Back to skill

Security audit

加密货币监控与告警

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs read-only crypto price lookups and local alert storage, but it overstates automated monitoring/on-chain capabilities and includes advice-like report wording despite saying it is not investment advice.

Review this skill before installing if you need dependable alerts: it saves alert settings but does not ship a working continuous monitor or notification sender. Treat generated market reports as informational only, and avoid relying on any operation-advice wording as financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

描述强调的是一个完整的加密货币监控/告警工具,包含实时监控、行情查看、市场日报和链上数据查看等能力。但提供的代码片段只负责告警规则的本地持久化管理(增删查),属于告警设置的辅助组件,而不是所宣称的完整监控功能本身。虽然“设置价格突破/跌破告警”这一小部分与代码一致,但描述中的多项核心能力在代码中均未体现,因此存在明显的描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明的核心卖点是“设置价格告警、实时监控、链上数据一键查看”,但提供的代码只是一次性拉取CoinGecko行情并打印日报/单币分析结果,没有任何告警逻辑、持续监控/定时轮询机制、通知发送能力,也没有访问任何链上数据源。虽然“生成市场日报、查看加密货币行情”与代码一致,且代码未执行交易等禁用行为,但整体上声明覆盖的主要能力明显超出代码实际实现,因此属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个较完整的行情监控与告警技能,核心能力包括价格告警、实时监控、日报生成和链上数据查看。但提供的代码只是在执行时进行一次性价格拉取和展示,没有任何告警逻辑、阈值设置、定时/持续监控机制、日报汇总功能,也没有访问任何链上数据源。代码的主要目的更接近“查询单个币种当前行情”,而不是“监控并告警”。虽然它确实与加密货币行情相关,且不涉及交易下单,但对声明中的关键功能存在明显缺失,因此描述与实际行为不准确,构成实质性不匹配。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The report template includes an '操作建议' section despite the manifest explicitly saying the skill is not for investment advice. In this context, that creates a trust and safety boundary violation: users may rely on generated recommendations as financial advice, especially in a high-volatility crypto setting.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Overly broad trigger phrases can cause the skill to activate in unrelated conversations, leading to unintended use of network-backed market lookups or alert-setting flows. In an agent ecosystem, misrouting user requests can leak context, create confusing outputs, or trigger actions the user did not intend, especially for finance-related topics where precision matters.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function is documented as fetching Binance real-time price, but it constructs a return object including data['time'] even though the /api/v3/ticker/price response does not include a time field. This is an active contradiction between the documented example behavior and what the endpoint actually returns, which would break the sample code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 11)May include surrounding context.

md
def get_binance_price(symbol="BTCUSDT"):
    """获取Binance实时价格"""
    url = f"https://api.binance.com/api/v3/ticker/price"
    params = {"symbol": symbol}
    response = requests.get(url, params=params)
    data = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 30)May include surrounding context.

md
def get_binance_price(symbol="BTCUSDT"):
    """获取Binance实时价格"""
    url = f"https://api.binance.com/api/v3/ticker/price"
    params = {"symbol": symbol}
    response = requests.get(url, params=params)
    data = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 58)May include surrounding context.

md
def get_binance_price(symbol="BTCUSDT"):
    """获取Binance实时价格"""
    url = f"https://api.binance.com/api/v3/ticker/price"
    params = {"symbol": symbol}
    response = requests.get(url, params=params)
    data = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 80)May include surrounding context.

md
def get_binance_price(symbol="BTCUSDT"):
    """获取Binance实时价格"""
    url = f"https://api.binance.com/api/v3/ticker/price"
    params = {"symbol": symbol}
    response = requests.get(url, params=params)
    data = response.json()

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames the skill as price monitoring, alerts, market snapshots, and on-chain data lookup, while this file adds K-line retrieval specifically '用于技术分析' and later technical indicator computations that support analytical interpretation rather than simple monitoring. That is a broader behavior category than the declared '只监控不下单、…不…投资建议' positioning, especially when paired with report-generation content elsewhere in the file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest scope is monitoring coin prices, setting alerts, and viewing market行情, but this function evaluates holder concentration, contract verification, ownership status, and liquidity-removal heuristics. Those are token due-diligence and scam-risk assessment capabilities, which are materially different from the stated monitoring purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language strings that assume Chinese as the required interaction language, including the module docstring and subsequent user-facing messages. The policy explicitly disallows forcing a specific language or locale unless the skill offers user choice or clearly documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 96)May include surrounding context.

md
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 109)May include surrounding context.

md
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 124)May include surrounding context.

md
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 142)May include surrounding context.

md
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/market_report.py (reported line 15)May include surrounding context.

python
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/market_report.py (reported line 54)May include surrounding context.

python
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/price_check.py (reported line 27)May include surrounding context.

python
def fetch_market_data():
    """从CoinGecko获取市场概览"""
    url = "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=20&page=1&sparkline=false&price_change_percentage=24h"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=15) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 144)May include surrounding context.

md
"binancecoin": "binance-coin", "dogecoin": "dogecoin",
    }
    cap_id = coincap_map.get(coin_id, coin_id)
    url = f"https://api.coincap.io/v2/assets/{cap_id}"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=10) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 152)May include surrounding context.

md
"binancecoin": "binance-coin", "dogecoin": "dogecoin",
    }
    cap_id = coincap_map.get(coin_id, coin_id)
    url = f"https://api.coincap.io/v2/assets/{cap_id}"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=10) as resp:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/price_check.py (reported line 51)May include surrounding context.

python
"binancecoin": "binance-coin", "dogecoin": "dogecoin",
    }
    cap_id = coincap_map.get(coin_id, coin_id)
    url = f"https://api.coincap.io/v2/assets/{cap_id}"
    try:
        req = urllib.request.Request(url, headers={"User-Agent": "Mozilla/5.0"})
        with urllib.request.urlopen(req, timeout=10) as resp:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

文件中的描述与使用条件均以中文固定表述,未说明是否支持根据用户偏好切换语言,也未提供显式的语言选择或 opt-in 机制。根据语言/locale 策略,若技能默认强制特定语言而无用户选择,可能构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.