Back to skill

Security audit

加密货币监控与告警

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly transparent crypto price/report helper, but users should not rely on it for guaranteed alerts or investment decisions.

Use this only as an informational crypto market helper. Expect it to query public market APIs and save alert settings locally, and verify any alert monitoring is actually running before relying on it. Do not treat generated reports, risk notes, or operation-advice wording as financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The finding correctly identifies that multiple named capabilities—price breakout alerts, continuous tracking, market daily reports, on-chain data views, and Binance support—are asserted but not actually implemented in this file. In this skill context, the danger is not code execution but deceptive or inaccurate operational claims that could cause users to miss critical crypto market movements because they trust unimplemented alerting behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The finding correctly identifies that multiple named capabilities—price breakout alerts, continuous tracking, market daily reports, on-chain data views, and Binance support—are asserted but not actually implemented in this file. In this skill context, the danger is not code execution but deceptive or inaccurate operational claims that could cause users to miss critical crypto market movements because they trust unimplemented alerting behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The finding correctly identifies that multiple named capabilities—price breakout alerts, continuous tracking, market daily reports, on-chain data views, and Binance support—are asserted but not actually implemented in this file. In this skill context, the danger is not code execution but deceptive or inaccurate operational claims that could cause users to miss critical crypto market movements because they trust unimplemented alerting behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents the skill documentation and examples exclusively in Chinese from the title onward, with no indication that users may choose another language. The policy explicitly flags forced language constraints without user opt-in, and there is no documented justification that this is a region-specific or Chinese-only skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 11)May include surrounding context.

md
def get_binance_price(symbol="BTCUSDT"):
    """获取Binance实时价格"""
    url = f"https://api.binance.com/api/v3/ticker/price"
    params = {"symbol": symbol}
    response = requests.get(url, params=params)
    data = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 30)May include surrounding context.

md
def get_binance_price(symbol="BTCUSDT"):
    """获取Binance实时价格"""
    url = f"https://api.binance.com/api/v3/ticker/price"
    params = {"symbol": symbol}
    response = requests.get(url, params=params)
    data = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 58)May include surrounding context.

md
def get_binance_price(symbol="BTCUSDT"):
    """获取Binance实时价格"""
    url = f"https://api.binance.com/api/v3/ticker/price"
    params = {"symbol": symbol}
    response = requests.get(url, params=params)
    data = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 80)May include surrounding context.

md
def get_binance_price(symbol="BTCUSDT"):
    """获取Binance实时价格"""
    url = f"https://api.binance.com/api/v3/ticker/price"
    params = {"symbol": symbol}
    response = requests.get(url, params=params)
    data = response.json()

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The report template includes an '操作建议' section despite the manifest stating the skill is not for investment advice. In a crypto context, this can mislead users into relying on automated output as financial guidance, defeating an explicit safety boundary and increasing risk of harmful decision-making.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language descriptions and user-facing output entirely in Chinese, including the module docstring and printed status messages. The skill does not offer any language selection or indicate that it is intentionally region-specific, which creates a language/locale policy concern under the natural-language policy rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language docstrings and user-facing messages entirely in Chinese, but there is no indication that the skill is region-specific or that users can opt into another language. Under the language/locale policy, forcing a specific language without user choice is a policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 96)May include surrounding context.

md
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 109)May include surrounding context.

md
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 124)May include surrounding context.

md
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 142)May include surrounding context.

md
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/market_report.py (reported line 15)May include surrounding context.

python
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/price_check.py (reported line 27)May include surrounding context.

python
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The coin_id argument is interpolated directly into the URL path without validation or encoding before making an external request. While the host remains fixed to CoinGecko, unvalidated path construction can enable malformed requests, unexpected endpoint access on the same domain, log injection via error messages, or abuse of the script as a network client with attacker-controlled request paths.

Content

Scanner excerpt · scripts/market_report.py (reported line 54)May include surrounding context.

python
def format_analysis(coin_id):
    """单币深度分析"""
    url = f"https://api.coingecko.com/api/v3/coins/{coin_id}?localization=false&tickers=false&community_data=false&developer_data=false"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language strings in the module docstring and CLI help text are exclusively Chinese, which can constitute a language/locale policy violation when no user choice or opt-in is provided. The file does not indicate that the locale is intentionally region-specific or offer an alternative language.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 144)May include surrounding context.

md
"binancecoin": "binance-coin", "dogecoin": "dogecoin",
    }
    cap_id = coincap_map.get(coin_id, coin_id)
    url = f"https://api.coincap.io/v2/assets/{cap_id}"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=10) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 152)May include surrounding context.

md
"binancecoin": "binance-coin", "dogecoin": "dogecoin",
    }
    cap_id = coincap_map.get(coin_id, coin_id)
    url = f"https://api.coincap.io/v2/assets/{cap_id}"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=10) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/price_check.py (reported line 51)May include surrounding context.

python
"binancecoin": "binance-coin", "dogecoin": "dogecoin",
    }
    cap_id = coincap_map.get(coin_id, coin_id)
    url = f"https://api.coincap.io/v2/assets/{cap_id}"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=10) as resp:

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest says the skill is for price monitoring, alerts, market viewing, daily reports, and one-click on-chain data lookup, explicitly not for investment advice. This file includes K-line retrieval and technical indicator calculations intended for analysis, plus rug-pull indicator evaluation, which go beyond straightforward monitoring and edge toward evaluative market-analysis functionality.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest frames the skill as a crypto price monitoring and alerting tool with market-viewing features. Rug-pull detection based on liquidity changes, holder concentration, contract verification, and ownership controls is a distinct token due-diligence capability not clearly declared in that purpose statement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.