Scan Report
20 /100
TronLink Wallet Skills
AI Agent技能集,用于TRON网络钱包管理、TRC-20代币查询、市场数据、DEX交换、Energy/Bandwidth资源管理和TRX质押
TronLink钱包技能核心功能为纯只读操作,代码干净无恶意行为;install.sh中的curl|sh是文档化的安装机制,存在理论风险但来源可信。
Safe to install
可安全使用。建议:1) 优先使用本地git clone而非curl|sh;2) 安装前检查install.sh哈希;3) 确认TRONGRID_API_KEY仅用于API认证不外泄。
Findings 2 items
| Severity | Finding | Location |
|---|---|---|
| Medium | 远程脚本执行安装机制 Supply Chain | README.md:16 |
| Low | 安装脚本执行本地文件操作 Priv Escalation | install.sh:54 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | NONE | READ | ✓ Aligned | SKILL.md声明只读,但install.sh执行文件操作用于安装 |
| Network | READ | READ | ✓ Aligned | tron_api.mjs:48-56 仅调用TronGrid/TronScan/CoinGecko公开API |
| Shell | NONE | NONE | — | tron_api.mjs无subprocess调用;mcp_server.mjs仅execFile运行tron_api.mjs |
| Environment | NONE | READ | ✓ Aligned | 仅读取TRONGRID_API_KEY/TRON_NETWORK用于配置,无敏感信息外泄 |
2 Critical 21 findings
Critical Dangerous Command 危险 Shell 命令
curl -sSL https://raw.githubusercontent.com/TronLink/tronlink-skills/main/install.sh | sh README.md:16 Critical Dangerous Command 危险 Shell 命令
curl -sSL https://raw.githubusercontent.com/TronLink/tronlink-skills/main/uninstall.sh | sh README.md:28 Medium External URL 外部 URL
https://www.trongrid.io/dashboard README.md:106 Medium External URL 外部 URL
https://api.trongrid.io README.md:120 Medium External URL 外部 URL
https://api.shasta.trongrid.io README.md:121 Medium External URL 外部 URL
https://nile.trongrid.io README.md:122 Medium External URL 外部 URL
https://trongrid.io SKILL.md:8 Medium External URL 外部 URL
https://www.trongrid.io/dashboard. docs/claude-integration-guide.md:207 Medium External URL 外部 URL
https://nodejs.org install.sh:271 Medium External URL 外部 URL
https://paulmillr.com/funding/ package-lock.json:55 Medium External URL 外部 URL
https://www.buymeacoffee.com/ricmoo package-lock.json:281 Medium External URL 外部 URL
https://apilist.tronscanapi.com/api scripts/tron_api.mjs:30 Medium External URL 外部 URL
https://docs.sun.io/developers/swap/smart-router scripts/tron_api.mjs:35 Medium External URL 外部 URL
https://rot.endjgfsv.link scripts/tron_api.mjs:37 Medium External URL 外部 URL
https://tnrouter.endjgfsv.link scripts/tron_api.mjs:38 Medium External URL 外部 URL
https://api.coingecko.com/api/v3 scripts/tron_api.mjs:43 Medium External URL 外部 URL
https://tronscan.org/#/token20/$ scripts/tron_api.mjs:594 Medium External URL 外部 URL
https://sunswap.com scripts/tron_api.mjs:766 Medium External URL 外部 URL
https://tronscan.org/#/transaction/$ scripts/tron_api.mjs:810 Medium External URL 外部 URL
https://tronnrg.com scripts/tron_api.mjs:909 Medium External URL 外部 URL
https://justlend.org scripts/tron_api.mjs:910 File Tree
19 files · 150.7 KB · 4345 lines JavaScript 2f · 1703L
Markdown 11f · 1432L
JSON 3f · 660L
Shell 3f · 550L
├─
▾
docs
│ ├─
claude-integration-guide.md
Markdown
│ ├─
integration-guide.sh
Shell
│ ├─
resource-model.md
Markdown
│ └─
staking-guide.md
Markdown
├─
▾
scripts
│ ├─
mcp_server.mjs
JavaScript
│ └─
tron_api.mjs
JavaScript
├─
▾
skills
│ ├─
▾
tron-market
│ │ └─
SKILL.md
Markdown
│ ├─
▾
tron-resource
│ │ └─
SKILL.md
Markdown
│ ├─
▾
tron-staking
│ │ └─
SKILL.md
Markdown
│ ├─
▾
tron-swap
│ │ └─
SKILL.md
Markdown
│ ├─
▾
tron-token
│ │ └─
SKILL.md
Markdown
│ └─
▾
tron-wallet
│ └─
SKILL.md
Markdown
├─
_meta.json
JSON
├─
install.sh
Shell
├─
package-lock.json
JSON
├─
package.json
JSON
├─
README.md
Markdown
├─
SKILL.md
Markdown
└─
uninstall.sh
Shell
Dependencies 3 items
| Package | Version | Source | Known Vulns | Notes |
|---|---|---|---|---|
fetch | native (Node.js 18+) | built-in | No | 无外部依赖 |
crypto | native (Node.js) | built-in | No | 无外部依赖 |
package-lock.json | N/A | npm | No | 仅Node.js内置模块,无第三方依赖 |
Security Positives
✓ tron_api.mjs核心功能为纯只读操作,无subprocess/child_process调用
✓ 使用Node.js原生模块(fetch/crypto),零第三方依赖,无供应链风险
✓ 所有API调用指向合法公开端点(TronGrid/TronScan/CoinGecko),无可疑网络目标
✓ Base58Check地址验证为本地实现,无eval/base64/混淆
✓ mcp_server.mjs仅execFile运行tron_api.mjs,无shell注入
✓ SKILL.md功能声明与实际代码完全一致,无阴影功能
✓ 不访问~/.ssh、.env等敏感路径,无凭证收割行为
✓ package.json声明空依赖,package-lock.json仅为Node.js内置依赖