Back to skill

Security audit

BTC Analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed BTC market-data analyzer, but it tells the agent to run an unaudited Python script from a mutable global install path.

Review this before installing. It may be useful for BTC technical analysis, but it produces trading signals and executes a Python script that was not included in the reviewed artifact. Install only if you trust the package source and can verify the referenced analyzer script and its permissions; do not treat its UP/DOWN/SKIP output as financial advice.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Warning
Location
SKILL.md:36
Finding

Execution of Unbundled Script from a Mutable Global Installation Path

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 36-37 and 81-86
Vulnerability Type: T07: Tool Hijacking and Spoofing
Risk Level: Medium

Vulnerable Code

text
Step 1 — Run the analyzer script via bash tool:
python3 ~/.npm-global/lib/node_modules/openclaw/skills/btc-analyzer/analyze.py
text
- Always run the script via bash tool — never fabricate or guess output values.
- Do not hardcode prices or decisions.
- If script fails, show the actual error message to the user.
- This skill uses Binance public API only — no API key or authentication required.
- Data is real-time; do not cache or reuse previous results.

Technical Analysis

The Skill requires the agent to execute analyze.py from a mutable global npm installation directory. That script is not included in the audited project, which contains only SKILL.md. The executable code and its asserted behavior therefore cannot be verified as part of this audit.

The fixed path does not establish the script's provenance or integrity. Any process or user capable of modifying that global installation can replace the expected analyzer with different Python code. The instruction to “always run” the script then provides a legitimate-looking execution path for the substituted implementation. Claims that the script only uses Binance's public API, requires no credentials, and emits a specific JSON structure are documentation assertions rather than enforceable controls.

Attack Path

  1. An attacker, compromised installer, or malicious package obtains write access to ~/.npm-global/lib/node_modules/openclaw/skills/btc-analyzer/analyze.py or its parent directory.
  2. The attacker creates or replaces analyze.py with attacker-controlled Python code.
  3. A user requests BTC analysis, causing the Skill workflow to be activated.
  4. Following SKILL.md, the agent invokes the global script through Bash with python3.
  5. Python executes ...[truncated 968 chars]
Remediation
View remediation

Remediation Suggestions

  • Bundle analyze.py within the reviewed Skill package so the instructions and executable implementation are distributed and audited together.
  • Resolve the script path relative to the Skill's verified installation directory rather than using a mutable global npm path.
  • Verify the bundled script's cryptographic hash or package signature before execution.
  • Restrict file permissions so untrusted users and unrelated package installers cannot modify the script or its parent directories.
  • Execute the analyzer with least privilege in a sandbox that limits filesystem access, environment-variable access, subprocess creation, and outbound networking.
  • Apply an outbound network allowlist restricted to the documented Binance HTTPS endpoint.
  • Validate the script's JSON output against a strict schema before presenting it to the user.
  • Fail safely when the bundled script is missing or fails integrity validation; do not search for or execute an alternative script from global paths.
  • Include the implementation and dependency metadata in future security reviews so its calculations, network behavior, and error handling can be verified.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises broad trigger phrases like 'get trading signal' and 'check market trend' without narrowing scope, disclaiming financial risk, or requiring explicit user confirmation before producing actionable trading guidance. In an agent environment, overly broad routing can cause the skill to activate in ambiguous contexts and generate high-stakes financial advice that users may rely on without understanding its limitations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill makes live requests to an external Binance API but does not clearly warn users that their request will cause outbound network access to a third-party service. Hidden external communication reduces transparency, can violate user or organizational expectations around data egress, and may expose contextual information such as timing, usage patterns, or derived prompts to an external provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The workflow instructs the agent to execute a local Python script via bash, but it does not clearly disclose subprocess execution to the user or constrain execution behavior in the skill document. Even though the command is fixed and appears simple, undisclosed code execution increases operational risk because users may not realize the agent is launching local code with the host's privileges.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.