Back to skill

Security audit

Indigo Staking

Security checks for vulnerabilities and agentic risk

Overview

This INDY staking skill is purpose-aligned, but its transaction instructions are inconsistent enough that users should review it carefully before using it with real funds.

Install only if you are prepared to manually verify every generated transaction in a trusted wallet or transaction inspector. Confirm the caller address, staking UTxO transaction hash and output index, all outputs, fees, and INDY amounts in both whole tokens and smallest units before signing, and avoid querying wallet-linked owner addresses without consent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/mcp-tools.md:47
Finding

Conflicting MCP Schemas Can Produce Incorrect Staking Transactions

Content
View full analysis

Vulnerability Details

File Location: references/mcp-tools.md:47-91, sub-skills/staking-manage.md:11-120, sub-skills/staking-rewards.md:12-25, and sub-skills/staking-query.md:55-67
Vulnerability Type: Inconsistent financial transaction schemas and token-unit handling
Risk Level: Medium

Vulnerable Documentation

The authoritative MCP reference defines the opening operation as requiring a Cardano address and an amount expressed as a string in the token's smallest unit:

markdown
### open_staking_position

Open a new INDY staking position by locking INDY tokens.

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `address` | `string` | Yes | User Cardano bech32 address |
| `amount` | `string` | Yes | Amount of INDY to stake (smallest unit) |

However, the management workflow omits the required address, changes the amount type to a number, and treats the value as whole INDY:

markdown
### open_staking_position

Open a new INDY staking position by locking INDY tokens. Staked INDY earns ADA rewards from protocol fees and grants governance voting power proportional to the staked amount.

**Parameters:**

| Parameter | Type | Required | Description |
|-----------|------|----------|-------------|
| `amount` | number | Yes | Amount of INDY to stake |

**Returns:** Transaction CBOR to be signed and submitted.

**Example — Stake 1000 INDY:**

User: "Open a new staking position with 1000 INDY"

Tool call: open_staking_position({ amount: 1000 })

text

Similar conflicts affect position adjustment. The MCP reference requires a caller address and explicit UTxO coordinates:

markdown
### adjust_staking_position

Adjust an existing staking position — add or remove staked INDY.

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `address` | `string` | Yes | User Cardano bech32 address |
| `stakingTxHash` | `string` | Yes | Staking position UTxO transaction hash |
| `sta
...[truncated 5882 chars]
Remediation
View remediation

Remediation Suggestions

  1. Establish one authoritative, machine-readable MCP schema and generate all reference tables and examples from it.
  2. Use identical parameter names, types, and meanings in every file:
    • Define whether address is the caller's wallet address or the staking-position address.
    • Require stakingTxHash and stakingOutputIndex consistently when UTxO coordinates are needed.
    • Use either owner or owners, with one consistent type.
    • Define whether reward distribution requires a caller address.
  3. Represent financial quantities as decimal strings rather than floating-point numbers.
  4. State the unit in every amount field and example. If the MCP endpoint expects smallest units, convert explicitly:
    • 1 INDY = 1,000,000 smallest units.
    • 1,000 INDY = "1000000000" smallest units.
  5. Before returning CBOR for signing, independently decode and validate the transaction. Display:
    • Network identifier.
    • Inputs and selected staking UTxO.
    • All outputs and recipient addresses.
    • INDY amount in both whole tokens and smallest units.
    • ADA rewards, deposits, and network fee.
    • Resulting total stake or withdrawal amount.
  6. Require explicit user confirmation of the normalized amount, selected position, outputs, and fee before presenting the transaction for signing.
  7. Reject ambiguous requests when a user owns multiple staking positions rather than selecting a position automatically.
  8. Add contract tests that execute every documented example against the actual MCP schema and fail on missing fields, incorrect parameter names, or denomination mismatches.
  9. Add boundary tests for zero, negative, fractional, minimum, and maximum amounts, along with Cardano network and address validation.
  10. Update all workflow documents together whenever the MCP interface changes to prevent schema drift.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file documents multiple financial write operations that produce unsigned transaction CBOR, but it does not warn users that these actions can open, modify, or close staking positions and may move or lock funds. In a wallet-integrated or agent-driven context, users may approve transactions they do not fully understand, increasing the risk of unintended asset movement, loss of rewards, or irreversible staking changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly encourages querying staking positions by owner address and presenting balances and accrued rewards, but it provides no privacy warning or guidance about consent. Because stake addresses are wallet-linked identifiers, using them can reveal a user's financial holdings and activity to the operator or any observer of prompts/logs, creating a real privacy and profiling risk even though the tool is read-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.