Back to skill

Security audit

Whale Alert Monitor 大户监控

Security checks for vulnerabilities and agentic risk

Overview

The skill is presented as real cryptocurrency whale monitoring, but its normal scripts generate simulated financial data and include risky direct billing code with an exposed API key.

Review carefully before installing. Do not rely on this skill for trading, compliance, or alerting decisions unless the mock-data paths are replaced with verified blockchain data sources and outputs clearly show provenance. Rotate the exposed SkillPay key, remove direct billing from package code or gate it through a trusted platform flow, and only enable Telegram, Discord, or custom webhooks if you are comfortable sending alert contents to those destinations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
payment.py:11
Finding

Hard-Coded Billing API Credential Exposed in Source Code

Content
View full analysis
Remediation
View remediation

other

Error
Location
scripts/transfer_monitor.py:87
Finding

Synthetic Transfers Are Presented and Distributed as Real Whale Alerts

Content
View full analysis
List[Dict]: """获取最近转账(模拟数据)""" import random transfers = [] base_time = datetime.now() - timedelta(hours=hours) # 生成5-20笔转账 for i in range(random.randint(5, 20)): tx_time = base_time + timedelta(minutes=random.uniform(0, hours * 60)) # 生成随机价值(大部分小额,少数大额) if token == 'ETH': value = random.expovariate(1/500) # 指数分布 elif token in ['USDC', 'USDT']: value = random.expovariate(1/500000) else: value = random.expovariate(1/1000) transfers.append({ 'timestamp': tx_time, 'from': f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}", 'to': f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}", 'value': value, 'token': token, 'hash': f"0x{''.join([random.choice('0123456789abcdef') for _ in range(64)])}" }) return transfers ``` The generated records are consumed as monitoring results at `scripts/transfer_monitor.py:186-196`: ```python for token in tokens: transfers = self.fetch_recent_transfers(token, hours=1) for transfer in transfers: alert = self.process_transfer(transfer) if alert: all_alerts.append(alert) self.trigger_alert(alert) ``` ### Technical Analysis The transfer-fetching routine does not contact a blockchain node, explorer, or indexed data provider. It creates random addresses, transaction hashes, timestamps, and transfer values. These records are then processed under the same alert thresholds as genuine transfers. When the daemon is used, generated alerts are forwarded to `Al ...[truncated 1393 chars]
Remediation
View remediation

other

Error
Location
scripts/whale_tracker.py:67
Finding

Random Wallet Activity and Balances Are Reported as Real Wallet Analysis

Content
View full analysis
List[Transaction]: """获取交易历史(模拟数据)""" import random transactions = [] base_time = datetime.now() - timedelta(days=days) tokens = ['ETH', 'USDC', 'USDT', 'WBTC', 'LINK'] # 生成10-30笔交易 for i in range(random.randint(10, 30)): tx_time = base_time + timedelta(hours=random.uniform(0, days * 24)) token = random.choice(tokens) # 生成价值 if token == 'ETH': value = random.uniform(10, 5000) elif token in ['USDC', 'USDT']: value = random.uniform(10000, 5000000) elif token == 'WBTC': value = random.uniform(1, 100) else: value = random.uniform(100, 50000) tx = Transaction( hash=f"0x{''.join([random.choice('0123456789abcdef') for _ in range(64)])}", timestamp=tx_time, from_addr=address if random.random() > 0.5 else f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}", to_addr=f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}" if random.random() > 0.5 else address, value=value, token=token, gas_price=random.uniform(10, 100), gas_used=random.randint(21000, 200000) ) transactions.append(tx) # 按时间排序 transactions.sort(key=lambda x: x.timestamp, reverse=True) return transactions ``` The wallet balance is independently fabricated: ```python # 获取交易 transactions = self.fetch_transactions(address, days) profile.transaction_history = transactions profile.total_transactions = len(transactions) if transactions: profile.first_seen = min(t.timestamp for t in transactions) ...[truncated 1538 chars]
Remediation
View remediation

