Back to skill

Security audit

SushiSwap API

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward SushiSwap API documentation skill, but it needs review because it can generate executable crypto swap transaction payloads and has under-disclosed financial-safety and network-scope risks.

Install only if you intend agents to use SushiSwap API data and transaction-building endpoints. Configure clients to use only https://api.sushi.com, do not auto-sign or broadcast returned transactions, and require explicit review of chain ID, token addresses, sender, recipient, amount, slippage, price impact, fee receiver, tx.to, tx.value, and calldata before any wallet approval.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/openapi.yaml:12
Finding

Alternate Mock Server May Receive Financial and Wallet Metadata

Content
View full analysis

Vulnerability Details

File Location: references/openapi.yaml:12-17
Related Instruction: SKILL.md:28-36
Vulnerability Type: Unnecessary third-party network destination in API configuration
Risk Level: Medium

Vulnerable Code

yaml
servers:
  - description: Sushi API
    url: https://api.sushi.com
  # Added by API Auto Mocking Plugin
  - description: SwaggerHub API Auto Mocking
    url: https://virtserver.swaggerhub.com/sushi-labs/sushi/7.0.0

The Skill instructs agents to select behavior dynamically from this schema:

markdown
Agents must **always rely on the schema contents** rather than hardcoded assumptions.

## How To Use

1. Load `references/openapi.yaml`
2. Discover available endpoints, parameters, and response shapes dynamically
3. Select the appropriate endpoint based on user intent and schema tags

Technical Analysis

The OpenAPI document lists a SwaggerHub mock server as an alternative to the intended production server, https://api.sushi.com. Schema-driven clients can select any server declared by the specification. The Skill does not expressly forbid use of the mock server or require an allowlist containing only the production origin.

Swap requests can contain wallet addresses in sender and recipient, token addresses, transaction amounts, referrer identity, fee receiver, and route preferences. Sending these parameters to the mock service would expose financial metadata and trading intent to an additional third party. The mock server is not required to provide the Skill's declared production SushiSwap integration and therefore exceeds the minimum network scope necessary for that functionality.

This finding does not indicate access to private keys, seed phrases, signing capabilities, local files, or elevated system privileges. The exposed scope is limited to request metadata deliberately included in API calls, but that data may still identify wallets ...[truncated 1076 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the SwaggerHub mock server from the OpenAPI document distributed with the production Skill.
  2. Retain only https://api.sushi.com as an authorized server.
  3. Add an explicit instruction requiring agents and clients to reject all schema server URLs except the allowlisted production origin.
  4. If a mock server is required for development, place it in a separate development-only schema that is not shipped with the Skill.
  5. Validate the final request origin immediately before transmission.
  6. Avoid logging complete query strings containing wallet addresses, amounts, fee receivers, or other financial metadata.

T09 · Insecure Skill Coding Practices

Warning
Location
references/openapi.yaml:89
Finding

Unsafe Maximum Price-Impact Default Is Described as Safe

Content
View full analysis

Vulnerability Details

File Location: references/openapi.yaml:89-100 and references/OPENAPI.md:33-35
Vulnerability Type: Unsafe financial transaction default
Risk Level: Medium

Vulnerable Code

yaml
maxPriceImpact:
  in: query
  name: maxPriceImpact
  description: the max price impact for route planning. It's better to set it to a reasonable value, for example 1 (100%)
  required: false
  schema:
    type: number
    minimum: 0
    exclusiveMinimum: true
    maximum: 1
    default: 1

The accompanying guide characterizes schema defaults as safe:

markdown
## Parameters and defaults

- Optional parameters have safe defaults defined in the schema
- Numeric tolerances (slippage, price impact) are decimals (e.g. `0.005 = 0.5%`)
- Comma-separated lists (DEXes, pools, tokens) must be passed as strings

Technical Analysis

A maxPriceImpact value of 1 permits price impact of up to 100%. This provides no meaningful economic protection against severely unfavorable routing or illiquid markets. The parameter is optional, so an agent following the guide may omit it based on the explicit assertion that optional defaults are safe.

This issue is especially significant because the /swap/v7/{chainId} endpoint returns executable transaction fields, including tx.to, tx.data, tx.value, and tx.gas. Although the Skill does not sign or broadcast the transaction, a user or wallet may sign the generated transaction while incorrectly assuming that conservative safeguards were applied.

No system privileges or wallet signing authority are obtained through this flaw. Its scope is the economic safety of generated swap transactions and the assets a user voluntarily authorizes through a separate wallet.

Attack Path

  1. A user asks the agent to generate an executable swap transaction.
  2. The agent follows references/OPENAPI.md and assumes optional schema defaults are safe ...[truncated 862 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the 100% default with a conservative, documented price-impact threshold appropriate for ordinary swaps.
  2. Require an explicit user-approved maxPriceImpact value before requesting executable transaction data.
  3. Remove the statement that all optional schema defaults are safe unless every default has been independently reviewed.
  4. Display the quoted price impact, minimum expected output, slippage tolerance, token pair, amount, recipient, transaction destination, and native-token value before the user signs.
  5. Require additional confirmation when price impact exceeds a conservative threshold.
  6. Reject or prominently warn on swaps with extreme price impact rather than relying exclusively on the API maximum.
  7. Preserve the rule that transaction calldata must come from the API, but treat the returned transaction as untrusted until its destination and economic parameters have been validated.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/openapi.yaml (reported line 10)May include surrounding context.

yaml
openapi: 3.0.0
info:
  # You application title. Required.
  title: Sushi API
  # API version. You can use semantic versioning like 1.0.0,
  # or an arbitrary string like 0.99-beta. Required.
  version: 7.0.0

  # API description. Arbitrary text in CommonMark or HTML.
  description: Documentation for interacting with the Sushi API

servers:
  - description: Sushi API
    url: https://api.sushi.com
  # Added by API Auto Mocking Plugin
  - description: SwaggerHub API Auto Mocking
    url: https://virtserver.swaggerhub.com/sushi-labs/sushi/7.0.0
tags:
  - name: swap
    description: All swap endpoints
  - name: price
    description: All price endpoints
  - name: token
    description: All token endpoints
  - name: liquidity-providers
    description: All liquidity provider endpoints
  - name: other
    description: Other endpoints

components:
  parameters:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly enables generation of executable swap transaction data, which can directly lead to on-chain actions affecting user funds, yet it provides no safety guidance about transaction review, recipient/amount verification, slippage, approvals, chain validation, or the danger of blindly executing returned payloads. In an agent setting, describing transaction generation as a routine API operation without guardrails increases the risk that downstream automation will create or present high-risk transaction payloads without adequate user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The swap transaction endpoint constructs ready-to-submit transaction fields including destination address, calldata, gas, and value, yet the spec lacks a clear user-facing warning that this output can directly cause asset movement if executed. In an agent environment, presenting actionable transaction payloads without strong safety framing materially raises the risk of prompt confusion, unsafe automation, or social-engineering-driven fund loss.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This manifest-style OpenAPI file describes the swap capability in very broad natural language ('generate a swap quote') without any limiting context about when this skill should or should not be invoked. For manifest files, missing specificity around activation scope can increase the chance of unintended invocation by overlapping with generic 'swap' or 'quote' requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The /swap endpoint generates executable transaction data but its summary/description presents it broadly as just generating a swap, without strong distinction from a quote-only informational call. In an agent-skill context, this ambiguity increases the chance an LLM or user workflow invokes a transaction-building endpoint when only analysis or pricing was intended, enabling unintended high-risk blockchain actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.