Back to skill

Security audit

BTC/ETH AI Trader

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it needs review because it stores messaging credentials in a local config file and sends trading reports to third-party chat services.

Install only if you are comfortable giving the skill outbound network access and storing messaging credentials locally. Move real tokens/webhooks out of config.json if possible, restrict bot and webhook permissions, verify every configured chat destination, and remember that the generated trading calls are not investment advice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
config.json:1
Finding

Messaging Credentials Are Stored in a Plaintext Project Configuration File

Content
View full analysis
Remediation
View remediation

other

Note
Location
scripts/advise.py:54
Finding

Runtime Access to an Undisclosed Secondary Market-Data Service

Content
View full analysis
0: return {"funding": float(d[0].get("funding_rate", 0)) * 100} except: pass return {} ``` The documentation identifies CoinEx as the system's data source, but report generation also contacts the Gate.io API. The secondary request is hardcoded and is not disclosed or configurable. ### Technical Analysis Executing report generation invokes `get_network_sentiment()`, which establishes an HTTPS connection to `api.gateio.ws`. This does not transmit configured messaging credentials or local files, and the endpoint is related to the advertised market-analysis function. However, the actual network behavior exceeds the documented data-source declaration. Undisclosed third-party communication can violate user expectations, organizational egress policies, privacy requirements, or jurisdictional restrictions. It may also cause the Skill to fail or stall in environments where only the documented CoinEx endpoint has been allowlisted. This finding does not constitute remote payload execution: the response is parsed as JSON and used only as a numeric funding-rate input. ### Attack Path 1. A user reviews the documentation and permits network access on the assumption that CoinEx is the market-data source. 2. The user runs `scripts/advise.py` or `scripts/push.py`. 3. `generate_full_report()` invokes `get_network_sentiment()`. 4. The host makes an outbound HTTPS request to `api.gateio.ws`. 5. ...[truncated 803 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The declared behavior materially differs from the implemented behavior: the README promises AI analysis, trade-entry recommendations, and multi-platform pushing, while static analysis indicates those capabilities are absent or incomplete and that external CoinEx dependency is underdisclosed. This mismatch is dangerous because users may trust the skill for financial decision-making or enable it in environments with external connectivity based on misleading documentation, causing unsafe reliance and unexpected data flows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and setup guidance are written in Chinese, and the file does not indicate that the skill is intended only for a Chinese-speaking or region-specific audience, nor does it offer an English or user-selectable language option. Under the policy rule for natural-language constraints, this is a locale/language restriction without opt-in or justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises network-dependent behavior and external data/push integrations, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization and transparency gap: an agent or reviewer cannot easily constrain or reason about what outbound access the skill requires, increasing the risk of unintended network use or data exfiltration through misconfiguration or future code changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description does not define clear activation constraints, trigger conditions, or examples, so an agent may invoke it too broadly whenever cryptocurrency topics appear. Overbroad invocation can lead to unnecessary external requests, unintended messaging actions, or financial-analysis outputs in contexts where the user did not explicitly request them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill states that it auto-pushes analysis every 30 minutes to external platforms, but it does not prominently warn users about the ongoing automated external transmission of generated content. In context, this is more dangerous because the skill integrates with multiple messaging channels, so users may unknowingly enable recurring outbound notifications that disclose trading-related information or create spam/abuse risks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/advise.py (reported line 58)May include surrounding context.

python
"""Fetch market sentiment data"""
    try:
        import urllib.request
        r = urllib.request.urlopen("https://api.gateio.ws/api/v4/futures/usdt/tickers?contract=BTC_USDT", timeout=5)
        d = json.loads(r.read())
        if isinstance(d, list) and len(d) > 0:
            return {"funding": float(d[0].get("funding_rate", 0)) * 100}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill generates all user-facing advice strings in Chinese, including recommendations and warnings, with no option for the user to select a language. This is a natural-language policy issue because it imposes a specific locale on all users without opt-in or documented regional scope.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/check.py (reported line 4)May include surrounding context.

python
"""Check prices for BTC and ETH - CoinEx API (China accessible)"""
import json, urllib.request

COINEX = "https://api.coinex.com/v1"

def get_price(symbol):
    try:

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The hardcoded Telegram API endpoint indicates intentional external transmission of report data to a third-party platform. In this skill's context, that is security-relevant because trading reports are likely to be sensitive and their routine export increases the chance of disclosure through configuration mistakes or compromised bot credentials.

