Back to skill

Security audit

Whale Alert Monitor 鲸鱼监控

Security checks for vulnerabilities and agentic risk

Overview

This paid crypto-monitoring skill is not clearly safe to install because its user-facing claims describe real whale and exchange monitoring while the implementation generates simulated financial data and includes risky billing code.

Review this carefully before installing. The strongest issue is not host compromise; it is trust and financial-data integrity. The skill appears to charge for monitoring, but its main reports and alerts are based on random simulated data rather than verified blockchain or exchange sources, and its billing credential is embedded in source code. Do not rely on its outputs for trading, accounting, compliance, or incident response unless the publisher replaces the simulation with verified data sources and rotates/removes the exposed billing key.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
payment.py:11
Finding

Hard-Coded SkillPay API Credential in Distributed Source Code

Content
View full analysis

Vulnerability Details

File Location: payment.py, lines 11-18
Vulnerability Type: Hard-coded API secret
Risk Level: High

Vulnerable Code

python
BILLING_API_URL = "https://skillpay.me"
BILLING_API_KEY = "sk_f03aa8f8bbcf79f7aa11c112d904780f22e62add1464e3c41a79600a451eb1d2"
SKILL_ID = "ac50f691-5081-4843-9942-bb3955872b23"
SKILL_NAME = "whale-alert-monitor"
PRICE_PER_CALL = 0.01  # USDT

HEADERS = {
    "X-API-Key": BILLING_API_KEY,
    "Content-Type": "application/json"
}

Technical Analysis

A live-looking SkillPay API key is embedded directly in source code distributed with the Skill. Anyone with access to the package can recover and reuse this credential. This also contradicts _meta.json, which declares SKILLPAY_API_KEY as the expected credential source.

The key is attached to requests made to the balance, charge, and payment-link endpoints. The actual privileges available to an attacker depend on SkillPay's server-side authorization, but client-side secrecy provides no protection once the credential is published.

Attack Path

  1. An attacker downloads or otherwise obtains the Skill package.
  2. The attacker reads payment.py and extracts BILLING_API_KEY.
  3. The attacker submits requests to the documented SkillPay billing endpoints with the exposed key in the X-API-Key header.
  4. If the service does not strictly bind the key to authorized users, fixed amounts, and the declared Skill ID, the attacker may perform unauthorized balance queries, generate payment links, submit billing requests, or consume the account's quota.
  5. Requests may appear to originate from the legitimate Skill because they use its credential.

Impact Assessment

The exposed credential may permit unauthorized use of the SkillPay account's billing API privileges. Potential effects include fraudulent or incorrect billing operations, information disclosure through balance queries, payment-link ...[truncated 207 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed API key immediately.
  2. Remove the credential from source code and repository history.
  3. Load the credential exclusively from SKILLPAY_API_KEY:
    python
    BILLING_API_KEY = os.environ.get("SKILLPAY_API_KEY")
    if not BILLING_API_KEY:
        raise RuntimeError("SKILLPAY_API_KEY is required")
    
  4. Construct authorization headers only after validating that the environment variable is present.
  5. Store production secrets in the platform's managed secret store rather than configuration files or package metadata.
  6. Configure SkillPay to bind the credential to the fixed Skill ID, permitted endpoints, expected price, and minimum required operations.
  7. Add rate limits, request auditing, replay protection, and anomaly alerts on the billing service.
  8. Avoid using "anonymous_user" as a billable fallback; require a validated user identity before attempting a charge.
  9. Add automated secret scanning to release and CI pipelines.

other

Warning
Location
scripts/whale_tracker.py:76
Finding

Wallet Tracking Generates Fabricated Transaction and Balance Data

Content
View full analysis

Vulnerability Details

File Location: scripts/whale_tracker.py, lines 76-113 and 118-150
Vulnerability Type: Fabricated financial monitoring data
Risk Level: Medium

Vulnerable Code

python
def fetch_transactions(self, address: str, days: int = 7) -> List[Transaction]:
    """获取交易历史(模拟数据)"""
    import random
    
    transactions = []
    base_time = datetime.now() - timedelta(days=days)
    
    tokens = ['ETH', 'USDC', 'USDT', 'WBTC', 'LINK']
    
