Back to skill

Security audit

my-crypto-signal-skill

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate crypto signal tool that contacts market/news APIs and stores local signal records, with no hidden destructive or exfiltration behavior found.

Install only if you are comfortable providing NewsAPI and optional CryptoPanic/Binance keys, sending market/news queries to those services or a configured proxy, and keeping generated trading-signal history on disk. Treat its BUY/SELL/HOLD outputs as informational analysis, not automatic trading authority or financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises capabilities that include environment access, file read/write, network access, and shell execution, but it does not declare any explicit tool scope or permissions boundaries. This increases the chance the agent invokes powerful actions implicitly, making credential access, local file modification, or external requests possible without clear least-privilege constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match normal conversation about buying, selling, macro news, or crypto generally, which can cause the skill to activate unintentionally. In this skill, accidental activation is more concerning because activation may lead to shell, network, and file operations rather than a harmless text-only response.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill instructs the agent to write an llm_judgment field back into a signal JSON file and then perform later verification, creating persistent state across runs. Persisting LLM-generated content in local files can taint future processing, create an audit trail containing untrusted text, and enable unintended cross-session influence if later steps trust or reuse that field.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## Rules
- NEVER print raw JSON or file contents; summarize key fields only.
- NEVER invent probability forecasts or advice beyond what the script outputs.
- After `signal` completes: write `llm_judgment` into the signal JSON (1-2 sentences max), then run `verify`. Do NOT do anything else.
- When reading any `.json` file, extract only: direction, confidence, score, key factor votes, news_summary. Discard the rest.

## Setup

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
- When reading any `.json` file, extract only: direction, confidence, score, key factor votes, news_summary. Discard the rest.

## Setup
Credentials: `~/.openclaw/credentials/crypto-signal.json` (auto-created, chmod 600).  
**Required:** `News_apiKey` / `NEWSAPI_KEY` · **Optional:** `CP_apiKey`/`CRYPTOPANIC_KEY`, `Bian_apiKey`/`BINANCE_API_KEY`, `proxy`/`HTTPS_PROXY` (mainland China: `http://127.0.0.1:7890`)

## Usage

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly references external APIs, proxy support, and a local credential file, but it does not clearly warn the user that data may be transmitted to third parties or that local secrets will be accessed. This creates a transparency and consent problem, especially in an agent setting where users may not expect market symbols, prompts, or derived data to be sent externally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto_signal.py (reported line 37)May include surrounding context.

python
_SIGNALS = _ROOT / "signals"
_RECORDS = _ROOT / "records"

BINANCE_BASE     = "https://api.binance.com/api/v3"
CRYPTOPANIC_BASE = "https://cryptopanic.com/api/v1/posts/"
NEWSAPI_BASE     = "https://newsapi.org/v2/everything"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The request parameters force language: "en", which imposes a specific language policy on users regardless of their locale or preferences. The file does not offer an opt-in/override mechanism or explain why English-only filtering is required.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code writes generated trading signals to disk, and elsewhere in the file similar writes persist verification results and historical records. While the writes are part of the program's functionality, there is no explicit user-facing warning here that running the tool stores market, signal, and verification data locally across multiple directories.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.