T09 · Insecure Skill Coding Practices
- Location
SKILL.md:7- Finding
Unsupported Generation of Live-Looking Financial Market Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 7–19
Vulnerability Type: Unsupported financial data generation
Risk Level: MediumVulnerable Code
markdown ## What You Get (Free) Ask: "Korea flow?" or "kimchi premium?" or "Upbit BTC status?" The agent will return: - Kimchi premium direction (positive / negative / neutral) - Whether Korean volume is surging or flat - One-line market read Example output:Kimchi Premium: +1.8% (elevated) Upbit BTC volume: surging (+34% vs 24h avg) Read: Korean retail buying ahead of Western session
text Technical Analysis
The skill instructs the agent to return current-looking cryptocurrency exchange metrics and market analysis, but the project contains no implementation, API integration, data source, timestamp validation, or retrieval procedure for obtaining these values.
Consequently, an agent may infer, guess, or fabricate the kimchi premium, Upbit trading-volume changes, and associated market interpretation. The example resembles a live market report and does not explicitly state that its values are fictional placeholders. This creates a risk that generated values will be presented as verified facts.
This issue is classified as an insecure skill practice because the skill requests actionable financial information without defining the data integrity, provenance, availability, or freshness controls required to produce it reliably.
Attack Path
- A user invokes the skill with a prompt such as
Korea flow?,kimchi premium?, orUpbit BTC status?. - The agent attempts to satisfy the documented output requirements.
- No verified market-data interface is available in the skill package.
- The agent generates or estimates plausible-looking premium and volume figures.
- The output is presented without mandatory source, timestamp, or uncertainty information.
- A user or automated trading workflow treats the unsupported report as current market intelligence and makes a finan ...[truncated 785 chars]
- A user invokes the skill with a prompt such as
- Remediation
View remediation
Remediation Suggestions
- Integrate a documented and authenticated market-data provider for Upbit, Bithumb, and the relevant comparison exchanges.
- Define an explicit calculation method for the kimchi premium, including trading pairs, currency-conversion sources, fees, and time synchronization.
- Include the source exchange, retrieval timestamp, comparison window, and data freshness in every response.
- Refuse to provide current metrics when source data is unavailable, stale, incomplete, or inconsistent.
- Clearly label all sample values as fictional examples that must never be presented as live market data.
- Separate factual measurements from inferred market commentary and disclose uncertainty for interpretations.
- Validate volume comparisons against a precisely defined baseline, such as a rolling 24-hour average calculated from verified observations.
- Require user confirmation before passing any resulting signal into a swap or other transaction workflow.
- Add tests covering unavailable APIs, stale timestamps, malformed exchange responses, inconsistent currency conversions, and extreme or implausible values.
- State that the output is informational and not a guarantee or substitute for independent financial verification.
