T08 · Insecure Dependencies
- Location
SKILL.md:251- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward crypto price alert helper with expected external API use, but users should note optional Telegram sharing, an unsafe sample /tmp log path, and some overstated alert features.
Install only if you are comfortable with price queries going to CoinGecko and, if enabled, alert messages going to Telegram. Avoid running the cron job as root, prefer a private log location instead of `/tmp`, and treat percentage-move and configurable file-alert claims as not implemented in the bundled script.
SKILL.md:251Unpinned Third-Party Dependency Installation
SKILL.md:186Predictable Temporary File Permits Symlink-Based File Clobbering
The code generally matches the core purpose of monitoring cryptocurrency prices and triggering alerts using CoinGecko, with support for console and Telegram notifications. However, the description claims support for percentage-move alerts and delivery to files, neither of which is implemented in this code. The code only evaluates absolute price thresholds ('above'/'below') and prints to console plus optional Telegram. These are material overstatements in the declared functionality, so this should be flagged as a description-behavior mismatch.
The skill performs network operations to CoinGecko and Telegram but does not declare tool scope or permissions in the manifest. This makes the skill's external communication capability less visible to reviewers and users, increasing the chance of unintended data egress or overbroad deployment in environments that rely on manifest-based policy enforcement.
The skill sends alert messages and chat destination data to Telegram, a third-party service, without a clear user-facing disclosure near the configuration and transmission path. Even though the data appears limited to market alerts, messages may contain user-authored content and operational metadata, creating an avoidable privacy and data-sharing risk.
The Telegram API endpoint enables outbound transmission of alert data to a third-party messaging service. In context this is intentional functionality, but it is still a genuine data-egress surface because configured messages and destination identifiers leave the local environment.
def send_telegram(message, bot_token, chat_id):
if not bot_token or not chat_id:
return
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
payload = {"chat_id": chat_id, "text": message, "parse_mode": "HTML"}
requests.post(url, json=payload, timeout=10)
This code transmits alert content to Telegram over the network, which is an intentional external data transfer to a third party. While not malicious, it is security-relevant because messages may include user-defined content and operational details, and the transmission is not paired with strong warnings, redaction controls, or explicit consent workflow in the skill itself.
return
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
payload = {"chat_id": chat_id, "text": message, "parse_mode": "HTML"}
requests.post(url, json=payload, timeout=10)
if __name__ == "__main__":
config_path = os.path.join(os.path.dirname(__file__), "crypto-alerts.json")
The manifest and documentation claim support for percentage-based alerts, including examples like alerting on a 5% move and documented percent_up/percent_down conditions. However, check_alerts only evaluates above and below price thresholds, so percentage-trigger alerts described by the skill are nonfunctional.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import os
from datetime import datetime
COINGECKO_API = "https://api.coingecko.com/api/v3"
def get_price(coin_id):
url = f"{COINGECKO_API}/simple/price"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import os
from datetime import datetime
COINGECKO_API = "https://api.coingecko.com/api/v3"
def get_price(coin_id):
url = f"{COINGECKO_API}/simple/price"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import os
from datetime import datetime
COINGECKO_API = "https://api.coingecko.com/api/v3"
def get_price(coin_id):
url = f"{COINGECKO_API}/simple/price"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import os
from datetime import datetime
COINGECKO_API = "https://api.coingecko.com/api/v3"
def get_price(coin_id):
url = f"{COINGECKO_API}/simple/price"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import os
from datetime import datetime
COINGECKO_API = "https://api.coingecko.com/api/v3"
def get_price(coin_id):
url = f"{COINGECKO_API}/simple/price"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import os
from datetime import datetime
COINGECKO_API = "https://api.coingecko.com/api/v3"
def get_price(coin_id):
url = f"{COINGECKO_API}/simple/price"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import os
from datetime import datetime
COINGECKO_API = "https://api.coingecko.com/api/v3"
def get_price(coin_id):
url = f"{COINGECKO_API}/simple/price"
The manifest says the skill supports alerts for 'percentage moves', but the alert logic only checks whether the current price is above or below a fixed target. Although 24h percentage change is fetched and displayed, it is never used to trigger alerts, so the implemented behavior is narrower than advertised.
The manifest description explicitly includes file-based alert delivery, but this file only prints alerts to stdout and optionally sends them to Telegram. There is no code path that writes triggered alerts to a file, creating a clear mismatch between stated capability and actual implementation.
The function transmits alert contents to Telegram, an external third party, whenever bot credentials are present, but there is no explicit user-facing disclosure or consent mechanism at the send point. In this skill's context the transmitted data is usually low sensitivity, but custom alert messages and trading-related information could still leak operational or personal details to an external service.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def send_telegram(message, bot_token, chat_id):
if not bot_token or not chat_id:
return
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
payload = {"chat_id": chat_id, "text": message, "parse_mode": "HTML"}
requests.post(url, json=payload, timeout=10)
This code sends data to the Telegram API over the network, which is an external transmission channel. In context this is expected functionality, but it still creates privacy and data-governance risk because alert messages, potentially including user-authored content or trading signals, leave the local environment and are delivered to a third party.
return
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
payload = {"chat_id": chat_id, "text": message, "parse_mode": "HTML"}
requests.post(url, json=payload, timeout=10)
if __name__ == "__main__":
config_path = os.path.join(os.path.dirname(__file__), "crypto-alerts.json")
The description presents file delivery as a supported alert destination alongside console and Telegram. In practice, the code always prints to console, optionally sends Telegram messages, and appends triggered alerts to a hard-coded /tmp/crypto_alerts_triggered.json path with no user-facing file delivery configuration, which is weaker than the claimed capability.
No suspicious patterns detected.