Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 90% confidence
- Finding
描述强调的是一个完整的加密货币监控/告警工具,包含实时监控、行情查看、市场日报和链上数据查看等能力。但提供的代码片段只负责告警规则的本地持久化管理(增删查),属于告警设置的辅助组件,而不是所宣称的完整监控功能本身。虽然“设置价格突破/跌破告警”这一小部分与代码一致,但描述中的多项核心能力在代码中均未体现,因此存在明显的描述与行为不一致。
- Content
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly performs read-only crypto price lookups and local alert storage, but it overstates automated monitoring/on-chain capabilities and includes advice-like report wording despite saying it is not investment advice.
Review this skill before installing if you need dependable alerts: it saves alert settings but does not ship a working continuous monitor or notification sender. Treat generated market reports as informational only, and avoid relying on any operation-advice wording as financial advice.
描述强调的是一个完整的加密货币监控/告警工具,包含实时监控、行情查看、市场日报和链上数据查看等能力。但提供的代码片段只负责告警规则的本地持久化管理(增删查),属于告警设置的辅助组件,而不是所宣称的完整监控功能本身。虽然“设置价格突破/跌破告警”这一小部分与代码一致,但描述中的多项核心能力在代码中均未体现,因此存在明显的描述与行为不一致。
声明的核心卖点是“设置价格告警、实时监控、链上数据一键查看”,但提供的代码只是一次性拉取CoinGecko行情并打印日报/单币分析结果,没有任何告警逻辑、持续监控/定时轮询机制、通知发送能力,也没有访问任何链上数据源。虽然“生成市场日报、查看加密货币行情”与代码一致,且代码未执行交易等禁用行为,但整体上声明覆盖的主要能力明显超出代码实际实现,因此属于描述与行为不一致。
声明描述的是一个较完整的行情监控与告警技能,核心能力包括价格告警、实时监控、日报生成和链上数据查看。但提供的代码只是在执行时进行一次性价格拉取和展示,没有任何告警逻辑、阈值设置、定时/持续监控机制、日报汇总功能,也没有访问任何链上数据源。代码的主要目的更接近“查询单个币种当前行情”,而不是“监控并告警”。虽然它确实与加密货币行情相关,且不涉及交易下单,但对声明中的关键功能存在明显缺失,因此描述与实际行为不准确,构成实质性不匹配。
The report template includes an '操作建议' section despite the manifest explicitly saying the skill is not for investment advice. In this context, that creates a trust and safety boundary violation: users may rely on generated recommendations as financial advice, especially in a high-volatility crypto setting.
Without declared permissions the skill's intent is opaque and cannot be validated.
Overly broad trigger phrases can cause the skill to activate in unrelated conversations, leading to unintended use of network-backed market lookups or alert-setting flows. In an agent ecosystem, misrouting user requests can leak context, create confusing outputs, or trigger actions the user did not intend, especially for finance-related topics where precision matters.
The function is documented as fetching Binance real-time price, but it constructs a return object including data['time'] even though the /api/v3/ticker/price response does not include a time field. This is an active contradiction between the documented example behavior and what the endpoint actually returns, which would break the sample code.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def get_binance_price(symbol="BTCUSDT"):
"""获取Binance实时价格"""
url = f"https://api.binance.com/api/v3/ticker/price"
params = {"symbol": symbol}
response = requests.get(url, params=params)
data = response.json()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def get_binance_price(symbol="BTCUSDT"):
"""获取Binance实时价格"""
url = f"https://api.binance.com/api/v3/ticker/price"
params = {"symbol": symbol}
response = requests.get(url, params=params)
data = response.json()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def get_binance_price(symbol="BTCUSDT"):
"""获取Binance实时价格"""
url = f"https://api.binance.com/api/v3/ticker/price"
params = {"symbol": symbol}
response = requests.get(url, params=params)
data = response.json()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def get_binance_price(symbol="BTCUSDT"):
"""获取Binance实时价格"""
url = f"https://api.binance.com/api/v3/ticker/price"
params = {"symbol": symbol}
response = requests.get(url, params=params)
data = response.json()
The manifest frames the skill as price monitoring, alerts, market snapshots, and on-chain data lookup, while this file adds K-line retrieval specifically '用于技术分析' and later technical indicator computations that support analytical interpretation rather than simple monitoring. That is a broader behavior category than the declared '只监控不下单、…不…投资建议' positioning, especially when paired with report-generation content elsewhere in the file.
The manifest scope is monitoring coin prices, setting alerts, and viewing market行情, but this function evaluates holder concentration, contract verification, ownership status, and liquidity-removal heuristics. Those are token due-diligence and scam-risk assessment capabilities, which are materially different from the stated monitoring purpose.
This code file contains natural-language strings that assume Chinese as the required interaction language, including the module docstring and subsequent user-facing messages. The policy explicitly disallows forcing a specific language or locale unless the skill offers user choice or clearly documents a justified region-specific constraint.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def fetch_market_data():
"""从CoinGecko获取市场概览"""
url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=15) as resp:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def fetch_market_data():
"""从CoinGecko获取市场概览"""
url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=15) as resp:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def fetch_market_data():
"""从CoinGecko获取市场概览"""
url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=15) as resp:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def fetch_market_data():
"""从CoinGecko获取市场概览"""
url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=15) as resp:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def fetch_market_data():
"""从CoinGecko获取市场概览"""
url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=15) as resp:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def fetch_market_data():
"""从CoinGecko获取市场概览"""
url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=15) as resp:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def fetch_market_data():
"""从CoinGecko获取市场概览"""
url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=15) as resp:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"binancecoin": "binance-coin", "dogecoin": "dogecoin",
}
cap_id = coincap_map.get(coin_id, coin_id)
url = f"https://api.coincap.io/v2/assets/{cap_id}"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=10) as resp:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"binancecoin": "binance-coin", "dogecoin": "dogecoin",
}
cap_id = coincap_map.get(coin_id, coin_id)
url = f"https://api.coincap.io/v2/assets/{cap_id}"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=10) as resp:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"binancecoin": "binance-coin", "dogecoin": "dogecoin",
}
cap_id = coincap_map.get(coin_id, coin_id)
url = f"https://api.coincap.io/v2/assets/{cap_id}"
try:
req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
with urllib.request.urlopen(req, timeout=10) as resp:
文件中的描述与使用条件均以中文固定表述,未说明是否支持根据用户偏好切换语言,也未提供显式的语言选择或 opt-in 机制。根据语言/locale 策略,若技能默认强制特定语言而无用户选择,可能构成自然语言政策问题。
No suspicious patterns detected.