Back to skill

Security audit

A股-加密货币-定时早报-多维度指标全方位分析-安装即用无复杂配置-自带验证降低幻觉

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with market-analysis use, but it can automatically use and transmit a saved CryptoPanic token during routine crypto fetches.

Review before installing. Run the fetch scripts only if you are comfortable with network calls to public market-data providers, avoid passing CryptoPanic tokens on the command line, unset CRYPTOPANIC_TOKEN unless you explicitly want news, and consider updating vulnerable dependencies before regular use. Treat generated trading reports as research, not financial advice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_samples.py:215
Finding

Implicit Credential Transmission During General Cryptocurrency Fetches

Content
View full analysis
JSONList: url = ( "https://cryptopanic.com/api/developer/v2/posts/?" f"auth_token={token}&public=true¤cies={base_symbol}&kind={kind}" ) try: resp = requests.get(url, timeout=10) except requests.RequestException: raise RuntimeError("CryptoPanic request failed") from None ``` ### Technical Analysis The general `fetch_crypto()` workflow automatically reads the `CRYPTOPANIC_TOKEN` environment variable and transmits it whenever the variable is present. This behavior occurs even when the caller only requests cryptocurrency prices or technical indicators and has not explicitly requested news. The transmission destination is the fixed CryptoPanic HTTPS endpoint, and the token is necessary when news is explicitly requested. Therefore, this is not evidence of attacker-controlled exfiltration. However, implicitly accessing and transmitting a credential exceeds the minimum privileges required for the general cryptocurrency-data workflow and conflicts with the documentation stating that the token should only be used when the user requests cryptocurrency news. The token is also embedded in the URL query string. Although HTTPS protects it in transit, complete URLs can be retained by local HTTP debugging tools, proxies, monitoring systems, or observability infrastructure. ### Attack Path 1. A user places a valid CryptoPanic token in ...[truncated 1142 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/fetch_news.py:21
Finding

CryptoPanic Token Accepted Through Exposed Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (17)

Tainted flow: 'url' from os.getenv (line 573, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/fetch_samples.py (reported line 551)May include surrounding context.

python
url = "https://fapi.binance.com/futures/data/globalLongShortAccountRatio"
    params = {"symbol": raw_symbol, "period": period, "limit": 1}
    try:
        resp = requests.get(url, params=params, timeout=10)
        if resp.status_code != 200:
            return {}
        payload = resp.json()

Tainted flow: 'url' from os.getenv (line 573, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The CryptoPanic token is embedded directly into the URL query string before calling requests.get. Even though the request goes to the intended host, secrets placed in URLs are commonly exposed through logs, proxies, monitoring systems, exception traces, browser/history equivalents in tooling, and upstream infrastructure, causing credential leakage. In an agent skill context that may emit diagnostics or be wrapped by other tooling, this is more dangerous than in a tightly controlled standalone script.

Content

Scanner excerpt · scripts/fetch_samples.py (reported line 578)May include surrounding context.

python
f"auth_token={token}&public=true&currencies={base_symbol}&kind={kind}"
    )
    try:
        resp = requests.get(url, timeout=10)
    except requests.RequestException:
        raise RuntimeError("CryptoPanic request failed") from None