    # 生成10-30笔交易
    for i in range(random.randint(10, 30)):
        tx_time = base_time + timedelta(hours=random.uniform(0, days * 24))
        
        token = random.choice(tokens)
        
        # 生成价值
        if token == 'ETH':
            value = random.uniform(10, 5000)
        elif token in ['USDC', 'USDT']:
            value = random.uniform(10000, 5000000)
        elif token == 'WBTC':
            value = random.uniform(1, 100)
        else:
            value = random.uniform(100, 50000)
        
        tx = Transaction(
            hash=f"0x{''.join([random.choice('0123456789abcdef') for _ in range(64)])}",
            timestamp=tx_time,
            from_addr=address if random.random() > 0.5 else f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}",
            to_addr=f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}" if random.random() > 0.5 else address,
            value=value,
            token=token,
            gas_price=random.uniform(10, 100),
            gas_used=random.randint(21000, 200000)
        )
        
        transactions.append(tx)
    
    transactions.sort(key=lambda x: x.timestamp, reverse=True)
    return transactions
python
def analyze_wallet(self, address: str, days: int = 30) -> WalletProfile:
    """分析钱包"""
    address = address.lower()
    
    if address not in self.wallets:
        self.add_wallet(a
...[truncated 2553 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace random generation with authenticated blockchain API or RPC queries.
  2. Validate chain identifiers, wallet-address formats, API responses, token decimals, pagination, and finality.
  3. Attach the data source, chain, block range, retrieval time, and confirmation status to every result.
  4. Keep demo data in a separate fixture or test module that cannot be selected accidentally in production.
  5. Add an explicit --demo flag and visibly mark every simulated output as synthetic.
  6. Prevent simulated records from being exported as production reports.
  7. Import dependencies at module scope and add tests that execute every analysis path.
  8. Compare sampled API results against a block explorer before release.

other

Warning
Location
scripts/transfer_monitor.py:87
Finding

Transfer Monitor Generates and Alerts on Random Transfers

Content
View full analysis

Vulnerability Details

File Location: scripts/transfer_monitor.py, lines 87-115 and 181-199
Vulnerability Type: Fabricated real-time transfer alerts
Risk Level: Medium

Vulnerable Code

python
def fetch_recent_transfers(self, token: str = 'ETH', hours: int = 1) -> List[Dict]:
    """获取最近转账(模拟数据)"""
    import random
    
    transfers = []
    base_time = datetime.now() - timedelta(hours=hours)
    
    # 生成5-20笔转账
    for i in range(random.randint(5, 20)):
        tx_time = base_time + timedelta(minutes=random.uniform(0, hours * 60))
        
        # 生成随机价值(大部分小额,少数大额)
        if token == 'ETH':
            value = random.expovariate(1/500)
        elif token in ['USDC', 'USDT']:
            value = random.expovariate(1/500000)
        else:
            value = random.expovariate(1/1000)
        
        transfers.append({
            'timestamp': tx_time,
            'from': f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}",
            'to': f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}",
            'value': value,
            'token': token,
            'hash': f"0x{''.join([random.choice('0123456789abcdef') for _ in range(64)])}"
        })
    
    return transfers
python
def monitor_once(self, tokens: Optional[List[str]] = None):
    """单次监控"""
    if tokens is None:
        tokens = ['ETH', 'USDC', 'USDT']
    
    logger.info(f"🔍 开始监控... 代币: {tokens}")
    
    all_alerts = []
    
    for token in tokens:
        transfers = self.fetch_recent_transfers(token, hours=1)
        
        for transfer in transfers:
            alert = self.process_transfer(transfer)
            if alert:
                all_alerts.append(alert)
                self.trigger_alert(alert)
    
    all_alerts.sort(key=lambda x: x.timestamp, reverse=True)
    
    logger.info(f"✅ 监控完成,发现
...[truncated 1815 chars]
Remediation
View remediation

Remediation Suggestions

  1. Retrieve transfers from an appropriate indexed API, node, or event subscription.
  2. Verify transaction hashes and block inclusion before generating alerts.
  3. Deduplicate events using chain ID and transaction or log identifiers.
  4. Separate simulation from production code and require an explicit demo mode.
  5. Prefix all demo notifications with an unmistakable SIMULATED label.
  6. Disable external notification handlers automatically while simulation mode is active unless the user explicitly opts in.
  7. Include source endpoint, block number, confirmation count, and chain name in each alert.
  8. Add integration tests using fixed blockchain fixtures instead of nondeterministic random data.