Content

Scanner excerpt · scripts/push.py (reported line 62)May include surrounding context.

python
try:
        # TG消息不能太长,截断
        msg = text[:3000] if len(text) > 3000 else text
        url = f"https://api.telegram.org/bot{t['bot_token']}/sendMessage"
        data = json.dumps({"chat_id": t["chat_id"], "text": msg, "parse_mode": "Markdown"}).encode()
        r = urllib.request.urlopen(urllib.request.Request(url, data=data, headers={"Content-Type": "application/json"}), timeout=10)
        return r.status == 200, "Telegram OK" if r.status == 200 else f"TG HTTP {r.status}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This code transmits the generated report to Telegram, an external third-party service, which is a real outbound data flow. In the context of a trading-analysis skill, reports may contain sensitive or proprietary strategy information, so sending them externally without validation, minimization, or user confirmation creates confidentiality risk.

Content

Scanner excerpt · scripts/push.py (reported line 64)May include surrounding context.

python
msg = text[:3000] if len(text) > 3000 else text
        url = f"https://api.telegram.org/bot{t['bot_token']}/sendMessage"
        data = json.dumps({"chat_id": t["chat_id"], "text": msg, "parse_mode": "Markdown"}).encode()
        r = urllib.request.urlopen(urllib.request.Request(url, data=data, headers={"Content-Type": "application/json"}), timeout=10)
        return r.status == 200, "Telegram OK" if r.status == 200 else f"TG HTTP {r.status}"
    except Exception as e:
        return False, f"TG异常: {e}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This sends report content to a Discord webhook URL, which is an external endpoint that may expose trading intelligence to unintended parties if the webhook is leaked, misconfigured, or shared. Because webhook URLs act as bearer secrets, any misuse or compromise can result in silent exfiltration of the report.

Content

Scanner excerpt · scripts/push.py (reported line 77)May include surrounding context.

python
try:
        msg = text[:1800] if len(text) > 1800 else text
        data = json.dumps({"content": f"```{msg}```"}).encode()
        r = urllib.request.urlopen(urllib.request.Request(d["webhook_url"], data=data, headers={"Content-Type": "application/json"}), timeout=10)
        return r.status == 204, "Discord OK"
    except Exception as e:
        return False, f"Discord异常: {e}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This posts the report to a WeCom webhook, creating an external transmission channel for potentially sensitive trading content. If the webhook is misrouted, leaked, or the receiving channel has broad membership, confidential analysis can be exposed beyond the intended audience.

Content

Scanner excerpt · scripts/push.py (reported line 90)May include surrounding context.

python
try:
        msg = text[:2000] if len(text) > 2000 else text
        data = json.dumps({"msgtype": "text", "text": {"content": msg}}).encode()
        r = urllib.request.urlopen(urllib.request.Request(w["webhook_url"], data=data, headers={"Content-Type": "application/json"}), timeout=10)
        return r.status == 200, "企微OK"
    except Exception as e:
        return False, f"企微异常: {e}"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script automatically sends the generated trading report to all configured third-party messaging platforms without any confirmation, review step, or explicit consent at send time. Because reports may contain sensitive trading signals, account-related context, or other proprietary information, this creates a real data leakage risk if the configuration is wrong, shared, or compromised.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and instructions are entirely in Chinese and mention a China-specific data source connection, but they do not state that the skill is intentionally region- or language-specific or provide user opt-in for language preference. This can violate language/locale policy when users are not given a documented choice or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill as a trading analysis system without any indication that language is configurable or that the Chinese-only locale is an intentional regional constraint. Under the policy, natural-language content that forces a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Several docstrings and user-facing status/error strings are presented only in Chinese, such as the timeout message and platform status messages. This can violate language/locale policy when the skill forces a specific language without user opt-in or a documented regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.