T09 · Insecure Skill Coding Practices
- Location
scripts/analyze.mjs:8- Finding
Fabricated Token Analysis and Security Assessments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has no host-compromise behavior, but its crypto analysis and alert features are materially misleading for financial use.
Install only if you understand this as a demo or placeholder. Do not rely on its token lists, audit status, liquidity-lock claims, risk scores, alerts, or position-size suggestions for trading decisions until it uses verified live data sources and clearly labels simulated output.
scripts/analyze.mjs:8Fabricated Token Analysis and Security Assessments
scripts/alert.mjs:35Price Alerts Are Stored but Never Monitored or Triggered
Referenced artifact was not completely inspected
### 1. 新代币监控 (`monitor.mjs`)
Referenced artifact was not completely inspected
### 2. 代币分析 (`analyze.mjs`)
Referenced artifact was not completely inspected
### 3. 风险评估 (`risk.mjs`)
The skill description begins in Chinese and the rest of the README is written entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking region. This is a natural-language locale policy concern because it effectively imposes a language on users without opt-in.
The file’s user-facing instructions, command descriptions, outputs, and safety notes are all presented in Chinese, which effectively forces a specific language for use of the skill. The policy allows fixed language only when users are given a choice or when the locale constraint is explicitly documented and justified, neither of which appears here.
This code file contains natural-language strings such as the header comment and CLI output that are exclusively in Chinese. Under the policy, forcing a specific language without opt-in is a violation unless the locale restriction is clearly documented and justified, which is not present here.
The script presents itself as performing detailed token analysis, but it returns fabricated results derived only from the last character of the supplied address. In a security or trading context, this can mislead users into trusting fake risk scores, audit status, and participation advice, potentially causing financial harm through bad decisions.
This code file contains natural-language strings such as the title and help text only in Chinese, with no option to select another language. That creates a language/locale policy concern because users are implicitly forced into a specific language rather than being given a choice or clear documented justification.
This code includes its title, help text, status messages, and labels in Chinese, which effectively forces a specific language for users. The file does not provide any opt-in, fallback, or explanation that this is intentionally limited to a Chinese-speaking or region-specific audience.
The script presents itself as a multidimensional token risk assessment tool, but the actual logic returns canned assessments based only on the last character of the supplied address. In a trading or investment context, this is dangerous because users may rely on fabricated security conclusions such as 'contract audited' or 'liquidity locked,' leading to financial loss from false trust in unsafe tokens.
This code presents all user-facing descriptions, risk labels, prompts, and help text in Chinese only, including the banner, usage instructions, and warnings. The policy for natural-language violations applies to all file types, and there is no indication that the user can choose a language or that the locale restriction is explicitly justified.
The description includes only Chinese natural-language text ("代币狙击手,新代币监控和风险评估") alongside the product name, which signals a fixed language presentation. There is no indication that users can choose another language or that the package is intentionally restricted to a Chinese-speaking or region-specific audience.
No suspicious patterns detected.