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a comprehensive install-and-use market analysis skill spanning both A-shares and crypto, with rich analytics and multiple output modes. The actual code chunk is much narrower: it is only a command-line wrapper around an A-share fetch function and outputs JSON. While this could be a supporting component of a larger system, the supplied code chunk itself does not substantiate the described primary capabilities. Because the visible behavior is materially narrower than the declared purpose and lacks the dual-market and analysis/reporting functionality emphasized in the description, this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a comprehensive, install-and-use dual-market analysis skill covering both A-shares and crypto, with extensive indicator coverage, news/sentiment, and multiple default report types. The actual code chunk is narrowly scoped: it is a command-line wrapper that parses a single crypto symbol, invokes fetch_crypto, and prints JSON. Based on this chunk alone, the implemented behavior is limited to crypto data retrieval/serialization, not full-spectrum market analysis or report generation. This is a material description-to-behavior mismatch in primary purpose and scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a broad, install-and-use analysis skill covering both A-shares and cryptocurrencies, with multidimensional indicators, strategy-oriented outputs, and multiple default report types. The supplied code chunk does not implement that scope. It only defines a command-line script that calls fetch_morning(...) and prints JSON for A-share morning briefing inputs, with parameters for industries, limit-ups, LHB, and breakfast items. There is no evidence in this chunk of crypto data access, mixed-market analysis, report generation, sentiment/news processing, strategy recommendations, or validation mechanisms. This is a materially narrower and different behavior than the declared primary purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Forcing Chinese-preferred output without explicit user opt-in can override user expectations and system behavior, especially in multilingual environments. While not directly enabling code execution or data exfiltration, it is a control-plane issue that can degrade reliability, cause instruction conflicts, and potentially obscure safety-critical content if the user expected another language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger rules are broad enough to activate on ordinary financial discussion terms like 'strategy', 'entry', 'stop', or 'win rate', which can cause the skill to load or steer responses when the user did not explicitly request this specialized behavior. In an agent setting, this increases the risk of prompt-scope overreach, unwanted instruction injection into unrelated conversations, and financial-analysis framing being applied too aggressively.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Repeating a Chinese-preferred language rule in the trigger section reinforces behavior that may supersede user-selected language preferences during activation. In agent workflows, duplicated behavioral constraints can make the skill more persistent and harder to override, increasing the chance of misaligned responses.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill references executable scripts, environment variables, file paths, and external data sources, yet declares no explicit tool/permission scope. In an agent runtime, this can cause the skill to inherit overly broad capabilities such as shell, network, file write, and env access, increasing the blast radius if the prompt is misused or the implementation is later extended unsafely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are extremely broad and instruct the system to 'immediately load' the skill for many generic finance-related terms. In agentic environments, overbroad auto-activation can cause the wrong skill to seize control of unrelated requests, unnecessarily invoking networked data collection, increasing prompt-injection exposure from external content, and degrading decision integrity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The 'When to use' section relies on very broad keywords such as strategy, stop loss, targets, drawdown, order book, and morning briefing without precise scoping. This can lead to inadvertent routing of many common requests into a skill that references external scripts and data sources, expanding attack surface and making prompt-injection or unsafe financial-advice flows more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains substantial user-facing guidance in both English and Chinese, including dependency/setup and A-share data-source instructions. Under the language/locale policy rule, forcing or assuming a language without user opt-in can be a policy issue unless the regional scope is clearly justified; here the file does not explicitly state that it is intended only for Chinese-speaking users or offer an alternative.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/bootstrap.py (reported line 33)May include surrounding context.

python
# Create venv
    if not venv_dir.exists():
        subprocess.check_call([sys.executable, "-m", "venv", str(venv_dir)])

    py = _venv_python(venv_dir)
    if not py.exists():

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/bootstrap.py (reported line 41)May include surrounding context.

python
return 1

    # Install deps
    subprocess.check_call([str(py), "-m", "pip", "install", "-U", "pip"])
    subprocess.check_call([str(py), "-m", "pip", "install", "-r", str(req)])

    print("ok")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/bootstrap.py (reported line 42)May include surrounding context.

python
# Install deps
    subprocess.check_call([str(py), "-m", "pip", "install", "-U", "pip"])
    subprocess.check_call([str(py), "-m", "pip", "install", "-r", str(req)])

    print("ok")
    print(f"venv: {venv_dir}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code defines Chinese-only financial metric labels and later emits multiple Chinese-labeled fields and status strings, indicating the skill is effectively locked to a specific language/locale. The file does not offer a user choice of language or document a locale-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: requests==2.32.5 — 2 advisory(ies): CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func); CVE-2026-25645 (Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract)

Medium
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is pinned to requests==2.32.5, which the finding reports as affected by CVE-2026-25645 and fixed in 2.33.0. Even though this skill is primarily a market-analysis tool and the vulnerable helper may only be reachable in specific code paths, shipping a known-vulnerable HTTP library is still risky because any code path that processes zipped content via the affected utility could expose insecure temporary-file behavior and enable local file overwrite, data exposure, or race-condition abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.