T09 · Insecure Skill Coding Practices
- Location
scripts/set-alert.sh:24- Finding
Arbitrary Python Code Execution Through Unsafe Alert Input Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a small crypto price alert skill, but its alert-setting script has a real code-injection risk and its service/alert documentation is inconsistent.
Review before installing. Use only with trusted alert inputs, and do not let an agent pass untrusted message text into set-alert.sh until the heredoc and JSON construction are fixed. Expect outbound requests to both Binance and CoinGecko, not just Binance. Do not place Telegram bot tokens in local config files unless they are protected and excluded from sharing or source control.
scripts/set-alert.sh:24Arbitrary Python Code Execution Through Unsafe Alert Input Interpolation
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
Monitor cryptocurrency prices and send alerts when thresholds are crossed. No API key required — uses Binance public API.
# Check a single token
bash scripts/check-price.sh btc
# Check multiple tokens
bash scripts/check-price.sh btc eth sol
# Set an alert
bash scripts/set-alert.sh btc 100000 "BTC above 100K"
# Check alerts
bash scripts/check-alerts.sh
Edit scripts/config.sh to set your Tel
The skill claims monitoring, Binance API access, and alerting, but the available documentation indicates none of these are actually implemented while also writing persistent state to the user's home directory. Undeclared persistence is dangerous because it expands the skill's footprint on the system and can surprise users with retained data or overwritten state.
The skill claims monitoring, Binance API access, and alerting, but the available documentation indicates none of these are actually implemented while also writing persistent state to the user's home directory. Undeclared persistence is dangerous because it expands the skill's footprint on the system and can surprise users with retained data or overwritten state.
The skill claims monitoring, Binance API access, and alerting, but the available documentation indicates none of these are actually implemented while also writing persistent state to the user's home directory. Undeclared persistence is dangerous because it expands the skill's footprint on the system and can surprise users with retained data or overwritten state.
The skill documentation advertises behavior that involves shell execution, network access, and local state writes, but it does not declare any explicit tool scope or permissions. This is dangerous because users and hosting platforms cannot accurately evaluate or constrain what the skill is allowed to do, increasing the chance of unintended file modification or network activity.
The file contains internally inconsistent documentation about whether Binance or CoinGecko is used. While not an exploit by itself, inconsistent dependency documentation creates supply-chain and privacy review blind spots because reviewers cannot tell which external service will receive requests.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Check all active alerts
STATE_FILE="$HOME/.crypto-alert-state.json"
COINGECKO_API="https://api.coingecko.com/api/v3"
if [ ! -f "$STATE_FILE" ]; then
echo "No alerts configured. Use set-alert.sh first."
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Check all active alerts
STATE_FILE="$HOME/.crypto-alert-state.json"
COINGECKO_API="https://api.coingecko.com/api/v3"
if [ ! -f "$STATE_FILE" ]; then
echo "No alerts configured. Use set-alert.sh first."
The manifest explicitly states that the skill uses the Binance public API, which is part of its described behavior and user-facing contract. This script actually defines and uses the CoinGecko API endpoint to retrieve prices, so the implemented behavior does not match the stated integration.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Uses Binance public API (no key required)
# Usage: bash check-price.sh BTC ETH SOL
BINANCE_API="https://api.binance.com/api/v3"
check_token() {
local symbol=$1
The skill instructs users to place a Telegram bot token and chat ID into a local config file without clearly warning that the token is sensitive secret material. This is dangerous because users may commit the file to source control, share it, or store it insecurely, enabling unauthorized message sending through their bot.
No suspicious patterns detected.