T09 · Insecure Skill Coding Practices
- Location
scripts/crypto_analyzer.py:20- Finding
Hard-Coded SkillPay Billing API Credential
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This crypto analysis skill has disclosed paid features, but its main documented workflow is inconsistent with the code and can perform automatic billing using an embedded SkillPay credential.
Review this skill carefully before installing. Do not run the paid analyzer or setup scripts unless you intentionally want SkillPay billing, understand that calls can automatically deduct 0.05 USDT, and trust the embedded billing integration. The publisher should remove and rotate the hard-coded API key, fix the advertised free path, add explicit per-charge confirmation, and pin the ClawHub CLI version used by setup and publish commands.
scripts/crypto_analyzer.py:20Hard-Coded SkillPay Billing API Credential
scripts/crypto_analyzer.py:410Advertised Free Interface Transmits a User Identifier and Performs Automatic Billing
scripts/auto_setup.sh:51Unpinned Third-Party Package Execution Through npx
This code actively charges a user's account via an external billing API, which exceeds the stated purpose of a crypto analysis assistant. In a skill context, hidden or weakly disclosed charging logic can lead to unauthorized financial loss, especially if invoked automatically by another agent or UI without clear user approval.
The charge function performs automatic billing against a remote service using a privileged API key with no explicit user confirmation, authorization check, or transactional safeguard at the point of charge. In a paid skill context this is especially dangerous because any caller or downstream integration that invokes the command may trigger real monetary charges without informed approval.
The document instructs users to execute a local setup script and then republish the skill, but it does not clearly warn that these commands modify configuration and push a new version publicly. In a security-sensitive workflow, this can cause users to make irreversible or externally visible changes without reviewing what the script does.
The guide tells users to run npx clawhub publish without pinning a specific package version, which allows whatever version is currently resolved from the registry to execute on the user's machine. If the upstream package is compromised or a breaking/malicious update is published, the user could run unintended code during publish.
The skill description is written entirely in Chinese, including installation, usage, pricing, and disclaimer sections, with no indication that other languages are supported or that Chinese is required for a region-specific purpose. This is a natural-language locale constraint that can violate policy when no user opt-in or documented justification is provided.
The README instructs users to run npx clawhub install crypto-scope without pinning an explicit package version. This causes users to fetch whatever version is current at execution time, creating a supply-chain risk if the package is later compromised, replaced, or updated with malicious code. Because this is an install command in user-facing documentation, the context increases the chance of direct execution.
The document instructs users to run npx clawhub publish without pinning an exact package version. This can cause execution of an unexpected or newly published package version at publish time, creating a supply-chain risk if the package is compromised or behavior changes maliciously.
The document describes paid invocation behavior and pricing, but the clear warning that every call triggers automatic charges appears only near the end. Users may follow setup and testing steps before fully appreciating that each invocation deducts funds, which creates a consent and billing transparency risk.
The one-line setup command again uses npx clawhub publish without a pinned version, exposing users to the same package substitution or unexpected-update risk. Because this is presented as a copy-paste convenience command, it increases the chance users will execute it without review.
The trigger list includes broad terms such as 'crypto', 'bitcoin', and generic price-analysis phrases, which can cause the skill to activate in ordinary conversations beyond explicit user intent. Over-broad activation increases the chance of unwanted tool use, external API calls, and exposure to monetized or side-effecting flows in contexts where the user did not clearly request this skill.
The skill metadata and documentation are presented in Chinese, including the primary description and usage sections, but there is no indication that users may choose another language. This can violate language/locale policy when a skill implicitly forces one language without opt-in or explicit justification.
The skill instructs users to run npx clawhub install crypto-scope without pinning an exact package/version, which creates a supply-chain risk: the command can resolve to whatever package/version is current at execution time. If the upstream package, dependency tree, or registry entry is compromised, users may execute attacker-controlled code during install.
The script presents itself as an almost automatic setup helper while it also edits source code and republishes the skill package, which can mislead users about the scope of actions being taken. In security terms, this reduces informed consent and increases the chance an operator will trigger code modification and external publication without adequate review.
The script modifies crypto_analyzer.py in place using sed -i.bak based on user input, without previewing the diff or asking for confirmation. Even if the input is intended to be a Skill ID, silent source rewriting can corrupt code, introduce unintended changes, or be abused in a supply-chain workflow where maintainers run the helper without closely inspecting results.
