Back to skill

Security audit

Whale Alert Monitor 鲸鱼监控

Security checks for vulnerabilities and agentic risk

Overview

This paid crypto-monitoring skill needs review because it claims real whale and exchange monitoring but its core data generators are simulated, and it ships risky billing and webhook code.

Install only if you are comfortable reviewing and fixing it first: treat the monitoring results as simulated until real data ingestion is implemented, rotate/remove the embedded SkillPay key, require explicit billing consent, and restrict webhook destinations before using it with real accounts or financial decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
payment.py:11
Finding

Hard-Coded SkillPay Billing API Credential

Content
View full analysis
float: """Query user balance.""" try: resp = requests.get( f"{BILLING_API_URL}/api/v1/billing/balance", params={"user_id": user_id}, headers=HEADERS, timeout=10 ) ``` ### Technical Analysis A secret-looking SkillPay API key is embedded directly in the distributed source code and automatically included in the `X-API-Key` header of billing requests. Anyone with access to the package can extract and reuse this credential independently of the Skill. This implementation contradicts `_meta.json:11-13`, which declares that the billing credential should be supplied through the `SKILLPAY_API_KEY` environment variable: ```json "payment": { "api_key_env": "SKILLPAY_API_KEY", "user_id_env": "SKILLPAY_USER_ID", "required": true } ``` Embedding a shared credential prevents meaningful per-deployment isolation and makes credential rotation difficult. Source-control history, package mirrors, logs, backups, and downstream copies may continue exposing the key even after the current file is changed. The key is transmitted only to the fixed HTTPS endpoint `https://skillpay.me` in the reviewed implementation; no evidence was found that it is deliberately exfiltrated elsewhere. Nevertheless, its publication makes unauthorized direct use possible. ### Attack Path 1. An attacker downloads or otherwise obtains the Skill package. 2. The attack ...[truncated 1059 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/alert_manager.py:198
Finding

Unrestricted Custom Webhook Enables Blind Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (51)

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · payment.py (reported line 29)May include surrounding context.

python
def check_balance(user_id: str) -> float:
    """查询用户余额"""
    try:
        resp = requests.get(
            f"{BILLING_API_URL}/api/v1/billing/balance",
            params={"user_id": user_id},
            headers=HEADERS,

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
98% confidence
Finding

The code automatically charges the user by sending a billing request using a user identity sourced from the environment, without verifying that the identity was securely bound to the current user session or that the user explicitly confirmed the charge at runtime. If an attacker or misconfigured host can set SKILLPAY_USER_ID, charges could be misattributed or triggered against the wrong account.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/alert_manager.py (reported line 141)May include surrounding context.

python
str, data: Optional[Dict]):
        """控制台通知"""
        print(f"\n{'='*80}")
        print(f"🚨 预警通知")
        print(f"{'='*80}")
        print(message)
        if data:
            print(f"\n数据: {json.dumps(data, indent=2)}")
        print(f"{'='*80}\n")
    
    def _send_telegram(self, message: str, data: Optional[Dict]):
        """Telegram通知"""
        bot_token = os.getenv('TELEGRAM_BOT_TOKEN')
        chat_id = os.getenv('TELEGRAM_CHAT_ID')
        
        if not bot_token or not chat_id:
            logger.warning("Telegram配置缺失")
            return
        
        try:
            url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
            payload = {
                'chat_id': chat_id,
                'text': message,
                'parse_mode': 'Markdown'
            }
            
            response = requests.post(url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅

Tainted flow: 'url' from os.getenv (line 149, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 156)May include surrounding context.

python
'parse_mode': 'Markdown'
            }
            
            response = requests.post(url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅ Telegram通知已发送")
            else:

Tainted flow: 'webhook_url' from os.getenv (line 200, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The skill posts alert content and structured data to a Discord webhook URL taken directly from an environment variable. Because webhook URLs are opaque bearer secrets and may point to any external endpoint controlled by whoever sets configuration, sensitive transaction-monitoring data can be sent off-platform without validation, allowlisting, or user-visible consent.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 190)May include surrounding context.

python
'embeds': [embed]
            }
            
            response = requests.post(webhook_url, json=payload, timeout=10)
            if response.status_code == 204:
                logger.info("✅ Discord通知已发送")
            else:

Tainted flow: 'webhook_url' from os.getenv (line 200, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The custom webhook sender transmits arbitrary alert messages and attached data to a fully configurable external URL from the environment. This creates a straightforward exfiltration path for monitored data, especially because there is no destination validation, no disclosure to the end user, and no filtering of potentially sensitive payload fields.

