T09 · Insecure Skill Coding Practices
- Location
payment.py:11- Finding
Hard-Coded Billing API Credential Exposed in Source Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is presented as real cryptocurrency whale monitoring, but its normal scripts generate simulated financial data and include risky direct billing code with an exposed API key.
Review carefully before installing. Do not rely on this skill for trading, compliance, or alerting decisions unless the mock-data paths are replaced with verified blockchain data sources and outputs clearly show provenance. Rotate the exposed SkillPay key, remove direct billing from package code or gate it through a trusted platform flow, and only enable Telegram, Discord, or custom webhooks if you are comfortable sending alert contents to those destinations.
payment.py:11Hard-Coded Billing API Credential Exposed in Source Code
scripts/transfer_monitor.py:87Synthetic Transfers Are Presented and Distributed as Real Whale Alerts
scripts/whale_tracker.py:67Random Wallet Activity and Balances Are Reported as Real Wallet Analysis
scripts/exchange_flow.py:94Random Exchange Flows Are Presented as Market Signals
scripts/holding_analyzer.py:53Random Trades and Artificial Profit Calculations Are Reported as Wallet Holdings
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
def check_balance(user_id: str) -> float:
"""查询用户余额"""
try:
resp = requests.get(
f"{BILLING_API_URL}/api/v1/billing/balance",
params={"user_id": user_id},
headers=HEADERS,
The code transmits an environment-derived user identifier to a third-party billing endpoint and immediately attempts to charge that identity. In this skill context, payment enforcement is unrelated to whale-wallet monitoring and can cause unauthorized billing, privacy leakage, and unexpected monetization of skill use.
返回: {"ok": bool, "balance": float, "payment_url": str|None}
"""
try:
resp = requests.post(
f"{BILLING_API_URL}/api/v1/billing/charge",
headers=HEADERS,
json={
The function sends an environment-derived user identifier to an external payment-link service, exposing billing identity to a third party. In a wallet-monitoring skill this is unnecessary to the declared functionality and expands data sharing and monetization behavior beyond user expectations.
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
"""生成充值链接"""
try:
resp = requests.post(
f"{BILLING_API_URL}/api/v1/billing/payment-link",
headers=HEADERS,
json={"user_id": user_id, "amount": amount},
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
str, data: Optional[Dict]):
"""控制台通知"""
print(f"\n{'='*80}")
print(f"🚨 预警通知")
print(f"{'='*80}")
print(message)
if data:
print(f"\n数据: {json.dumps(data, indent=2)}")
print(f"{'='*80}\n")
def _send_telegram(self, message: str, data: Optional[Dict]):
"""Telegram通知"""
bot_token = os.getenv('TELEGRAM_BOT_TOKEN')
chat_id = os.getenv('TELEGRAM_CHAT_ID')
if not bot_token or not chat_id:
logger.warning("Telegram配置缺失")
return
try:
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
payload = {
'chat_id': chat_id,
'text': message,
'parse_mode': 'Markdown'
}
response = requests.post(url, json=payload, timeout=10)
if response.status_code == 200:
logger.info("✅
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
'parse_mode': 'Markdown'
}
response = requests.post(url, json=payload, timeout=10)
if response.status_code == 200:
logger.info("✅ Telegram通知已发送")
else:
The code reads DISCORD_WEBHOOK_URL from the environment and sends alert message/data directly to that external endpoint with no validation or allowlisting. If the environment variable is misconfigured, maliciously injected, or points to an unexpected destination, potentially sensitive wallet-monitoring data can be exfiltrated to an attacker-controlled server.
'embeds': [embed]
}
response = requests.post(webhook_url, json=payload, timeout=10)
if response.status_code == 204:
logger.info("✅ Discord通知已发送")
else:
The custom webhook sender transmits message and structured data to a URL taken directly from CUSTOM_WEBHOOK_URL without validation, authentication policy checks, or destination restrictions. This creates a straightforward exfiltration channel for monitored transaction data and any future sensitive fields included in alerts if an attacker can influence configuration or deployment environment.
'timestamp': datetime.now().isoformat()
}
response = requests.post(webhook_url, json=payload, timeout=10)
if response.status_code == 200:
logger.info("✅ Webhook通知已发送")
except Exception as e:
The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.
The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.
The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.
The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.
The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.
The file implements full payment enforcement for a skill whose stated purpose is whale-wallet monitoring, creating a clear mismatch between advertised behavior and actual execution. This is dangerous because users or reviewers may approve the skill for analytics functionality while it performs unrelated billing actions and external data transmission.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Etherscan
ETHERSCAN_API_KEY=xxx
The file-level description claims to track real whale-wallet activity, but the implementation only generates mock transactions. This deceptive mismatch is dangerous in the skill context because users expect actionable real-time financial intelligence, not synthetic data masquerading as real monitoring.
The function advertised as fetching wallet transactions fabricates random blockchain activity instead of retrieving real on-chain data. In a crypto-monitoring skill, this can mislead users into making trading, compliance, or alerting decisions based on false information, which is a substantive integrity and trust failure.
The skill advertises executable scripts, configuration files with secrets, API usage, and notification/webhook features, but does not declare any tool scope such as permissions or allowed-tools. That creates an overbroad and ambiguous execution model where file, environment, and network access may be used without explicit review, increasing the chance of unintended data exposure or external actions.
The manifest description and invocation guidance are entirely in Chinese, and the file does not indicate that users may interact in other languages or choose a locale. Under the policy, language constraints should be opt-in or clearly justified as region-specific.
The metadata declares payment credential environment variables and mandatory billing despite the skill’s stated purpose being whale-wallet monitoring. Even if used for legitimate monetization, introducing API-key handling expands the attack surface and creates a pathway for sensitive credential misuse or confused-deputy behavior if the runtime exposes those secrets to skill logic or logs.
The top-level natural-language description is written in Chinese and presents the skill as such without any indication that language selection is optional. The policy explicitly flags language or locale constraints when a skill forces a specific language without user opt-in.
This external transmission sends billing data to a third-party charge endpoint and triggers a debit operation. Because the skill's declared purpose is unrelated to payments, the transmission is more dangerous: it represents undisclosed monetization and privacy-relevant data sharing during normal skill execution.
返回: {"ok": bool, "balance": float, "payment_url": str|None}
"""
try:
resp = requests.post(
f"{BILLING_API_URL}/api/v1/billing/charge",
headers=HEADERS,
json={
This outbound request shares user billing identity with an external payment-link endpoint. In a non-billing-focused skill, such transmission is unexpected and increases privacy and trust risks even if the endpoint is legitimate.
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
"""生成充值链接"""
try:
resp = requests.post(
f"{BILLING_API_URL}/api/v1/billing/payment-link",
headers=HEADERS,
json={"user_id": user_id, "amount": amount},
The skill derives billing identity from an environment variable and uses it to charge or create payment links. In this context, that creates a risk of misbinding charges to the wrong user, silent identity propagation, and abuse if the environment value is injected or shared across sessions.
The docstring claims the function only verifies whether the user has paid, but the implementation actually calls charge_user and debits the account. This misleading interface increases the chance that callers invoke it assuming a safe check, resulting in accidental or repeated charges.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
ETHERSCAN_API_KEY = "YourApiKey"
BASE_URL = "https://api.etherscan.io/api"
No suspicious patterns detected.