other

Warning
Location
scripts/exchange_flow.py:101
Finding

Exchange Flow Analysis Produces Random Market Signals

Content
View full analysis

Vulnerability Details

File Location: scripts/exchange_flow.py, lines 101-151
Vulnerability Type: Fabricated exchange-flow intelligence
Risk Level: Medium

Vulnerable Code

python
def fetch_flow_data(self, exchange: str, hours: int = 24) -> List[FlowRecord]:
    """获取资金流向数据(模拟)"""
    import random
    
    records = []
    base_time = datetime.now() - timedelta(hours=hours)
    
    exchange_info = self.exchange_addresses.get(exchange)
    if not exchange_info:
        return records
    
    # 生成10-30笔流向记录
    tokens = ['ETH', 'BTC', 'USDT', 'USDC']
    
    for i in range(random.randint(10, 30)):
        tx_time = base_time + timedelta(minutes=random.uniform(0, hours * 60))
        
        token = random.choice(tokens)
        flow_type = random.choice([FlowType.INFLOW, FlowType.OUTFLOW])
        
        if token in ['ETH']:
            amount = random.uniform(100, 5000)
            price = 3500
        elif token in ['BTC', 'WBTC']:
            amount = random.uniform(10, 200)
            price = 65000
        else:
            amount = random.uniform(100000, 10000000)
            price = 1
        
        usd_value = amount * price
        
        if flow_type == FlowType.INFLOW:
            from_addr = f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}"
            to_addr = random.choice(exchange_info['addresses'])
        else:
            from_addr = random.choice(exchange_info['addresses'])
            to_addr = f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}"
        
        record = FlowRecord(
            timestamp=tx_time,
            exchange=exchange_info['name'],
            flow_type=flow_type,
            token=token,
            amount=amount,
            usd_value=usd_value,
            tx_hash=f"0x{''.join([random.choice('0123456789abcdef') for _ in range(64)])}",
    
...[truncated 1499 chars]
Remediation
View remediation

Remediation Suggestions

  1. Derive exchange flows from verified on-chain transfers involving maintained exchange-address datasets.
  2. Record the chain, block number, transaction hash, token contract, token decimals, and data source.
  3. Verify and regularly update exchange-address ownership labels.
  4. Replace fixed prices with timestamped pricing data from a documented source.
  5. Clearly distinguish raw observations from speculative market interpretation.
  6. Move random data generation into isolated test fixtures.
  7. Prevent production reports and daemon logs from presenting simulated records as live events.
  8. Add deterministic tests for flow direction and aggregation calculations.

other

Warning
Location
scripts/holding_analyzer.py:71
Finding

Holding and Profit Analysis Is Based on Random Trades and Artificial Profit Assumptions

Content
View full analysis

Vulnerability Details

File Location: scripts/holding_analyzer.py, lines 71-103 and 144-164
Vulnerability Type: Fabricated holdings and profit-and-loss calculations
Risk Level: Medium

Vulnerable Code

python
def fetch_trade_history(self, address: str, days: int = 30) -> List[Trade]:
    """获取交易历史(模拟)"""
    import random
    
    trades = []
    base_time = datetime.now() - timedelta(days=days)
    
    tokens = ['ETH', 'LINK', 'UNI', 'AAVE']
    
    for i in range(random.randint(20, 50)):
        trade_time = base_time + timedelta(hours=random.uniform(0, days * 24))
        
        token = random.choice(tokens)
        action = random.choice(['buy', 'sell'])
        
        base_price = self.get_token_price(token)
        # 模拟历史价格(有波动)
        price = base_price * random.uniform(0.7, 1.3)
        amount = random.uniform(10, 1000)
        
        trade = Trade(
            timestamp=trade_time,
            token=token,
            action=action,
            amount=amount,
            price=price,
            value=amount * price
        )
        
        trades.append(trade)
    
    trades.sort(key=lambda x: x.timestamp)
    return trades
python
def calculate_pnl_history(self, trades: List[Trade]) -> List[Dict]:
    """计算PnL历史"""
    history = []
    running_pnl = 0
    
    daily_pnl = defaultdict(float)
    
    for trade in trades:
        if trade.action == 'sell':
            # 简化为卖出一律盈利(实际应该计算成本)
            daily_pnl[trade.timestamp.date()] += trade.value * 0.1
    
    for date, pnl in sorted(daily_pnl.items()):
        running_pnl += pnl
        history.append({
            'date': date.isoformat(),
            'daily_pnl': pnl,
            'cumulative_pnl': running_pnl
        })
    
    return history

Technical Analysis

The analyzer does not retrieve the supplied address's trad ...[truncated 1353 chars]