Content

Scanner excerpt · scripts/alert_manager.py (reported line 213)May include surrounding context.

python
'timestamp': datetime.now().isoformat()
            }
            
            response = requests.post(webhook_url, json=payload, timeout=10)
            if response.status_code == 200:
                logger.info("✅ Webhook通知已发送")
        except Exception as e:

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims real monitoring and alerts, yet the findings indicate simulated transaction data, only limited offline detection, minimal exchange-flow logic, and an undeclared JSON export capability. Hidden export functionality combined with overstated monitoring claims can create confidentiality concerns and deceptive reliance on non-production analytics.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims real monitoring and alerts, yet the findings indicate simulated transaction data, only limited offline detection, minimal exchange-flow logic, and an undeclared JSON export capability. Hidden export functionality combined with overstated monitoring claims can create confidentiality concerns and deceptive reliance on non-production analytics.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill claims real monitoring and alerts, yet the findings indicate simulated transaction data, only limited offline detection, minimal exchange-flow logic, and an undeclared JSON export capability. Hidden export functionality combined with overstated monitoring claims can create confidentiality concerns and deceptive reliance on non-production analytics.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill claims real monitoring and alerts, yet the findings indicate simulated transaction data, only limited offline detection, minimal exchange-flow logic, and an undeclared JSON export capability. Hidden export functionality combined with overstated monitoring claims can create confidentiality concerns and deceptive reliance on non-production analytics.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill claims real monitoring and alerts, yet the findings indicate simulated transaction data, only limited offline detection, minimal exchange-flow logic, and an undeclared JSON export capability. Hidden export functionality combined with overstated monitoring claims can create confidentiality concerns and deceptive reliance on non-production analytics.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims real monitoring and alerts, yet the findings indicate simulated transaction data, only limited offline detection, minimal exchange-flow logic, and an undeclared JSON export capability. Hidden export functionality combined with overstated monitoring claims can create confidentiality concerns and deceptive reliance on non-production analytics.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-configuration.md (reported line 158)May include surrounding context.

环境变量配置

.env 文件

bash
# Etherscan
ETHERSCAN_API_KEY=xxx

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill is marketed as monitoring real exchange fund flows, but its core collection routine generates fabricated random records instead of retrieving blockchain or exchange data. In a financial monitoring context, this can mislead users into making trading or risk decisions based on false signals, which is a security-relevant integrity failure rather than a harmless demo issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill advertises real on-chain whale tracking and exchange-flow analysis, but this code fabricates random transfer events instead of monitoring any blockchain source. In a paid monitoring skill, this is dangerous because users may make financial decisions based on fake alerts, creating a material integrity and trust failure rather than a harmless demo mismatch.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill claims to monitor whale activity and exchange flows, but the implementation generates random addresses, values, balances, and transaction patterns rather than analyzing blockchain state. In the context of cryptocurrency tracking, fabricated analytics can cause users to trust false alerts, potentially leading to financial loss or fraudulent-looking behavior from the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The primary skill description is written in Chinese, and the file does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate a language/locale policy when users are not given an explicit opt-in or alternative.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill metadata declares no explicit tool scope or permission boundaries, while the static analysis indicates capabilities such as environment access, file read/write, and network use. In an agent environment, missing scope declarations can allow behavior beyond what a user would reasonably expect, especially for a monitoring skill that may touch external services and local persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The phrase '当你想追踪聪明钱的每一步,监测大户交易行为时使用此技能' describes invocation in very broad, natural language terms rather than giving specific trigger phrases or constraints. This can overlap with common analytical requests about crypto markets and may cause unintended activation because the file does not provide negative examples or clear scope limits.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file implements extensive billing and payment enforcement logic that is unrelated to the stated whale-alert monitoring function. Hidden or non-core monetization code increases supply-chain risk because users invoking an analytics skill may not expect automatic charging behavior embedded in the skill implementation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This external transmission sends user-linked billing data to a third-party payment service and directly initiates a charge. In the context of a crypto whale-monitoring skill, this is more dangerous because payment enforcement is orthogonal to the core functionality and can surprise users or expose them to unauthorized billing if identity binding is weak.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The skill transmits user-linked data to an external payment-link endpoint, which creates privacy and account-association exposure to a third party. In isolation this is common for billing, but in this skill context it is still a real concern because the payment subsystem is embedded in a tool whose declared purpose is market monitoring rather than payments.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill reads a payment identity from an environment variable even though whale monitoring does not require such host-level access. This creates an unnecessary trust boundary crossing: environment variables can be misconfigured, attacker-controlled in some deployments, or reveal/bind sensitive account context that the skill should not independently consume.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill charges at startup via verify_payment()/require_payment() without a just-in-time warning or confirmation. This can lead to unauthorized or surprise charges, especially when the skill is invoked automatically or when the mapped billing identity is incorrect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.