Back to skill

Security audit

Indigo Stability

Security checks for vulnerabilities and agentic risk

Overview

This is a focused Indigo Protocol stability-pool helper that builds unsigned transactions for user-directed DeFi actions, with no hidden code or persistence in the submitted artifacts.

Before installing, understand that this skill can help prepare unsigned Cardano transactions for Indigo Stability Pool deposits, withdrawals, closures, and request processing. Review asset, amount, address, UTxO, and expected effect in your wallet before signing, and separately trust or audit the required @indigoprotocol/indigo-mcp server.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation describes write operations that affect user funds and notes they return an unsigned transaction, but it does not explicitly warn users that these actions can move assets, create withdrawals, or require careful review before signing. In a wallet-integrated or agent-driven context, this omission can lead users to approve financially impactful transactions without understanding the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description states that close_sp_account withdraws all deposits and claims rewards, but it is presented as a normal operation without a clear caution banner or user warning. For markdown skill documentation, operations affecting user assets or causing irreversible account state changes should include explicit warnings about impact and review before signing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill guides users through processing and annulling stability-pool requests that produce unsigned transaction CBOR for signing, but it does not prominently warn that signing will authorize on-chain financial state changes that may be irreversible once submitted. In a DeFi context, omission of clear signing/finality warnings can mislead users into approving transactions they do not fully understand, increasing the risk of unintended fund movements or account-state changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file includes the example trigger "Show my stability pool accounts," which is relatively broad natural language and does not define exclusion conditions or tighter activation scope. Without additional constraints, similar everyday account-viewing requests could ambiguously invoke this skill when the user may not specifically intend a stability-pool query workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.