Back to skill

Security audit

Crypto Price Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward crypto price alert helper with expected external API use, but users should note optional Telegram sharing, an unsafe sample /tmp log path, and some overstated alert features.

Install only if you are comfortable with price queries going to CoinGecko and, if enabled, alert messages going to Telegram. Avoid running the cron job as root, prefer a private log location instead of `/tmp`, and treat percentage-move and configurable file-alert claims as not implemented in the bundled script.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Note
Location
SKILL.md:251
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:186
Finding

Predictable Temporary File Permits Symlink-Based File Clobbering

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code generally matches the core purpose of monitoring cryptocurrency prices and triggering alerts using CoinGecko, with support for console and Telegram notifications. However, the description claims support for percentage-move alerts and delivery to files, neither of which is implemented in this code. The code only evaluates absolute price thresholds ('above'/'below') and prints to console plus optional Telegram. These are material overstatements in the declared functionality, so this should be flagged as a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill performs network operations to CoinGecko and Telegram but does not declare tool scope or permissions in the manifest. This makes the skill's external communication capability less visible to reviewers and users, increasing the chance of unintended data egress or overbroad deployment in environments that rely on manifest-based policy enforcement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill sends alert messages and chat destination data to Telegram, a third-party service, without a clear user-facing disclosure near the configuration and transmission path. Even though the data appears limited to market alerts, messages may contain user-authored content and operational metadata, creating an avoidable privacy and data-sharing risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The Telegram API endpoint enables outbound transmission of alert data to a third-party messaging service. In context this is intentional functionality, but it is still a genuine data-egress surface because configured messages and destination identifiers leave the local environment.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
def send_telegram(message, bot_token, chat_id):
    if not bot_token or not chat_id:
        return
    url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
    payload = {"chat_id": chat_id, "text": message, "parse_mode": "HTML"}
    requests.post(url, json=payload, timeout=10)

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This code transmits alert content to Telegram over the network, which is an intentional external data transfer to a third party. While not malicious, it is security-relevant because messages may include user-defined content and operational details, and the transmission is not paired with strong warnings, redaction controls, or explicit consent workflow in the skill itself.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
return
    url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
    payload = {"chat_id": chat_id, "text": message, "parse_mode": "HTML"}
    requests.post(url, json=payload, timeout=10)

if __name__ == "__main__":
    config_path = os.path.join(os.path.dirname(__file__), "crypto-alerts.json")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and documentation claim support for percentage-based alerts, including examples like alerting on a 5% move and documented percent_up/percent_down conditions. However, check_alerts only evaluates above and below price thresholds, so percentage-trigger alerts described by the skill are nonfunctional.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
import os
from datetime import datetime

COINGECKO_API = "https://api.coingecko.com/api/v3"

def get_price(coin_id):
    url = f"{COINGECKO_API}/simple/price"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
import os
from datetime import datetime

COINGECKO_API = "https://api.coingecko.com/api/v3"

def get_price(coin_id):
    url = f"{COINGECKO_API}/simple/price"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
import os
from datetime import datetime

COINGECKO_API = "https://api.coingecko.com/api/v3"

def get_price(coin_id):
    url = f"{COINGECKO_API}/simple/price"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
import os
from datetime import datetime

COINGECKO_API = "https://api.coingecko.com/api/v3"

def get_price(coin_id):
    url = f"{COINGECKO_API}/simple/price"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
import os
from datetime import datetime

COINGECKO_API = "https://api.coingecko.com/api/v3"

def get_price(coin_id):
    url = f"{COINGECKO_API}/simple/price"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
import os
from datetime import datetime

COINGECKO_API = "https://api.coingecko.com/api/v3"

def get_price(coin_id):
    url = f"{COINGECKO_API}/simple/price"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · crypto_alert.py (reported line 9)May include surrounding context.

python
import os
from datetime import datetime

COINGECKO_API = "https://api.coingecko.com/api/v3"

def get_price(coin_id):
    url = f"{COINGECKO_API}/simple/price"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill supports alerts for 'percentage moves', but the alert logic only checks whether the current price is above or below a fixed target. Although 24h percentage change is fetched and displayed, it is never used to trigger alerts, so the implemented behavior is narrower than advertised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description explicitly includes file-based alert delivery, but this file only prints alerts to stdout and optionally sends them to Telegram. There is no code path that writes triggered alerts to a file, creating a clear mismatch between stated capability and actual implementation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The function transmits alert contents to Telegram, an external third party, whenever bot credentials are present, but there is no explicit user-facing disclosure or consent mechanism at the send point. In this skill's context the transmitted data is usually low sensitivity, but custom alert messages and trading-related information could still leak operational or personal details to an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · crypto_alert.py (reported line 63)May include surrounding context.

python
def send_telegram(message, bot_token, chat_id):
    if not bot_token or not chat_id:
        return
    url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
    payload = {"chat_id": chat_id, "text": message, "parse_mode": "HTML"}
    requests.post(url, json=payload, timeout=10)

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This code sends data to the Telegram API over the network, which is an external transmission channel. In context this is expected functionality, but it still creates privacy and data-governance risk because alert messages, potentially including user-authored content or trading signals, leave the local environment and are delivered to a third party.

Content

Scanner excerpt · crypto_alert.py (reported line 65)May include surrounding context.

python
return
    url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
    payload = {"chat_id": chat_id, "text": message, "parse_mode": "HTML"}
    requests.post(url, json=payload, timeout=10)

if __name__ == "__main__":
    config_path = os.path.join(os.path.dirname(__file__), "crypto-alerts.json")

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description presents file delivery as a supported alert destination alongside console and Telegram. In practice, the code always prints to console, optionally sends Telegram messages, and appends triggered alerts to a hard-coded /tmp/crypto_alerts_triggered.json path with no user-facing file delivery configuration, which is weaker than the claimed capability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.