Back to skill

Security audit

Crypto Alert

Security checks for vulnerabilities and agentic risk

Overview

This looks like a small crypto price alert skill, but its alert-setting script has a real code-injection risk and its service/alert documentation is inconsistent.

Review before installing. Use only with trusted alert inputs, and do not let an agent pass untrusted message text into set-alert.sh until the heredoc and JSON construction are fixed. Expect outbound requests to both Binance and CoinGecko, not just Binance. Do not place Telegram bot tokens in local config files unless they are protected and excluded from sharing or source control.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/set-alert.sh:24
Finding

Arbitrary Python Code Execution Through Unsafe Alert Input Interpolation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

YARA rule 'ransomware_behavior': Ransomware-like patterns (mass encryption, ransom notes) [malware]

Critical
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.


name: crypto-alert version: 1.0.0 description: Monitor cryptocurrency prices and send alerts when thresholds are crossed. No API key required — uses Binance public API. Supports BTC, ETH, SOL, and 10+ tokens.

Crypto Alert Monitor

Monitor cryptocurrency prices and send alerts when thresholds are crossed. No API key required — uses Binance public API.

Usage

bash
# Check a single token
bash scripts/check-price.sh btc

# Check multiple tokens
bash scripts/check-price.sh btc eth sol

# Set an alert
bash scripts/set-alert.sh btc 100000 "BTC above 100K"

# Check alerts
bash scripts/check-alerts.sh

Configuration

Edit scripts/config.sh to set your Tel

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims monitoring, Binance API access, and alerting, but the available documentation indicates none of these are actually implemented while also writing persistent state to the user's home directory. Undeclared persistence is dangerous because it expands the skill's footprint on the system and can surprise users with retained data or overwritten state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims monitoring, Binance API access, and alerting, but the available documentation indicates none of these are actually implemented while also writing persistent state to the user's home directory. Undeclared persistence is dangerous because it expands the skill's footprint on the system and can surprise users with retained data or overwritten state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims monitoring, Binance API access, and alerting, but the available documentation indicates none of these are actually implemented while also writing persistent state to the user's home directory. Undeclared persistence is dangerous because it expands the skill's footprint on the system and can surprise users with retained data or overwritten state.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documentation advertises behavior that involves shell execution, network access, and local state writes, but it does not declare any explicit tool scope or permissions. This is dangerous because users and hosting platforms cannot accurately evaluate or constrain what the skill is allowed to do, increasing the chance of unintended file modification or network activity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file contains internally inconsistent documentation about whether Binance or CoinGecko is used. While not an exploit by itself, inconsistent dependency documentation creates supply-chain and privacy review blind spots because reviewers cannot tell which external service will receive requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/check-alerts.sh (reported line 5)May include surrounding context.

sh
# Check all active alerts

STATE_FILE="$HOME/.crypto-alert-state.json"
COINGECKO_API="https://api.coingecko.com/api/v3"

if [ ! -f "$STATE_FILE" ]; then
    echo "No alerts configured. Use set-alert.sh first."

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/check-alerts.sh (reported line 16)May include surrounding context.

sh
# Check all active alerts

STATE_FILE="$HOME/.crypto-alert-state.json"
COINGECKO_API="https://api.coingecko.com/api/v3"

if [ ! -f "$STATE_FILE" ]; then
    echo "No alerts configured. Use set-alert.sh first."

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest explicitly states that the skill uses the Binance public API, which is part of its described behavior and user-facing contract. This script actually defines and uses the CoinGecko API endpoint to retrieve prices, so the implemented behavior does not match the stated integration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/check-price.sh (reported line 6)May include surrounding context.

sh
# Uses Binance public API (no key required)
# Usage: bash check-price.sh BTC ETH SOL

BINANCE_API="https://api.binance.com/api/v3"

check_token() {
    local symbol=$1

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs users to place a Telegram bot token and chat ID into a local config file without clearly warning that the token is sensitive secret material. This is dangerous because users may commit the file to source control, share it, or store it insecurely, enabling unauthorized message sending through their bot.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.