Back to skill

Security audit

Whale Alert Monitor 大户监控

Security checks for vulnerabilities and agentic risk

Overview

This paid whale-monitoring skill discloses some billing and notification behavior, but it ships a hardcoded billing credential and presents simulated crypto-monitoring data as real-time monitoring.

Review carefully before installing. Treat this as a paid, externally connected skill, rotate or remove the embedded billing key, require explicit consent before charges, and do not rely on its monitoring reports until live data sources replace the current simulated outputs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
payment.py:11
Finding

Hardcoded Billing API Credential

Content
View full analysis

Vulnerability Details

File Location: payment.py, lines 11–18
Vulnerability Type: Hardcoded API credential
Risk Level: High

Vulnerable Code

python
BILLING_API_URL = "https://skillpay.me"
BILLING_API_KEY = "sk_f03aa8f8bbcf79f7aa11c112d904780f22e62add1464e3c41a79600a451eb1d2"
SKILL_ID = "ac50f691-5081-4843-9942-bb3955872b23"
SKILL_NAME = "whale-alert-monitor"
PRICE_PER_CALL = 0.01  # USDT

HEADERS = {
    "X-API-Key": BILLING_API_KEY,
    "Content-Type": "application/json"
}

Technical Analysis

A live-format billing API key is embedded directly in distributable source code and placed in the X-API-Key header used by the balance, charge, and payment-link requests. Any party with access to the package can recover the credential without authentication or reverse engineering.

This implementation also conflicts with _meta.json, which declares SKILLPAY_API_KEY as the intended environment variable. Hardcoding the key prevents secure per-deployment secret management and makes revocation or rotation difficult.

The billing API’s server-side authorization policy was not available for review. Exploitability and maximum impact therefore depend on the permissions assigned to this key, but exposing an authentication credential is independently a confirmed security defect.

Attack Path

  1. An attacker downloads or otherwise obtains the Skill package.
  2. The attacker opens payment.py and extracts BILLING_API_KEY.
  3. The attacker reconstructs authenticated requests using the disclosed base URL, header name, and endpoints present in the same file.
  4. The attacker sends requests to the balance, charge, or payment-link endpoints while presenting the exposed key.
  5. If the billing service accepts the key, the attacker performs any billing operations authorized to that credential until it is revoked, rotated, or restricted by the provider.

Impact Assessment

The attacker can obtain the billing integration’s API identity and potentia ...[truncated 497 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed API key immediately; assume it has already been compromised.
  2. Remove the credential from the source code and repository history.
  3. Read the key from the declared environment variable and fail closed when it is absent:
python
BILLING_API_KEY = os.environ.get("SKILLPAY_API_KEY")
if not BILLING_API_KEY:
    raise RuntimeError("SKILLPAY_API_KEY is required")

HEADERS = {
    "X-API-Key": BILLING_API_KEY,
    "Content-Type": "application/json",
}
  1. Provision separate credentials per deployment instead of sharing one package-wide secret.
  2. Restrict the credential to the minimum required endpoints, Skill ID, transaction amount, and rate limits.
  3. Add server-side authorization checks so callers cannot select arbitrary users, Skill IDs, or charge amounts.
  4. Store production credentials in a dedicated secret manager or protected runtime environment.
  5. Add automated secret scanning to CI and pre-commit workflows.
  6. Review billing-provider logs for suspicious activity involving the exposed key and invalidate affected sessions or transactions.
  7. Require explicit user consent before initiating a charge and avoid the "anonymous_user" fallback for billable operations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (48)

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · payment.py (reported line 29)May include surrounding context.

python
def check_balance(user_id: str) -> float:
    """查询用户余额"""
    try:
        resp = requests.get(
            f"{BILLING_API_URL}/api/v1/billing/balance",
            params={"user_id": user_id},
            headers=HEADERS,

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
98% confidence
Finding

The code transmits a platform-derived user identifier to a third-party billing service and immediately attempts to charge the user whenever verification runs. In the context of a whale-monitoring skill, embedding hidden payment enforcement with a hardcoded API key and automatic debit behavior is unrelated to core functionality and can enable unauthorized charging and identity sharing.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The function sends the user identifier to an external payment-link service, exposing user identity data to a third party outside the skill's stated monitoring purpose. In this skill context, generating recharge links is unrelated to whale alerting and increases the risk of covert monetization, user tracking, and redirection to external payment flows.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/alert_manager.py (reported line 141)May include surrounding context.

python
str, data: Optional[Dict]):
        """控制台通知"""
        print(f"\n{'='*80}")
        print(f"🚨 预警通知")
        print(f"{'='*80}")
        print(message)
        if data:
            print(f"\n数据: {json.dumps(data, indent=2)}")
        print(f"{'='*80}\n")
    
    def _send_telegram(self, message: str, data: Optional[Dict]):
        """Telegram通知"""
        bot_token = os.getenv('TELEGRAM_BOT_TOKEN')
        chat_id = os.getenv('TELEGRAM_CHAT_ID')
        
        if not bot_token or not chat_id:
            logger.warning("Telegram配置缺失")
            return
        
        try:
            url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
            payload = {
                'chat_id': chat_id,
                'text': message,
                'parse_mode': 'Markdown'
            }
            
            response = requests.post(url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅

Tainted flow: 'url' from os.getenv (line 149, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 156)May include surrounding context.

python
'parse_mode': 'Markdown'
            }
            
            response = requests.post(url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅ Telegram通知已发送")
            else:

Tainted flow: 'webhook_url' from os.getenv (line 200, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The Discord webhook URL is taken directly from an environment variable and used as the outbound destination. If an attacker can influence that environment variable or if sensitive alert contents are included in notifications, the skill can silently send operational or financial monitoring data to an unintended third party.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 190)May include surrounding context.

python
'embeds': [embed]
            }
            
            response = requests.post(webhook_url, json=payload, timeout=10)
            if response.status_code == 204:
                logger.info("✅ Discord通知已发送")
            else:

Tainted flow: 'webhook_url' from os.getenv (line 200, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The custom webhook destination is fully controlled by the CUSTOM_WEBHOOK_URL environment variable and receives arbitrary message and data payloads. In an agent skill context, this creates a real exfiltration channel because monitored wallet activity, alert metadata, or future enriched data could be transmitted to any external host without code-level destination restrictions.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 213)May include surrounding context.

python
'timestamp': datetime.now().isoformat()
            }
            
            response = requests.post(webhook_url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅ Webhook通知已发送")
        except Exception as e:

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the finding indicates undeclared payment processing via an external billing service, balance checks, per-call charging, payment link generation, and execution gating based on environment-derived identity. Hidden billing and external API use materially change the trust and data-handling model, exposing users to unexpected charges, identity leakage, and off-platform interactions they did not explicitly consent to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the finding indicates undeclared payment processing via an external billing service, balance checks, per-call charging, payment link generation, and execution gating based on environment-derived identity. Hidden billing and external API use materially change the trust and data-handling model, exposing users to unexpected charges, identity leakage, and off-platform interactions they did not explicitly consent to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the finding indicates undeclared payment processing via an external billing service, balance checks, per-call charging, payment link generation, and execution gating based on environment-derived identity. Hidden billing and external API use materially change the trust and data-handling model, exposing users to unexpected charges, identity leakage, and off-platform interactions they did not explicitly consent to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the finding indicates undeclared payment processing via an external billing service, balance checks, per-call charging, payment link generation, and execution gating based on environment-derived identity. Hidden billing and external API use materially change the trust and data-handling model, exposing users to unexpected charges, identity leakage, and off-platform interactions they did not explicitly consent to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the finding indicates undeclared payment processing via an external billing service, balance checks, per-call charging, payment link generation, and execution gating based on environment-derived identity. Hidden billing and external API use materially change the trust and data-handling model, exposing users to unexpected charges, identity leakage, and off-platform interactions they did not explicitly consent to.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The entire file implements billing enforcement even though the skill is described as a whale-wallet monitoring assistant. This capability mismatch is a strong indicator of hidden behavior: the skill can block execution and push users into an external payment flow that is not justified by its declared purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-configuration.md (reported line 158)May include surrounding context.

环境变量配置

.env 文件

bash
# Etherscan
ETHERSCAN_API_KEY=xxx

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill metadata promises real-time whale wallet monitoring and exchange-flow tracking, but this implementation only creates random local transactions and produces offline analysis. This mismatch is dangerous because users may trust the tool for time-sensitive financial surveillance while it provides fabricated, non-live results.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code explicitly generates simulated transaction history but later analyzes it and presents balances, accumulation/distribution patterns, and wallet reports in a way that appears operationally meaningful. In a crypto-monitoring skill, this can mislead users into making trading, compliance, or monitoring decisions based on fabricated data, which is a security-relevant integrity failure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises capabilities that imply environment access, file operations, and network use, but it does not declare any tool scope or permissions boundaries. In an agent ecosystem, missing scope declarations can cause over-privileged execution, reduce reviewability, and make it harder to enforce least privilege for a skill that may read secrets, write files, or contact external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill promotes Telegram/Discord/Webhook notifications but does not clearly warn that monitored wallet addresses, alert contents, and potentially sensitive user-configured data may be transmitted to third-party messaging services. In a crypto-monitoring context, that can expose trading interests, operational intelligence, or internal watchlists to external providers and any compromised channels.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The configuration example includes sensitive messaging credentials such as bot tokens, chat IDs, and webhook URLs without safety guidance. Users may paste real secrets into configs, commit them to repositories, or expose them in logs, leading to account takeover of bots/webhooks, spam, message interception, or unauthorized notification delivery.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and subsequent user-facing strings are written in Chinese, indicating the skill is designed to communicate in a fixed language. There is no opt-in, fallback, or documentation that this is a region-specific skill, so this creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This request sends user-linked billing data to an external service for charging. Because the skill's declared purpose is cryptocurrency whale monitoring rather than payments, the transmission is contextually suspicious and supports unauthorized monetization and privacy leakage.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This external transmission sends user-linked data to obtain a payment URL from a third party. In this context, it facilitates off-platform payment collection unrelated to the skill's stated function and can steer users into unreviewed payment flows.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill reads a platform user identity from an environment variable and uses it for third-party payment enforcement, a capability not required for wallet monitoring. This creates unnecessary access to user identity data and enables cross-system linkage or charging without a justified need.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docstring claims the function verifies whether the user has already paid, but the implementation actually performs a charge operation. This deception is dangerous because it disguises billing side effects as a harmless check, increasing the chance of unauthorized charges and evading reviewer or user scrutiny.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-configuration.md (reported line 8)May include surrounding context.

基础配置

python
ETHERSCAN_API_KEY = "YourApiKey"
BASE_URL = "https://api.etherscan.io/api"

常用端点

Static analysis

No suspicious patterns detected.