other

Error
Location
scripts/exchange_flow.py:94
Finding

Random Exchange Flows Are Presented as Market Signals

Content
View full analysis
List[FlowRecord]: """获取资金流向数据(模拟)""" import random records = [] base_time = datetime.now() - timedelta(hours=hours) exchange_info = self.exchange_addresses.get(exchange) if not exchange_info: return records # 生成10-30笔流向记录 tokens = ['ETH', 'BTC', 'USDT', 'USDC'] for i in range(random.randint(10, 30)): tx_time = base_time + timedelta(minutes=random.uniform(0, hours * 60)) token = random.choice(tokens) flow_type = random.choice([FlowType.INFLOW, FlowType.OUTFLOW]) # 生成金额 if token in ['ETH']: amount = random.uniform(100, 5000) price = 3500 elif token in ['BTC', 'WBTC']: amount = random.uniform(10, 200) price = 65000 else: amount = random.uniform(100000, 10000000) price = 1 usd_value = amount * price if flow_type == FlowType.INFLOW: from_addr = f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}" to_addr = random.choice(exchange_info['addresses']) else: from_addr = random.choice(exchange_info['addresses']) to_addr = f"0x{''.join([random.choice('0123456789abcdef') for _ in range(40)])}" record = FlowRecord( timestamp=tx_time, exchange=exchange_info['name'], flow_type=flow_type, token=token, amount=amount, usd_value=usd_value, tx_hash=f"0x{''.join([random.choice('0123456789abcdef') for _ in range(64)])}", from_addr=from_addr, to_addr=to_addr ) records.a ...[truncated 1506 chars]
Remediation
View remediation

other

Error
Location
scripts/holding_analyzer.py:53
Finding

Random Trades and Artificial Profit Calculations Are Reported as Wallet Holdings

Content
View full analysis
float: """获取代币价格(简化版)""" if token not in self.price_cache: # 模拟价格 prices = { 'ETH': 3500, 'BTC': 65000, 'WBTC': 65000, 'USDC': 1, 'USDT': 1, 'LINK': 18, 'UNI': 12, 'AAVE': 145 } self.price_cache[token] = prices.get(token, 1) return self.price_cache[token] ``` The trade history is randomly generated: ```python def fetch_trade_history(self, address: str, days: int = 30) -> List[Trade]: """获取交易历史(模拟)""" import random trades = [] base_time = datetime.now() - timedelta(days=days) tokens = ['ETH', 'LINK', 'UNI', 'AAVE'] for i in range(random.randint(20, 50)): trade_time = base_time + timedelta(hours=random.uniform(0, days * 24)) token = random.choice(tokens) action = random.choice(['buy', 'sell']) base_price = self.get_token_price(token) # 模拟历史价格(有波动) price = base_price * random.uniform(0.7, 1.3) amount = random.uniform(10, 1000) trade = Trade( timestamp=trade_time, token=token, action=action, amount=amount, price=price, value=amount * price ) trades.append(trade) # 按时间排序 trades.sort(key=lambda x: x.timestamp) return trades ``` Every generated sale is also treated as a ten-percent realized profit: ```python for trade in trades: if trade.action == 'sell': # 简化为卖出一律盈利(实际应该计算成本) daily_pnl[trade.timestamp.date()] += trade.value * 0.1 ``` ### Technical Anal ...[truncated 1556 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (47)

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · payment.py (reported line 29)May include surrounding context.

python
def check_balance(user_id: str) -> float:
    """查询用户余额"""
    try:
        resp = requests.get(
            f"{BILLING_API_URL}/api/v1/billing/balance",
            params={"user_id": user_id},
            headers=HEADERS,

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
98% confidence
Finding

The code transmits an environment-derived user identifier to a third-party billing endpoint and immediately attempts to charge that identity. In this skill context, payment enforcement is unrelated to whale-wallet monitoring and can cause unauthorized billing, privacy leakage, and unexpected monetization of skill use.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The function sends an environment-derived user identifier to an external payment-link service, exposing billing identity to a third party. In a wallet-monitoring skill this is unnecessary to the declared functionality and expands data sharing and monetization behavior beyond user expectations.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/alert_manager.py (reported line 141)May include surrounding context.

python
str, data: Optional[Dict]):
        """控制台通知"""
        print(f"\n{'='*80}")
        print(f"🚨 预警通知")
        print(f"{'='*80}")
        print(message)
        if data:
            print(f"\n数据: {json.dumps(data, indent=2)}")
        print(f"{'='*80}\n")
    
    def _send_telegram(self, message: str, data: Optional[Dict]):
        """Telegram通知"""
        bot_token = os.getenv('TELEGRAM_BOT_TOKEN')
        chat_id = os.getenv('TELEGRAM_CHAT_ID')
        
        if not bot_token or not chat_id:
            logger.warning("Telegram配置缺失")
            return
        
        try:
            url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
            payload = {
                'chat_id': chat_id,
                'text': message,
                'parse_mode': 'Markdown'
            }
            
            response = requests.post(url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅

Tainted flow: 'url' from os.getenv (line 149, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 156)May include surrounding context.

python
'parse_mode': 'Markdown'
            }
            
            response = requests.post(url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅ Telegram通知已发送")
            else:

Tainted flow: 'webhook_url' from os.getenv (line 200, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The code reads DISCORD_WEBHOOK_URL from the environment and sends alert message/data directly to that external endpoint with no validation or allowlisting. If the environment variable is misconfigured, maliciously injected, or points to an unexpected destination, potentially sensitive wallet-monitoring data can be exfiltrated to an attacker-controlled server.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 190)May include surrounding context.

python
'embeds': [embed]
            }
            
            response = requests.post(webhook_url, json=payload, timeout=10)
            if response.status_code == 204:
                logger.info("✅ Discord通知已发送")
            else:

Tainted flow: 'webhook_url' from os.getenv (line 200, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The custom webhook sender transmits message and structured data to a URL taken directly from CUSTOM_WEBHOOK_URL without validation, authentication policy checks, or destination restrictions. This creates a straightforward exfiltration channel for monitored transaction data and any future sensitive fields included in alerts if an attacker can influence configuration or deployment environment.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 213)May include surrounding context.

python
'timestamp': datetime.now().isoformat()
            }
            
            response = requests.post(webhook_url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅ Webhook通知已发送")
        except Exception as e:

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description says it is a whale-monitoring assistant, but the content also introduces an external paid SkillPay flow with per-call charging and balance requirements that are unrelated to the declared monitoring purpose. Hidden or under-declared billing behavior is dangerous because it can trigger financial transactions, collect payment-related data, or gate functionality in ways the user and reviewer did not consent to.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements full payment enforcement for a skill whose stated purpose is whale-wallet monitoring, creating a clear mismatch between advertised behavior and actual execution. This is dangerous because users or reviewers may approve the skill for analytics functionality while it performs unrelated billing actions and external data transmission.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-configuration.md (reported line 158)May include surrounding context.

环境变量配置

.env 文件

bash
# Etherscan
ETHERSCAN_API_KEY=xxx

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file-level description claims to track real whale-wallet activity, but the implementation only generates mock transactions. This deceptive mismatch is dangerous in the skill context because users expect actionable real-time financial intelligence, not synthetic data masquerading as real monitoring.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function advertised as fetching wallet transactions fabricates random blockchain activity instead of retrieving real on-chain data. In a crypto-monitoring skill, this can mislead users into making trading, compliance, or alerting decisions based on false information, which is a substantive integrity and trust failure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises executable scripts, configuration files with secrets, API usage, and notification/webhook features, but does not declare any tool scope such as permissions or allowed-tools. That creates an overbroad and ambiguous execution model where file, environment, and network access may be used without explicit review, increasing the chance of unintended data exposure or external actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and invocation guidance are entirely in Chinese, and the file does not indicate that users may interact in other languages or choose a locale. Under the policy, language constraints should be opt-in or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The metadata declares payment credential environment variables and mandatory billing despite the skill’s stated purpose being whale-wallet monitoring. Even if used for legitimate monetization, introducing API-key handling expands the attack surface and creates a pathway for sensitive credential misuse or confused-deputy behavior if the runtime exposes those secrets to skill logic or logs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level natural-language description is written in Chinese and presents the skill as such without any indication that language selection is optional. The policy explicitly flags language or locale constraints when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This external transmission sends billing data to a third-party charge endpoint and triggers a debit operation. Because the skill's declared purpose is unrelated to payments, the transmission is more dangerous: it represents undisclosed monetization and privacy-relevant data sharing during normal skill execution.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This outbound request shares user billing identity with an external payment-link endpoint. In a non-billing-focused skill, such transmission is unexpected and increases privacy and trust risks even if the endpoint is legitimate.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill derives billing identity from an environment variable and uses it to charge or create payment links. In this context, that creates a risk of misbinding charges to the wrong user, silent identity propagation, and abuse if the environment value is injected or shared across sessions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docstring claims the function only verifies whether the user has paid, but the implementation actually calls charge_user and debits the account. This misleading interface increases the chance that callers invoke it assuming a safe check, resulting in accidental or repeated charges.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-configuration.md (reported line 8)May include surrounding context.

基础配置

python
ETHERSCAN_API_KEY = "YourApiKey"
BASE_URL = "https://api.etherscan.io/api"

常用端点

Static analysis

No suspicious patterns detected.