Back to skill

Security audit

A股-加密货币-定时早报-多维度指标全方位分析-安装即用无复杂配置-自带验证降低幻觉

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly fits its market-analysis purpose, but it should be reviewed because its scripts can use a CryptoPanic API token automatically and pass it through URL or command-line based workflows.

Install only if you are comfortable with a market-analysis skill that can run network-fetching Python scripts and produce trading-plan style reports. Prefer setting CryptoPanic credentials only for explicit news fetches, avoid passing tokens on the command line, and review dependency installation before running bootstrap.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_samples.py:571
Finding

CryptoPanic API Token Exposed Through Command-Line Arguments and URL Query Strings

Content
View full analysis
JSONList: url = ( "https://cryptopanic.com/api/developer/v2/posts/?" f"auth_token={token}&public=true¤cies={base_symbol}&kind={kind}" ) try: resp = requests.get(url, timeout=10) ``` Related documentation explicitly encourages the command-line option in `references/data_sources.md:13` and describes the token-bearing URL at `references/data_sources.md:40-41`. ### Technical Analysis The `--token` option allows a credential to be supplied directly in the process command line. Depending on the operating system and runtime environment, command-line arguments may be exposed through: - Shell history files. - Process inspection utilities. - Process accounting or endpoint monitoring. - CI/CD job logs. - Wrapper scripts and orchestration metadata. The token is then interpolated into the request URL as the `auth_token` query parameter. Although HTTPS encrypts the request in transit, query strings can still be captured by local HTTP debugging, application-performance monitoring, proxy telemetry, exception instrumentation, or server-side access logs. The request is sent only to the declared CryptoPanic HT ...[truncated 1215 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/fetch_samples.py:215
Finding

Generic Crypto Fetching Automatically Uses an Ambient News API Token

Content
View full analysis
Remediation
View remediation
JSONDict: ... if include_news: token = os.getenv("CRYPTOPANIC_TOKEN") if token: data["news"] = fetch_cryptopanic( token, _base_symbol(normalized_symbol) ) else: data["news"] = [] else: data["news"] = [] ``` 2. Add an explicit `--include-news` option to `scripts/fetch_crypto.py`. 3. Read `CRYPTOPANIC_TOKEN` only after the caller has enabled news retrieval. 4. Keep public market-data retrieval and authenticated news retrieval as separate execution paths where practical. 5. Document all network destinations and clarify that authenticated requests occur only with explicit caller approval. 6. Add a test that sets `CRYPTOPANIC_TOKEN`, calls `fetch_crypto()` with its default options, and verifies that no CryptoPanic request occurs. ]]>

T08 · Insecure Dependencies

Note
Location
scripts/bootstrap.py:32
Finding

Bootstrap Installs Network Dependencies Without Artifact Hash Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (20)

Tainted flow: 'url' from os.getenv (line 573, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/fetch_samples.py (reported line 551)May include surrounding context.

python
url = "https://fapi.binance.com/futures/data/globalLongShortAccountRatio"
    params = {"symbol": raw_symbol, "period": period, "limit": 1}
    try:
        resp = requests.get(url, params=params, timeout=10)
        if resp.status_code != 200:
            return {}
        payload = resp.json()

Tainted flow: 'url' from os.getenv (line 573, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
98% confidence
Finding

This is a real issue because the CryptoPanic token from the environment is interpolated directly into the request URL query string before being sent with requests.get. Query-string credentials are more likely to be exposed through logs, proxy records, monitoring systems, exception traces, browser/history-style captures in some tooling, or upstream service telemetry, making accidental credential leakage more likely.

Content

Scanner excerpt · scripts/fetch_samples.py (reported line 578)May include surrounding context.

python
f"auth_token={token}&public=true&currencies={base_symbol}&kind={kind}"
    )
    try:
        resp = requests.get(url, timeout=10)
    except requests.RequestException:
        raise RuntimeError("CryptoPanic request failed") from None

