T09 · Insecure Skill Coding Practices
- Location
payment.py:15- Finding
Hard-Coded Payment API Credential
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The Solana analytics skill is mostly coherent, but it embeds a payment API key and sends wallet addresses to an external payment service without clear in-skill disclosure.
Review this skill before installing. The Solana analysis pieces are ordinary market-data tooling, but the package exposes a payment-service API key and can link a wallet address to use of the skill through SkillPay. Install only if you are comfortable with that payment flow and the publisher has rotated the exposed key and clearly documented what wallet data is sent.
payment.py:15Hard-Coded Payment API Credential
payment.py:30Undisclosed Transmission of User Wallet Identifiers
scripts/ecosystem_monitor.py:136Predictable Temporary File Enables Symlink-Based File Overwrite
A Solana intelligence skill that also performs payment verification, uses an embedded API key, and introduces billing logic through an external SkillPay API is a serious description-behavior mismatch. Hidden monetization and embedded credentials are dangerous because they can exfiltrate secrets, mislead users about the skill's real purpose, and create unauthorized external dependencies unrelated to the declared function.
A Solana intelligence skill that also performs payment verification, uses an embedded API key, and introduces billing logic through an external SkillPay API is a serious description-behavior mismatch. Hidden monetization and embedded credentials are dangerous because they can exfiltrate secrets, mislead users about the skill's real purpose, and create unauthorized external dependencies unrelated to the declared function.
The skill declares no explicit tool scope or permission boundaries, yet the referenced capabilities imply access to environment data, file writing, and network operations. In an investment-analysis skill, undeclared powerful capabilities increase the risk of overreach, unexpected data access, or unauthorized outbound calls because neither users nor the platform can clearly constrain runtime behavior.
The manifest says the skill triggers whenever the user needs to analyze the Solana ecosystem, discover new projects, track opportunities, obtain market intelligence, or perform on-chain analysis. This covers a very wide range of ordinary crypto questions and does not define clear boundaries or exclusion conditions, increasing the chance of unintended invocation.
This manifest describes broad capabilities such as ecosystem analysis, new coin discovery, meme coin tracking, and investment opportunity identification, but it does not define when the skill should or should not activate. For manifest files, missing specificity on trigger scope or constraints is a vague-trigger issue because it can lead to unintended invocation in loosely related crypto conversations.
The manifest description is entirely in Chinese, which indicates a language-specific presentation without any visible opt-in or explanation that the skill is intended only for Chinese-speaking users. The policy requires that language or locale constraints be optional or clearly justified rather than implicitly enforced.
The file hardcodes a live API key for an external payment service, which is a direct secret exposure vulnerability. Anyone with access to the code can reuse the credential to query or abuse the SkillPay API, potentially impersonating the skill, accessing billing data, or incurring fraudulent activity against the account.
from datetime import datetime
# SkillPay API 配置
SKILLPAY_API_URL = "https://api.skillpay.io/v1"
SKILLPAY_API_KEY = "sk_f03aa8f8bbcf79f7aa11c112d904780f22e62add1464e3c41a79600a451eb1d2"
SKILL_SLUG = "shenmeng-solana-intelligence"
PRICE = "0.01" # USDT
The code hardcodes configuration for SkillPay and a BNB Chain payment flow, which is not an obvious requirement for analyzing the Solana ecosystem or monitoring on-chain opportunities. Monetization infrastructure may be valid operationally, but it is not justified by the skill’s declared analytical purpose unless explicitly documented.
The manifest describes a skill for Solana on-chain analysis, opportunity detection, meme trend tracking, and investment intelligence. This file instead implements paid access control by verifying payments with an external SkillPay service and presenting a payment flow on BNB Chain, which is a distinct product monetization function not described in the manifest.
The code transmits a user's wallet address and a timestamp to an external API, creating a privacy leak and linking user identity/activity to a third party. In a blockchain intelligence context, wallet addresses are especially sensitive because they can be correlated with on-chain behavior and profiling, and this file provides no user-facing notice or consent flow.
This markdown file contains all instructional content in Chinese and does not provide an opt-in, alternative language, or justification for restricting the skill reference to that locale. That can violate language/locale policy when users are not given a choice.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 获取 Solana 生态代币列表
curl "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&category=solana-ecosystem&order=market_cap_desc&per_page=100&page=1"
# 获取特定代币数据
curl "https://api.coingecko.com/api/v3/coins/bonk"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Solana TVL
curl "https://api.llama.fi/chain/Solana"
# 协议 TVL
curl "https://api.llama.fi/protocols"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Solana TVL
curl "https://api.llama.fi/chain/Solana"
# 协议 TVL
curl "https://api.llama.fi/protocols"
This markdown file contains user-facing instructional content exclusively in Chinese, and nowhere indicates that the skill is region- or language-specific or that users may choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def __init__(self):
self.base_urls = {
'defillama': 'https://api.llama.fi',
'coingecko': 'https://api.coingecko.com/api/v3',
}
def get_tvl(self) -> Optional[Dict]:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def __init__(self):
self.base_urls = {
'defillama': 'https://api.llama.fi',
'coingecko': 'https://api.coingecko.com/api/v3',
}
def get_tvl(self) -> Optional[Dict]:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def __init__(self):
self.base_urls = {
'defillama': 'https://api.llama.fi',
'coingecko': 'https://api.coingecko.com/api/v3',
}
def get_tvl(self) -> Optional[Dict]:
This Python file contains user-facing natural language exclusively in Chinese, including the module description and all report text, with no indication that language is configurable or that the skill is intended only for a Chinese-speaking or region-specific audience. That creates a locale-policy issue because the skill effectively forces a specific language without user opt-in.
The phrase 'detect new opportunities on Solana' is open-ended and does not specify whether it refers to launchpad tokens, DeFi protocols, NFT activity, or other contexts. Without narrower scope, it can collide with general market-advice or research queries.
Natural-language strings and module descriptions in this file are presented in Chinese, including user-facing payment guidance, but there is no indication that users can opt into this language or select an alternative. That can violate language/locale policy when a specific language is imposed implicitly.
The manifest frames this skill as a Solana analysis, monitoring, and opportunity-detection tool. In addition to generating a report, the script persists collected market data to /tmp as JSON, which is a side effect not implied by the description's analytics-focused wording.
No suspicious patterns detected.