Scan Report
20 /100
whale-alert-monitor
虚拟币大户账户预警监测助手 - 实时监控鲸鱼钱包动向、大额转账、交易所资金流向
鲸鱼监控技能功能正常,但存在硬编码支付API密钥的安全隐患,属于轻微配置问题而非恶意行为
Safe to install
将 BILLING_API_KEY 移至环境变量或配置文件,不要硬编码在源代码中
Findings 3 items
| Severity | Finding | Location |
|---|---|---|
| Medium | 支付API密钥硬编码 | payment.py:12 |
| Low | 第三方依赖无版本锁定 | N/A |
| Info | 模拟数据而非真实API | scripts/*.py |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Network | READ | READ | ✓ Aligned | 所有脚本使用 requests 库进行 API 调用 |
| Filesystem | NONE | NONE | — | 代码仅在本地目录读写配置和日志,无敏感路径访问 |
| Shell | NONE | NONE | — | 未使用 subprocess/os.system 等 shell 执行 |
1 High 24 findings
High API Key 疑似硬编码凭证
API_KEY = "sk_f03aa8f8bbcf79f7aa11c112d904780f22e62add1464e3c41a79600a451eb1d2" payment.py:12 Medium Wallet Address 加密货币钱包地址
0x742d35Cc6634C0532925a3b8D4E6D3b6e8d3e8D3 SKILL.md:78 Medium Wallet Address 加密货币钱包地址
0x3f5CE5FBFe3E9af3971dD833D26bA9b5C936f0bE SKILL.md:96 Medium Wallet Address 加密货币钱包地址
0x71660c4005BA85c37ccec55d0C4493E66Fe775d3 SKILL.md:101 Medium External URL 外部 URL
https://skillpay.me payment.py:11 Medium External URL 外部 URL
https://api.etherscan.io/api references/api-configuration.md:8 Medium External URL 外部 URL
https://eth-mainnet.g.alchemy.com/v2/ references/api-configuration.md:54 Medium External URL 外部 URL
https://deep-index.moralis.io/api/v2/ references/api-configuration.md:89 Medium External URL 外部 URL
https://eth-mainnet.g.alchemy.com/v2/KEY references/api-configuration.md:112 Medium External URL 外部 URL
https://eth-mainnet.g.alchemy.com/v2/$ references/api-configuration.md:137 Medium External URL 外部 URL
https://etherscan.io references/api-configuration.md:138 Medium External URL 外部 URL
https://bsc-dataseed.binance.org references/api-configuration.md:142 Medium External URL 外部 URL
https://bscscan.com references/api-configuration.md:143 Medium External URL 外部 URL
https://arb-mainnet.g.alchemy.com/v2/$ references/api-configuration.md:147 Medium External URL 外部 URL
https://arbiscan.io references/api-configuration.md:148 Medium External URL 外部 URL
https://opt-mainnet.g.alchemy.com/v2/$ references/api-configuration.md:152 Medium External URL 外部 URL
https://optimistic.etherscan.io references/api-configuration.md:153 Medium Wallet Address 加密货币钱包地址
0xdB3c617cDd2fBf0c8611C04A49d34C7B332e2BB6 references/wallet-labels.md:8 Medium Wallet Address 加密货币钱包地址
0x5a52E96BAcdaBb82fd05763E25335261B270Efcb references/wallet-labels.md:9 Medium Wallet Address 加密货币钱包地址
0x503828976D22510aad0201ac7EC88293211D23Da references/wallet-labels.md:15 Medium Wallet Address 加密货币钱包地址
0x6b75d8AF000000e20B7a7DD000000090D0000000 references/wallet-labels.md:20 Medium Wallet Address 加密货币钱包地址
0xf89d7b9c864f589bbF53f821d7EfC68c91d70958 references/wallet-labels.md:25 Medium Wallet Address 加密货币钱包地址
0x2B6eD29a95753C3Ad948348e3e7b1A251039FBB9 references/wallet-labels.md:30 Medium External URL 外部 URL
https://api.telegram.org/bot scripts/alert_manager.py:149 File Tree
11 files · 74.5 KB · 2441 lines Python 7f · 1864L
Markdown 3f · 558L
JSON 1f · 19L
├─
▾
references
│ ├─
api-configuration.md
Markdown
│ └─
wallet-labels.md
Markdown
├─
▾
scripts
│ ├─
alert_manager.py
Python
│ ├─
exchange_flow.py
Python
│ ├─
holding_analyzer.py
Python
│ ├─
monitor_daemon.py
Python
│ ├─
transfer_monitor.py
Python
│ └─
whale_tracker.py
Python
├─
_meta.json
JSON
├─
payment.py
Python
└─
SKILL.md
Markdown
Dependencies 1 items
| Package | Version | Source | Known Vulns | Notes |
|---|---|---|---|---|
requests | * | pip | No | 无版本锁定,建议锁定版本如 requests>=2.28.0 |
Security Positives
✓ 文档与代码功能一致,无阴影功能
✓ 未使用 shell 命令执行,无远程代码注入风险
✓ 未访问敏感文件路径(~/.ssh、.env等)
✓ 无 base64/eval 等可疑编码执行
✓ 通知发送使用环境变量配置,不存在凭证收割
✓ 代码结构清晰,纯业务逻辑,无恶意行为