Back to skill

Security audit

Crypto Kline BTC加密货币K线数据-HuoBi

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small Huobi market-data helper that only runs a local Node script to query Huobi's public API and print results.

Install only if you are comfortable with a Node script making outbound requests to Huobi for public market data. Use full trading pairs such as btcusdt rather than the shorthand examples if the API rejects symbols like BTC.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
node scripts/huobi-kline.js BTC 1d 30 # BTC日线最近30条

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
node scripts/huobi-kline.js BTC 1d 30 # BTC日线最近30条

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
node scripts/huobi-kline.js BTC 1d 30 # BTC日线最近30条

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description, headings, and usage guidance are entirely in Chinese, which imposes a specific language on users without indicating that other languages are available. The policy explicitly calls for flagging language or locale constraints unless the skill offers user choice or clearly documents a justified regional limitation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example commands use base asset symbols such as "BTC" and "ETH", while the parameter description immediately below says the first argument is a trading pair like "btcusdt/ethusdt/solusdt". This is an active contradiction in the file's own documentation about what input the skill expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill name and description are written only in Chinese, which indicates a fixed language choice in user-facing metadata. There is no indication that users can select another language or that the locale restriction is intentional and documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.