The script invokes npx clawhub publish without pinning a specific package version, which allows whatever version resolves at execution time to run with the user's privileges. If the upstream package is compromised, replaced, or unexpectedly changed, the script could execute untrusted code during a release workflow and potentially exfiltrate credentials or tamper with the published package.
The script performs an external publish operation immediately, without an explicit warning or confirmation gate before releasing to ClawHub. This is dangerous because it can cause unintended public deployment of modified code, potentially shipping unsafe or tampered content and leaking metadata through the changelog or release process.
The script hardcodes a live-looking API key directly in source and echoes part of it to the terminal, which creates a clear secret-exposure risk through version control, logs, screenshots, backups, and local file disclosure. In this context, the script is specifically for payment-platform configuration, so compromise of the credential could let an attacker access or modify SkillPay-related resources or abuse the account.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
echo "📚 相关文件:"
echo " - 配置文件: $SCRIPT_PATH"
echo " - 备份文件: ${SCRIPT_PATH}.backup"
echo " - 使用文档: ~/.openclaw/workspace/skills/crypto-scope/SKILL.md"
echo ""
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 配置
# ═══════════════════════════════════════════════════
COINGECKO_API = "https://api.coingecko.com/api/v3"
SKILLPAY_API = "https://skillpay.me/api/v1/billing"
SKILLPAY_API_KEY = os.environ.get("SKILLPAY_API_KEY", "sk_0de94ea93e9aca73aafc2b6457b8de378389a21661f9c6ad4e6b7929e390e971")
CRYPTO_SKILL_ID = "0c9fb051-d210-46c4-b4d8-67f6cb6ba624" # SkillPay Skill ID(2026-03-07 19:51配置)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 配置
# ═══════════════════════════════════════════════════
COINGECKO_API = "https://api.coingecko.com/api/v3"
SKILLPAY_API = "https://skillpay.me/api/v1/billing"
SKILLPAY_API_KEY = os.environ.get("SKILLPAY_API_KEY", "sk_0de94ea93e9aca73aafc2b6457b8de378389a21661f9c6ad4e6b7929e390e971")
CRYPTO_SKILL_ID = "0c9fb051-d210-46c4-b4d8-67f6cb6ba624" # SkillPay Skill ID(2026-03-07 19:51配置)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 配置
# ═══════════════════════════════════════════════════
COINGECKO_API = "https://api.coingecko.com/api/v3"
SKILLPAY_API = "https://skillpay.me/api/v1/billing"
SKILLPAY_API_KEY = os.environ.get("SKILLPAY_API_KEY", "sk_0de94ea93e9aca73aafc2b6457b8de378389a21661f9c6ad4e6b7929e390e971")
CRYPTO_SKILL_ID = "0c9fb051-d210-46c4-b4d8-67f6cb6ba624" # SkillPay Skill ID(2026-03-07 19:51配置)
The script hard-codes a billing API endpoint, a billing skill identifier, and a default SkillPay API key inside a crypto analysis tool. Embedding billing capability and fallback credentials in an analysis skill creates unauthorized monetization risk and exposes a secret that could be abused to query balances or charge accounts through the external billing service.
The code accesses a billing API key and supports external billing calls without clear disclosure to the user that a financial backend is involved. Combined with the embedded default secret, this increases both privacy and security risk because the skill can silently interact with billing infrastructure using privileged credentials.
This request posts user_id and skill_id to an external billing endpoint, creating an outbound data flow with financial account context. In a nominally analytical skill, undisclosed external transmission tied to billing is risky because it expands exposure of user-linked data and can be triggered as a prerequisite for normal use.
def check_balance(self, user_id: str) -> Dict[str, Any]:
"""检查用户余额"""
try:
resp = requests.post(
f"{SKILLPAY_API}/balance",
headers={
"X-API-Key": self.api_key,
This outbound request performs an actual charge operation against an external billing service using privileged API credentials. Because the skill can trigger monetary deductions as part of normal commands, compromise, misuse, or insufficient disclosure could directly cause unauthorized financial loss.
def charge_user(self, user_id: str, amount: float = 0.05) -> Dict[str, Any]:
"""扣费"""
try:
resp = requests.post(
f"{SKILLPAY_API}/charge",
headers={
"X-API-Key": self.api_key,
No suspicious patterns detected.