Back to skill

Security audit

Token Shark

Security checks for vulnerabilities and agentic risk

Overview

This skill has no host-compromise behavior, but its crypto analysis and alert features are materially misleading for financial use.

Install only if you understand this as a demo or placeholder. Do not rely on its token lists, audit status, liquidity-lock claims, risk scores, alerts, or position-size suggestions for trading decisions until it uses verified live data sources and clearly labels simulated output.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/analyze.mjs:8
Finding

Fabricated Token Analysis and Security Assessments

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/alert.mjs:35
Finding

Price Alerts Are Stored but Never Monitored or Triggered

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
### 1. 新代币监控 (`monitor.mjs`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
### 2. 代币分析 (`analyze.mjs`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
### 3. 风险评估 (`risk.mjs`)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description begins in Chinese and the rest of the README is written entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking region. This is a natural-language locale policy concern because it effectively imposes a language on users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s user-facing instructions, command descriptions, outputs, and safety notes are all presented in Chinese, which effectively forces a specific language for use of the skill. The policy allows fixed language only when users are given a choice or when the locale constraint is explicitly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings such as the header comment and CLI output that are exclusively in Chinese. Under the policy, forcing a specific language without opt-in is a violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script presents itself as performing detailed token analysis, but it returns fabricated results derived only from the last character of the supplied address. In a security or trading context, this can mislead users into trusting fake risk scores, audit status, and participation advice, potentially causing financial harm through bad decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language strings such as the title and help text only in Chinese, with no option to select another language. That creates a language/locale policy concern because users are implicitly forced into a specific language rather than being given a choice or clear documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code includes its title, help text, status messages, and labels in Chinese, which effectively forces a specific language for users. The file does not provide any opt-in, fallback, or explanation that this is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script presents itself as a multidimensional token risk assessment tool, but the actual logic returns canned assessments based only on the last character of the supplied address. In a trading or investment context, this is dangerous because users may rely on fabricated security conclusions such as 'contract audited' or 'liquidity locked,' leading to financial loss from false trust in unsafe tokens.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code presents all user-facing descriptions, risk labels, prompts, and help text in Chinese only, including the banner, usage instructions, and warnings. The policy for natural-language violations applies to all file types, and there is no indication that the user can choose a language or that the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description includes only Chinese natural-language text ("代币狙击手,新代币监控和风险评估") alongside the product name, which signals a fixed language presentation. There is no indication that users can choose another language or that the package is intentionally restricted to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.