Back to skill

Security audit

Crypto Market Data Skill (No Key Required)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed market-data client whose network access and token caching fit its purpose, with some credential-handling hardening users should understand before installing.

Install only if you are comfortable with the skill contacting api.igent.net for market data and caching a temporary service token locally. Avoid setting API_BASE_URL unless you trust the endpoint and use HTTPS; administrators may want to sandbox network egress and improve token-file permissions before broad deployment.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/api_client.js:52
Finding

Authentication Token Stored Without Explicitly Restrictive File Permissions

Content
View full analysis
= expiresAt.getTime()) return null; return data.token || null; } catch (e) { console.error(`Warning: Failed to load token file: ${e.message}`); return null; } } async function _fetchNewToken() { const reqUrl = `${BASE_URL}/token`; const { status, body } = await _httpRequest(reqUrl); if (status === 200) { const data = JSON.parse(body); fs.writeFileSync(TOKEN_FILE, JSON.stringify(data)); return data.token; } throw new Error(`Failed to fetch token. Status: ${status}`); } ``` ### Technical Analysis The client persists the API session token in plaintext at `scripts/.token`. The call to `fs.writeFileSync` does not set an explicit restrictive file mode, so the resulting permissions depend on the host process's umask and the state of any existing file. On a permissively configured multi-user system, another local account or process may be able to read the cached token. Storing runtime credentials inside the Skill source directory also increases the possibility that the file will be copied, archived, or included in a package unintentionally. The network token is required for the declared market-data functionality, and the documentation discloses the cache. The security issue is therefore not the retrieval itself, but the insufficiently hardened storage mechanism. ### Attack Path 1. ...[truncated 1171 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/api_client.js:8
Finding

Arbitrary API Base URL Allows Authentication Tokens and Queries to Be Sent Over Plaintext HTTP

Content
View full analysis
{ const parsed = new URL(reqUrl); const mod = parsed.protocol === 'https:' ? https : http; const options = { hostname: parsed.hostname, port: parsed.port, path: parsed.pathname + parsed.search, method: 'GET', headers: { 'User-Agent': USER_AGENT, ...headers }, }; const req = mod.request(options, (res) => { let body = ''; res.on('data', (chunk) => (body += chunk)); res.on('end', () => resolve({ status: res.statusCode, body })); }); req.on('error', reject); req.end(); }); } async function get(endpoint, params) { let token; try { token = await getToken(); } catch (e) { return { error: e.message }; } const parsed = new URL(`${BASE_URL}${endpoint}`); if (params) { for (const [key, value] of Object.entries(params)) { parsed.searchParams.set(key, value); } } const headers = { accept: 'application/json', 'X-API-Token': token, }; try { const { status, body } = await _httpRequest(parsed.toString(), headers); ``` ### Technical Analysis Although the documented default endpoint is HTTPS, `API_BASE_URL` can replace it with any origin. `_httpRequest()` explicitly selects Node.js's plaintext `http` module for non-HTTPS URLs and does not reject insecure schemes. All authenticated API operations use the same configurable base URL. Consequently, the `X-API-Token` header and user-supplied market queries can be sent to an arbitrary host over an unencrypted connection. The ...[truncated 1963 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill advertises broad crypto, stock, company-profile, and analytics coverage with zero external dependencies, while the available evidence indicates narrower functionality and reliance on an internal API client. Overstated claims reduce transparency and can conceal what code is actually doing, which is risky in environments where skills are auto-installed or granted access based on metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill advertises broad crypto, stock, company-profile, and analytics coverage with zero external dependencies, while the available evidence indicates narrower functionality and reliance on an internal API client. Overstated claims reduce transparency and can conceal what code is actually doing, which is risky in environments where skills are auto-installed or granted access based on metadata.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill documents code-like capabilities and authenticated network behavior but does not declare any explicit tool scope or permissions boundary. In an agent setting, missing scope metadata makes it harder for users and orchestrators to constrain environment or network access, increasing the chance of unintended execution with broader privileges than expected.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The skill transmits data to an external endpoint to obtain session tokens and likely to perform subsequent API requests. External transmission is expected for a market-data integration skill, but it remains security-sensitive because it introduces third-party trust, metadata leakage, and a path for credential exchange that users may not fully expect from the top-level description.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
### Authentication
Authentication is handled **automatically** by the internal `api_client.js`. Here is how it works simply:

- **Endpoint**: `GET https://api.igent.net/api/token`
- **Mechanism**:
    1.  **Automatic Retrieval**: The first time you use a tool, it asks the server for a temporary session token.
    2.  **Local Storage**: This token is stored in a hidden `.token` file locally so it can be reused for subsequent requests.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that an authentication token is stored in a hidden local .token file but does not warn about on-disk credential persistence, file permissions, or multi-user exposure. Persisted tokens can be stolen by other local processes, accidentally committed, or reused outside the intended session if storage is not carefully controlled.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/api_client.js (reported line 8)May include surrounding context.

js
const path = require('path');
const url = require('url');

const BASE_URL = process.env.API_BASE_URL || 'https://api.igent.net/api';
const TOKEN_FILE = path.join(__dirname, '.token');
const USER_AGENT = 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36';

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a market-data integration that requires no API key for free-tier use, but this client explicitly requests a token from /token and uses it for all API calls. Persisting and injecting a token is a materially different access model than the description suggests, and is not obvious from the manifest language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill persists an authentication token to a local file without any indication of access restrictions, encryption, or user disclosure. On multi-user systems or permissive file permission environments, other local users or processes could read the token and reuse it to access the backing API until expiry.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The stated purpose is real-time cryptocurrency and stock market data integration, which implies network retrieval, but the implementation also writes a .token file to disk. Local credential/token persistence is additional behavior not conveyed by the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.