Back to skill

Security audit

加密货币投资研究

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small cryptocurrency lookup helper that queries CoinGecko and does not show hidden persistence, credential access, destructive behavior, or exfiltration beyond expected API queries.

Install only if you are comfortable with cryptocurrency queries being sent to CoinGecko. Treat it as a price and market-data lookup tool, not a complete investment research, trend-analysis, or news-tracking assistant.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述覆盖了价格、行情、趋势、新闻等较广泛的加密货币研究能力,但代码仅调用 CoinGecko API 实现了价格查询、Top 市值币种列表和币种搜索。它没有新闻获取功能,也没有真正的趋势分析或更广义的投资研究能力。虽然“价格、行情”部分基本符合,但整体声明比实际能力更宽,存在明显描述与行为不完全一致的情况。未发现额外敏感或越权能力,主要问题是声明过度涵盖了未实现的研究/新闻/趋势功能。

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/crypto.sh (reported line 7)May include surrounding context.

sh
case "$1" in
    price)
        COIN="$2"
        curl -s "https://api.coingecko.com/api/v3/simple/price?ids=${COIN}&vs_currencies=usd,cny&include_24hr_change=true&include_market_cap=true" | python3 -m json.tool
        ;;
    top)
        curl -s "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=10&page=1&sparkline=false&price_change_percentage=24h" | python3 -c "

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/crypto.sh (reported line 10)May include surrounding context.

sh
curl -s "https://api.coingecko.com/api/v3/simple/price?ids=${COIN}&vs_currencies=usd,cny&include_24hr_change=true&include_market_cap=true" | python3 -m json.tool
        ;;
    top)
        curl -s "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=10&page=1&sparkline=false&price_change_percentage=24h" | python3 -c "
import sys, json
data = json.load(sys.stdin)
print('='*70)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/crypto.sh (reported line 29)May include surrounding context.

sh
;;
    search)
        QUERY="$2"
        curl -s "https://api.coingecko.com/api/v3/search?query=${QUERY}" | python3 -c "
import sys, json
data = json.load(sys.stdin)
for coin in data.get('coins', [])[:5]:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says the skill triggers whenever a user asks about cryptocurrency prices, market conditions, trends, or news, which covers a very wide range of ordinary conversation. It does not define exclusions, boundaries, or narrower invocation constraints, so the activation scope is ambiguous and could cause unintended triggering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill metadata and usage examples are entirely in Chinese, which implies a fixed language experience for the skill. There is no indication that users can choose another language or that the Chinese-only behavior is a documented locale-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Comments and printed output such as the description and table headers are fixed in Chinese, with no option for the user to select another language or locale. This is a natural-language policy concern because it imposes a specific language rather than offering choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto.py (reported line 12)May include surrounding context.

python
case "$1" in
    price)
        COIN="$2"
        curl -s "https://api.coingecko.com/api/v3/simple/price?ids=${COIN}&vs_currencies=usd,cny&include_24hr_change=true&include_market_cap=true" | python3 -m json.tool
        ;;
    top)
        curl -s "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=10&page=1&sparkline=false&price_change_percentage=24h" | python3 -c "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto.py (reported line 39)May include surrounding context.

python
case "$1" in
    price)
        COIN="$2"
        curl -s "https://api.coingecko.com/api/v3/simple/price?ids=${COIN}&vs_currencies=usd,cny&include_24hr_change=true&include_market_cap=true" | python3 -m json.tool
        ;;
    top)
        curl -s "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=10&page=1&sparkline=false&price_change_percentage=24h" | python3 -c "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto.py (reported line 69)May include surrounding context.

python
case "$1" in
    price)
        COIN="$2"
        curl -s "https://api.coingecko.com/api/v3/simple/price?ids=${COIN}&vs_currencies=usd,cny&include_24hr_change=true&include_market_cap=true" | python3 -m json.tool
        ;;
    top)
        curl -s "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=10&page=1&sparkline=false&price_change_percentage=24h" | python3 -c "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto.sh (reported line 7)May include surrounding context.

sh
case "$1" in
    price)
        COIN="$2"
        curl -s "https://api.coingecko.com/api/v3/simple/price?ids=${COIN}&vs_currencies=usd,cny&include_24hr_change=true&include_market_cap=true" | python3 -m json.tool
        ;;
    top)
        curl -s "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=10&page=1&sparkline=false&price_change_percentage=24h" | python3 -c "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto.sh (reported line 10)May include surrounding context.

sh
case "$1" in
    price)
        COIN="$2"
        curl -s "https://api.coingecko.com/api/v3/simple/price?ids=${COIN}&vs_currencies=usd,cny&include_24hr_change=true&include_market_cap=true" | python3 -m json.tool
        ;;
    top)
        curl -s "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=10&page=1&sparkline=false&price_change_percentage=24h" | python3 -c "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/crypto.sh (reported line 29)May include surrounding context.

sh
case "$1" in
    price)
        COIN="$2"
        curl -s "https://api.coingecko.com/api/v3/simple/price?ids=${COIN}&vs_currencies=usd,cny&include_24hr_change=true&include_market_cap=true" | python3 -m json.tool
        ;;
    top)
        curl -s "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&order=market_cap_desc&per_page=10&page=1&sparkline=false&price_change_percentage=24h" | python3 -c "

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language documentation in Chinese only, including the module docstring and function docstrings, without any indication that language choice is optional. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script sends user-supplied coin or search query data to the external CoinGecko API via curl, but it provides no visible notice, prompt, or comment explaining that data will be transmitted off-system. For code files, outbound network calls that transmit user or system data should have some form of user disclosure unless clearly documented as part of the skill's stated purpose, which is not evident within this file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.