Back to skill

Security audit

链上数据查询(专业版)

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about blockchain data queries and paid endpoints, but its broad activation wording could route ordinary analytics tasks into a payment-capable workflow.

Review this skill before installing. Use it only for explicit on-chain or blockchain data tasks, enable per-call payment confirmation, set a low total budget, use a dedicated low-balance wallet, and avoid autonomous mode unless stop conditions are configured.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill’s summary/description declares very broad usage such as data analysis, report generation, statistics, visualization, and automation workflows, which can cause the agent to invoke it for many generic requests unrelated to the specialized blockchain domain. In this skill, broad activation is more dangerous because the toolset includes exec/write and paid endpoints, so accidental invocation can trigger unnecessary command execution, external requests, or spending.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The declared coverage keywords are fragmented and overly permissive, including common terms like 'Use', 'when', and generic analytics concepts, creating ambiguous trigger conditions. In an agent environment, this increases the chance of unintended routing into a skill that can access external services and initiate paid workflows.

Static analysis

No suspicious patterns detected.