Back to skill

Security audit

BTC Price Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: fetches Bitcoin pricing and sends a Telegram notification, with no hidden persistence or unrelated data access found.

Install only if you are comfortable giving the skill a Telegram bot token and chat ID and having BTC price messages sent through Telegram. Consider updating the requests dependency before use, and treat the README's 'No API keys needed' claim as referring to CoinGecko rather than Telegram.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (10)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/main.py (reported line 16)May include surrounding context.

python
#!/usr/bin/env python3
"""
BTC Price Monitor for OpenClaw
Fetches Bitcoin price from CoinGecko and sends to Telegram
"""

import os
import requests
import sys
from datetime import datetime

# ==================================================
# CONFIGURATION - REPLACE WITH YOUR VALUES
# ==================================================

TELEGRAM_BOT_TOKEN = os.environ.get("TELEGRAM_BOT_TOKEN", "YOUR_BOT_TOKEN_HERE")
TELEGRAM_CHAT_ID = os.environ.get("TELEGRAM_CHAT_ID", "YOUR_CHAT_ID_HERE")
PRICE_THRESHOLD = float(os.environ.get("PRICE_THRESHOLD_USD", "50000"))

# ==================================================


def get_btc_price():
    """Fetch current BTC price from CoinGecko (free, no API key)"""
    try:
        url = "https://api.coingecko.com/api/v3/simple/price?ids=bitcoin&vs_currencies=usd"
        response = requests.get(url, timeout=10)
        data = response.json()
        return data["bitcoin"]["usd"]
    except Exce

Tainted flow: 'url' from os.environ.get (line 40, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/main.py (reported line 27)May include surrounding context.

python
"""Fetch current BTC price from CoinGecko (free, no API key)"""
    try:
        url = "https://api.coingecko.com/api/v3/simple/price?ids=bitcoin&vs_currencies=usd"
        response = requests.get(url, timeout=10)
        data = response.json()
        return data["bitcoin"]["usd"]
    except Exception as e:

Tainted flow: 'url' from os.environ.get (line 40, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/main.py (reported line 48)May include surrounding context.

python
}

    try:
        response = requests.post(url, json=payload, timeout=10)
        return response.status_code == 200
    except Exception as e:
        print(f"Failed to send Telegram message: {e}")

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · scripts/main.py (reported line 35)May include surrounding context.

python
def send_telegram_message(message):
    """Send message to Telegram"""
    if TELEGRAM_BOT_TOKEN == "YOUR_BOT_TOKEN_HERE" or TELEGRAM_CHAT_ID == "YOUR_CHAT_ID_HERE":
        print("ERROR: Please set your TELEGRAM_BOT_TOKEN and TELEGRAM_CHAT_ID")
        return False

Known Vulnerable Dependency: requests==2.31.0 — 6 advisory(ies): CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi); CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func) +3 more

Medium
Category
Supply Chain
Confidence
97% confidence
Finding

The file pins requests to version 2.31.0, which is identified in the finding as having multiple published advisories, including credential leakage via malicious URLs and request verification/session-related issues. Keeping a dependency locked to a known vulnerable version exposes any code using it to those upstream flaws, especially if the skill performs HTTP requests to untrusted or user-influenced destinations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/main.py (reported line 26)May include surrounding context.

python
def get_btc_price():
    """Fetch current BTC price from CoinGecko (free, no API key)"""
    try:
        url = "https://api.coingecko.com/api/v3/simple/price?ids=bitcoin&vs_currencies=usd"
        response = requests.get(url, timeout=10)
        data = response.json()
        return data["bitcoin"]["usd"]

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/main.py (reported line 40)May include surrounding context.

python
print("ERROR: Please set your TELEGRAM_BOT_TOKEN and TELEGRAM_CHAT_ID")
        return False

    url = f"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/sendMessage"
    payload = {
        "chat_id": TELEGRAM_CHAT_ID,
        "text": message,

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/main.py (reported line 48)May include surrounding context.

python
}

    try:
        response = requests.post(url, json=payload, timeout=10)
        return response.status_code == 200
    except Exception as e:
        print(f"Failed to send Telegram message: {e}")

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The markdown states that the skill sends Telegram notifications, which implies transmission of data to a third-party service. The description does not include any warning about privacy, what data is sent, or that external network communication occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly sends fetched Bitcoin price data to Telegram using configured bot credentials, but the description and usage sections do not clearly warn the user that an external message will be sent. This is a transparency and consent issue: users may invoke what appears to be a local price check without realizing it triggers outbound communication through their Telegram account configuration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.