Back to skill

Security audit

Crypto Search

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Kaito search helper for Twitter/X and News content, with no executable code, persistence, or hidden local access.

Installers should understand that this skill sends search queries to Kaito MCP and may retrieve public Twitter/X and News results. Review the query before running it, especially if a request is vague, but no hidden or high-impact behavior was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match many ordinary user requests, increasing the chance this skill activates unintentionally in contexts where a different tool or stricter workflow should be used. In an agent environment, over-broad invocation can cause unintended external searches, unnecessary data handling, and policy bypass through accidental tool selection, especially because this skill is designed as a reusable primitive within larger workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill says at L186 to default to sort_by: relevance unless the user requests otherwise, and the output template at L160 says results are ranked by relevance. However, L199 says showing smart_engagement is critical for demonstrating that results were ranked by smart_engagement, which directly conflicts with the stated default behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.