Back to skill

Security audit

Cardano Balances

Security checks for vulnerabilities and agentic risk

Overview

This skill is read-only in intent, but it asks for a full Cardano wallet seed phrase and installs an unpinned external MCP package.

Review carefully before installing. Use this only with a wallet setup you are comfortable exposing to the MCP process, and prefer a watch-only address or public-key based method instead of a seed phrase. Do not provide the recovery phrase for a wallet holding meaningful funds unless the dependency and runtime isolation have been independently reviewed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party MCP Package Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13-15
Vulnerability Type: Unpinned executable dependency
Risk Level: Medium

Vulnerable Code:

yaml
    install:
      - kind: node
        package: "@indigoprotocol/cardano-mcp"

Technical Analysis

The skill instructs the runtime to install the npm package @indigoprotocol/cardano-mcp without specifying an exact version or integrity hash. Consequently, the package contents installed in the future may differ from those available when the skill was audited.

The repository does not contain the package source, a lockfile, an integrity value, or other controls that would allow the installed artifact to be verified against a reviewed version. Because npm packages can contain lifecycle scripts and executable runtime logic, a compromised or unexpectedly modified release could execute code with the privileges granted to the skill process.

There is no evidence in the audited files that the named package is currently malicious. The vulnerability is the mutable and unverifiable trust relationship created by the unpinned installation configuration.

Attack Path

  1. An attacker compromises the npm publisher account, package distribution channel, or a future package release.
  2. The attacker publishes a modified version of @indigoprotocol/cardano-mcp.
  3. The skill installation process resolves the package without an exact version or integrity constraint.
  4. The modified package is installed and its lifecycle or runtime code executes.
  5. The package accesses the process environment, wallet credential, filesystem, or network resources available to the MCP process.
  6. The attacker may exfiltrate sensitive information or perform actions under the process account's permissions.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the account running the skill or MCP server. Because the skill also ...[truncated 286 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact, reviewed version rather than allowing mutable resolution:
    yaml
    install:
      - kind: node
        package: "@indigoprotocol/cardano-mcp"
        version: "X.Y.Z"
    
  2. Use a lockfile containing package integrity hashes and verify it during installation.
  3. Obtain the package only from a trusted registry and validate package provenance or signed release metadata where supported.
  4. Review the selected package version, including lifecycle scripts and transitive dependencies.
  5. Disable npm lifecycle scripts when they are unnecessary.
  6. Run the MCP server in a restricted environment with minimal filesystem access, outbound network access, and environment variables.
  7. Introduce an update-review process so dependency upgrades are explicitly audited before deployment.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:11
Finding

Full Wallet Seed Phrase Is Exposed to a Read-Only Balance Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:11-12
Vulnerability Type: Excessive credential privilege and sensitive secret exposure
Risk Level: High

Vulnerable Code:

yaml
    requires:
      env: [SEED_PHRASE]

The declared read-only purpose is documented separately in the same file:

markdown
Query wallet balances, addresses, and UTxOs on the Cardano blockchain.

Technical Analysis

A seed phrase is a wallet recovery credential capable of deriving private keys and conferring control over associated funds. The skill's documented functions are limited to querying balances, addresses, and UTxOs. Those operations do not inherently require access to a full wallet recovery secret; they can generally be implemented with public addresses or suitable watch-only public-key material.

Requiring SEED_PHRASE through a process environment variable violates least-privilege principles. It makes the secret available to the MCP process and potentially to dependency code, diagnostic tooling, crash handlers, child processes, or other components able to inspect that process environment.

The audited Markdown does not directly transmit, log, or misuse the seed phrase. The risk arises from granting wallet-control credentials to an external executable dependency for operations that are described as read-only.

Attack Path

  1. A user configures the required SEED_PHRASE environment variable.
  2. The Cardano MCP process starts in an environment containing the recovery secret.
  3. A compromised dependency, vulnerable MCP implementation, malicious update, debugging facility, or process-inspection capability reads the environment variable.
  4. The seed phrase is copied or transmitted outside the trusted environment.
  5. An attacker imports the phrase into another wallet and derives the corresponding private keys.
  6. The attacker signs and submits unauthorized transactions, potentially transferring as ...[truncated 528 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove SEED_PHRASE from the skill's required environment variables.
  2. For read-only queries, accept public Cardano addresses or an account-level extended public key with only the minimum required derivation scope.
  3. Use a dedicated watch-only wallet interface for balance, address, and UTxO inspection.
  4. If a future feature genuinely requires signing, isolate signing behind a hardware wallet or narrowly scoped signer that requires explicit user confirmation for every transaction.
  5. Never pass seed phrases through general process environment variables, command-line arguments, logs, prompts, or configuration files.
  6. Sandbox the MCP server and restrict its network, process, and filesystem permissions.
  7. Document the exact credential model and verify that read-only operations cannot invoke signing or export private key material.
  8. If a seed phrase has already been exposed to an untrusted process, create a new wallet from a newly generated seed and migrate the assets.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly requires a SEED_PHRASE environment variable, which is an extremely sensitive wallet secret that can authorize full control over the user's Cardano funds. Although the skill only claims to query balances and UTxOs, there is no warning about secret handling, no statement that the phrase must never be logged or exposed, and no indication that a less-privileged credential model is used, so the design unnecessarily increases the blast radius if the MCP server or surrounding tooling is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill documents a capability to retrieve all wallet addresses without any warning that addresses are sensitive identifiers that can be correlated with on-chain activity and wallet ownership. In a blockchain wallet context, exposing addresses can enable privacy loss, account profiling, and transaction tracing, especially if surfaced to an untrusted agent or third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents retrieval of all wallet UTxOs in CBOR hex format without warning that this reveals detailed wallet state, asset composition, and transaction-linked information. In Cardano, UTxO sets can be analyzed to infer balances, spending patterns, address relationships, and other sensitive financial metadata, making disclosure risky if users are not clearly warned.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example prompt "What's in my wallet?" is broad and conversational, which increases the chance the skill is invoked when a user did not explicitly intend a balance query. In a wallet context, unintended invocation can expose sensitive financial information such as balances and held assets, even though the skill itself is read-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.