Back to skill

Security audit

Crypto Market Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public BTC and ETH market data from Binance and formats analysis reports, with disclosed but user-controlled network and scheduling behavior.

Installers should understand that this skill contacts Binance's public API and can be used for scheduled daily reports. Only enable cron execution and messaging delivery after choosing the destination and schedule, and expect Chinese-language report text unless the skill is modified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill instructs use of a network-capable script (python3 scripts/fetch_crypto_data.py) and external Binance API access, but the manifest does not declare any permissions or allowed-tools scope. This creates an authorization and review gap: the skill’s runtime capabilities are broader than its declared policy surface, making it harder for operators to assess and constrain outbound access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The human-readable report example is written in Chinese and presents the output format as the default way to format user-facing results. There is no indication that language is configurable or that the user can choose English versus Chinese, which creates a locale/language policy concern.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The skill is designed for scheduled execution via cron, which introduces persistence beyond a single user-initiated session. Persistent or automated execution increases risk because network access and report delivery can continue without fresh user consent, and misconfiguration could lead to repeated external calls or unsolicited messaging.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

To schedule via OpenClaw cron:

bash
# Create a cron job to run daily at 10:00 AM UTC+8
# This corresponds to 02:00 UTC

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code hardcodes Chinese natural-language explanations and mixed Chinese sentiment labels in user-facing output, rather than offering a language choice. That creates a locale-policy issue because the skill imposes a specific language on users without explicit opt-in or documented regional scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring says the script 'Supports multiple symbols and intervals,' suggesting configurable symbol/interval handling. In actual execution, main() is hard-coded to only BTCUSDT and ETHUSDT and only fetches 4h and 1d intervals, so the documentation overstates what the script as used here actually does.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes RSI, SMAs, support/resistance, and bullish/bearish sentiment analysis, but this file also calculates EMAs, MACD, Bollinger Bands, volume analysis, and 7-day price change. These are still market-analysis features, so the mismatch is limited in risk, but the implemented behavior is broader than the stated description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.