Remediation
View remediation

Remediation Suggestions

  1. Retrieve verified wallet transfers, swaps, and token balances from appropriate chain data sources.
  2. Identify trades from decoded protocol events rather than assuming every transfer is a purchase or sale.
  3. Use timestamped market prices and document the pricing source.
  4. Implement a recognized cost-basis method such as FIFO, LIFO, or specific identification.
  5. Account for fees, token decimals, internal transactions, wrapped assets, bridging, and liquidity operations.
  6. Clearly separate realized and unrealized profit and loss.
  7. Remove the fixed ten-percent profit assumption.
  8. Place simulated trades in deterministic test fixtures and label demo reports prominently.
  9. Add reconciliation tests against known wallet histories before presenting results as production analysis.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (53)

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · payment.py (reported line 29)May include surrounding context.

python
def check_balance(user_id: str) -> float:
    """查询用户余额"""
    try:
        resp = requests.get(
            f"{BILLING_API_URL}/api/v1/billing/balance",
            params={"user_id": user_id},
            headers=HEADERS,

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
98% confidence
Finding

The code automatically charges whatever account is identified by SKILLPAY_USER_ID from the environment, without independently authenticating that the runtime value belongs to the current user or obtaining just-in-time consent. If an attacker or misconfigured runtime can set or influence this environment variable, charges could be applied to the wrong account, creating unauthorized billing and account abuse.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/alert_manager.py (reported line 141)May include surrounding context.

python
str, data: Optional[Dict]):
        """控制台通知"""
        print(f"\n{'='*80}")
        print(f"🚨 预警通知")
        print(f"{'='*80}")
        print(message)
        if data:
            print(f"\n数据: {json.dumps(data, indent=2)}")
        print(f"{'='*80}\n")
    
    def _send_telegram(self, message: str, data: Optional[Dict]):
        """Telegram通知"""
        bot_token = os.getenv('TELEGRAM_BOT_TOKEN')
        chat_id = os.getenv('TELEGRAM_CHAT_ID')
        
        if not bot_token or not chat_id:
            logger.warning("Telegram配置缺失")
            return
        
        try:
            url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
            payload = {
                'chat_id': chat_id,
                'text': message,
                'parse_mode': 'Markdown'
            }
            
            response = requests.post(url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅

Tainted flow: 'url' from os.getenv (line 149, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 156)May include surrounding context.

python
'parse_mode': 'Markdown'
            }
            
            response = requests.post(url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅ Telegram通知已发送")
            else:

Tainted flow: 'webhook_url' from os.getenv (line 200, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The Discord destination is taken directly from the DISCORD_WEBHOOK_URL environment variable and used for outbound POST requests. If that environment variable is misconfigured or maliciously set, alert contents can be silently sent to an attacker-controlled endpoint, creating an exfiltration path for monitored transaction data.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 190)May include surrounding context.

python
'embeds': [embed]
            }
            
            response = requests.post(webhook_url, json=payload, timeout=10)
            if response.status_code == 204:
                logger.info("✅ Discord通知已发送")
            else:

Tainted flow: 'webhook_url' from os.getenv (line 200, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The custom webhook feature posts message and data to whatever URL is provided in CUSTOM_WEBHOOK_URL without any validation. In an agent/skill context, this creates a generic exfiltration channel to arbitrary external infrastructure, which is especially risky because the payload may include operational or user-derived alert data.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 213)May include surrounding context.

python
'timestamp': datetime.now().isoformat()
            }
            
            response = requests.post(webhook_url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅ Webhook通知已发送")
        except Exception as e:

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description suggests robust tracking of whales and exchange flows, but the reported implementation uses random/mock data, no real-time alerting, and simplistic hardcoded-address heuristics. In this context, overclaiming analytical precision is harmful because users may rely on inaccurate outputs for trading, alerting, or compliance-like monitoring decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description suggests robust tracking of whales and exchange flows, but the reported implementation uses random/mock data, no real-time alerting, and simplistic hardcoded-address heuristics. In this context, overclaiming analytical precision is harmful because users may rely on inaccurate outputs for trading, alerting, or compliance-like monitoring decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill description suggests robust tracking of whales and exchange flows, but the reported implementation uses random/mock data, no real-time alerting, and simplistic hardcoded-address heuristics. In this context, overclaiming analytical precision is harmful because users may rely on inaccurate outputs for trading, alerting, or compliance-like monitoring decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill description suggests robust tracking of whales and exchange flows, but the reported implementation uses random/mock data, no real-time alerting, and simplistic hardcoded-address heuristics. In this context, overclaiming analytical precision is harmful because users may rely on inaccurate outputs for trading, alerting, or compliance-like monitoring decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill description suggests robust tracking of whales and exchange flows, but the reported implementation uses random/mock data, no real-time alerting, and simplistic hardcoded-address heuristics. In this context, overclaiming analytical precision is harmful because users may rely on inaccurate outputs for trading, alerting, or compliance-like monitoring decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description suggests robust tracking of whales and exchange flows, but the reported implementation uses random/mock data, no real-time alerting, and simplistic hardcoded-address heuristics. In this context, overclaiming analytical precision is harmful because users may rely on inaccurate outputs for trading, alerting, or compliance-like monitoring decisions.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-configuration.md (reported line 158)May include surrounding context.

环境变量配置

.env 文件

bash
# Etherscan
ETHERSCAN_API_KEY=xxx

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring claims it monitors large on-chain transfers and sends alerts, but the implementation does not do that and instead produces fabricated activity. In the context of a crypto-alert skill with SkillPay enabled, this mismatch is dangerous because it misrepresents core functionality and can mislead users into trusting nonexistent monitoring coverage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This is a real integrity/security issue because the skill advertises real on-chain whale monitoring but instead fabricates random transfer events. In a paid financial-monitoring context, users could make trading or risk decisions based on false alerts, making this deceptive behavior materially harmful even without code execution or data exfiltration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module presents itself as a whale tracker, but the core implementation never performs real tracking and instead generates random transactions. This mismatch is security-relevant because the skill is marketed for monitoring large-wallet behavior, so the deceptive functionality can mislead users into trusting fake intelligence in a financial context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill description promises whale movement tracking, alerts, and exchange flow analysis, yet the code only performs local random-data generation and contains no real chain integration or alert pipeline. In the context of a paid crypto-monitoring skill, this is especially dangerous because it can induce reliance on false market signals and constitutes deceptive security/financial functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README presents the primary skill description in Chinese, which can impose a language constraint on users without any opt-in or explanation that the skill is intended for a Chinese-speaking audience. The policy requires either offering a language choice or clearly documenting and justifying the locale limitation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The manifest declares no explicit tool scope or permissions even though the associated skill behavior reportedly uses environment access, local file read/write, and network capabilities. This is dangerous because users and hosting systems cannot accurately evaluate what the skill may access, and hidden capability expansion increases the risk of data exfiltration, unauthorized persistence, or unexpected external communication.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says the skill is used '当你想追踪聪明钱的每一步,监测大户交易行为时' ('when you want to track smart money's every move or monitor large-holder trading behavior'), which is a broad natural-language activation description rather than a narrow, specific trigger. The file does not provide explicit trigger phrases, boundaries, or negative examples to clarify when the skill should or should not be invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The repeated usage guidance describes activation in broad terms such as wanting to track 'smart money' or monitor large traders, without narrowing context or defining clear criteria. In a markdown skill description, this can overlap with loosely related market-analysis requests and increase accidental invocation risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is almost entirely dedicated to payment enforcement even though the advertised skill purpose is whale-tracking analytics. This mismatch increases supply-chain and trust risk because users invoking an analytics skill may not expect automatic billing logic or third-party payment interactions embedded in the skill code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This sends billing data, including user_id, skill_id, amount, and an API-key-authenticated charge request, to an external service. In the context of a whale-tracking skill, this third-party transmission is more sensitive because it is unrelated to the core analytics purpose and can result in unauthorized financial actions if identity or invocation is abused.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

Static analysis

No suspicious patterns detected.