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This code chunk’s primary purpose is environment setup: creating a virtual environment, installing pip requirements, and printing sample commands. That is only a supporting implementation detail, not the declared analytical behavior. The declared description emphasizes rich financial analysis capabilities across crypto and A-shares, but none of those behaviors are present in this code. While bootstrap/setup can be part of such a skill, this chunk by itself materially differs from the declared purpose and does not substantiate the claimed capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description promises a comprehensive, install-and-use dual-market analysis skill covering both A-shares and crypto, multiple public data sources, news/sentiment, validation, and several rich report types. The supplied code chunk, however, only implements a command-line wrapper for fetching A-share data for one code and serializing it to JSON. This is materially narrower than the declared primary purpose. While this helper could be a supporting component of the larger skill, based on the supplied chunk alone it does not demonstrate the advertised crypto support, report generation, strategic analysis, or news/data-source breadth. Therefore the description is not accurately represented by this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description promises a full-featured, install-and-use dual-market analysis skill covering both A-shares and crypto, with multiple report types and broad analytical dimensions. The supplied code chunk, however, is narrowly scoped: it is a command-line wrapper for fetching crypto data for a single symbol and serializing it to JSON. There is no visible implementation of A-share analysis, report generation, market sentiment/news handling, strategy computation, or other declared capabilities. While this may be a supporting utility within a larger project, based on the provided chunk alone the actual behavior is materially narrower than the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad, install-and-use market analysis skill covering both A-shares and cryptocurrencies, with rich analytics, multiple report types, and numerous data sources. In contrast, the supplied code chunk only defines a command-line script that fetches A-share morning briefing JSON inputs and prints them. Its exposed options are limited to A-share morning data categories such as industries, previous limit-ups, institutional LHB, and breakfast items. There is no visible crypto support, no cross-market analysis, no strategy generation, no sentiment or derivatives handling, and no actual analytical/reporting logic in this chunk. Therefore, the code’s observed behavior is materially narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is configured to activate on extremely broad financial keywords such as 行情, 策略, 止损, 个股, 币对, and similar English equivalents. Overbroad triggers can cause the agent to load this skill in unrelated or weakly related contexts, exposing users to unsolicited financial-advice formatting, unnecessary tool use, and increased attack surface for prompt steering through casual keyword injection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document states the skill will auto-detect language but respond with Chinese by default when possible, rather than consistently honoring the user's language or offering an explicit opt-in choice. This is a natural-language locale policy constraint and is not clearly justified as region-specific compliance behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are very broad and can cause the skill to activate in routine financial conversations where the user did not intend specialized behavior. In an agent environment, ambiguous auto-activation can override safer defaults, cause unsolicited market-analysis workflows, or prompt collection/use of external data and tokens in contexts where that is unnecessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The line says “中文优先,否则英文回复,” which forces a preferred locale rather than simply matching user preference. The rule applies to natural-language policy in markdown, and this wording does not present language choice as optional or user-controlled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The English README states “auto language detection (Chinese preferred, else English)” and repeats “CN preferred” in the triggers/language section. This duplicates the same locale policy violation in user-facing natural language and still does not offer explicit user choice.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill references executable scripts, environment variables, network data sources, and file-based dependencies, but does not declare any explicit tool restrictions such as allowed-tools or permissions. In agent environments, this creates unnecessary ambient authority: the model may be able to invoke shell, network, filesystem, or env access beyond what the skill actually needs, increasing the blast radius of prompt misuse or prompt injection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'When to use' section relies heavily on broad keyword and topic matching without strong scope boundaries, making accidental or adversarial invocation easier. In a skill-enabled agent, this increases the chance that unrelated prompts trigger specialized behavior or associated tools, which is especially sensitive here because the skill discusses external data sources, scripts, and trading recommendations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The dependency instructions at L006-L007 are written in Chinese, and later sections also mix in Chinese-only content. Because the document does not offer an alternative language or state that it is intentionally region-specific, it can violate a language/locale policy requiring user choice or clear justification.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/bootstrap.py (reported line 33)May include surrounding context.

python
# Create venv
    if not venv_dir.exists():
        subprocess.check_call([sys.executable, "-m", "venv", str(venv_dir)])

    py = _venv_python(venv_dir)
    if not py.exists():

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/bootstrap.py (reported line 41)May include surrounding context.

python
return 1

    # Install deps
    subprocess.check_call([str(py), "-m", "pip", "install", "-U", "pip"])
    subprocess.check_call([str(py), "-m", "pip", "install", "-r", str(req)])

    print("ok")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/bootstrap.py (reported line 42)May include surrounding context.

python
# Install deps
    subprocess.check_call([str(py), "-m", "pip", "install", "-U", "pip"])
    subprocess.check_call([str(py), "-m", "pip", "install", "-r", str(req)])

    print("ok")
    print(f"venv: {venv_dir}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The CryptoPanic API token is embedded into the constructed URL, which is an insecure credential-handling pattern even if HTTPS is used. In the context of an agent skill that may run inside orchestrators, wrappers, debuggers, and shared logging infrastructure, URL-based secrets are especially risky because the full request target is commonly captured outside the developer's direct control.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: requests==2.32.5 — 2 advisory(ies): CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func); CVE-2026-25645 (Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract)

Medium
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is pinned to requests==2.32.5, which the finding indicates is affected by a known vulnerability fixed in 2.33.0. Even though this skill’s metadata suggests market-data collection rather than archive handling, vulnerable libraries remain part of the attack surface and may be exercised indirectly by current or future code paths or transitive usage.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Lines L119-L120 and the English mirror at L338-L339 state that the skill itself does not directly fetch data, implying a passive analysis-only role. However, elsewhere the README presents bundled scripts as part of normal skill usage for fetching market and news data over the network, so the documentation draws a distinction that could mislead about actual packaged behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.