. This example file's documented workflow instead uses contract metadata, top holders, transaction counts, and a TRC-10 supply list, and explicitly states that price and market cap are unavailable via TronGrid, which conflicts with the manifest's claimed ranking/discovery dimensions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The inline note says 'Price and market cap data are not available via TronGrid,' while the manifest says the skill can browse and rank tokens with price, volume, and market cap and compare tokens by market cap. This is an active documentation-to-stated-intent contradiction rather than a mere omission.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.