Back to skill

Security audit

Cavos Cli

Security checks for vulnerabilities and agentic risk

Overview

This wallet skill is purpose-aligned, but it asks agents to run an unpinned third-party CLI for sensitive session and on-chain operations without enough safety scoping.

Review before installing. Use only a trusted, pinned, audited Cavos CLI version, avoid passing session tokens through untrusted runtime installs, and require explicit confirmation of network, token, amount, recipient, spender, contract, entrypoint, and calldata before any transaction-changing command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:15
Finding

Unpinned Third-Party CLI Execution in Wallet Operations

Content
View full analysis
``` ``` The same unpinned `npx @cavos/cli` invocation pattern is also used for balance queries, transfers, token approvals, arbitrary contract execution, multicalls, simulation, and transaction-status operations throughout lines 31–66. ### Technical Analysis The Skill executes `@cavos/cli` by package name without specifying an audited version, integrity hash, lockfile, or verified local installation. Depending on the environment and local package availability, `npx` can retrieve and immediately execute a package release from the configured npm registry. Consequently, the code executed by this reviewed Skill is not immutable. A future package update, compromised publisher account, registry compromise, or malicious dependency introduced into the package could change the effective behavior without any corresponding change to `SKILL.md`. This is particularly security-sensitive because the CLI is instructed to handle session tokens and perform asset transfers, approvals, and arbitrary Starknet contract calls. Malicious package code would execute with the operating-system privileges, environment access, filesystem access, and network access granted to the agent process. ### Attack Path 1. An attacker compromises the `@cavos/cli` publisher account, its release process, or a transitive dependency. 2. The attacker publishes a malicious release under the expected package name. 3. An ag ...[truncated 1596 chars]
Remediation
View remediation
whoami --json ``` 2. Prefer installing the audited version ahead of time through a committed lockfile containing registry resolution and integrity metadata. Do not permit arbitrary runtime dependency resolution. 3. Invoke the verified local binary with network installation disabled: ```bash npx --no-install cavos whoami --json ``` Alternatively, execute the package binary directly from a controlled installation. 4. Verify the package source, maintainer identity, release provenance, integrity data, and transitive dependency tree before approving a version. Require a new review before upgrading. 5. Run the CLI in a sandbox with minimal filesystem, environment, and network access. Expose only the credentials and wallet permissions required for the current operation. 6. Apply restrictive wallet session policies, including transaction-value limits, approved contract and token allowlists, short expiration periods, and narrowly scoped methods. 7. Require explicit confirmation of transaction-critical fields—including network, recipient, token, amount, spender, contract, entrypoint, and calldata—before signing or submission. 8. Avoid passing session tokens directly on the command line where they may be retained in shell history or exposed through process inspection. Use a documented secure input mechanism if the CLI supports one. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (12)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill invokes npx @cavos/cli without pinning an exact package version, which causes runtime installation or resolution of whatever package version is current at execution time. This creates a supply-chain risk: a compromised upstream release, typo-squatted dependency path, or breaking change could lead to arbitrary code execution in the agent environment, and the risk is amplified because this CLI is used for wallet and transaction operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command uses npx @cavos/cli with no pinned version, meaning execution depends on the latest package state rather than a reviewed artifact. Because the tool manages authenticated wallet sessions, an upstream compromise or malicious update could expose credentials, alter outputs, or perform unintended actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using unpinned npx @cavos/cli for session import introduces supply-chain exposure at the moment sensitive session tokens are handled. A malicious or unexpected package version could capture imported tokens, modify session state, or leak secrets from the environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The balance command references an unpinned npx package, so the executed code may differ from what was reviewed when the skill was authored. While balance checks are read-only in intent, the invoked package still runs arbitrary JavaScript in the environment and can misreport wallet information or exfiltrate data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents token transfers and approvals but does not provide an explicit warning that these are irreversible on-chain actions and that approvals can authorize third parties to spend assets. In this context, the omission is dangerous because the skill is specifically for wallet operations, so users may execute financially destructive commands without clear safety framing or confirmation expectations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

An unpinned npx @cavos/cli is especially dangerous in a transfer command because any compromised or changed upstream package could tamper with destination, amount, token selection, or transaction-signing behavior. In this wallet context, a supply-chain issue can directly lead to irreversible loss of funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The approve command relies on an unpinned package, exposing the workflow to supply-chain compromise during an operation that can grant token spending rights. A malicious or altered CLI could increase approval amounts, change spenders, or hide dangerous approval semantics, potentially enabling theft far beyond a single transfer.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Executing arbitrary contract methods through an unpinned npx package combines supply-chain risk with high-impact blockchain actions. A compromised package could alter calldata, substitute contract addresses, or conceal the true transaction being submitted, resulting in unauthorized on-chain execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Although this command is framed as a read call, it still executes code fetched via unpinned npx, leaving the environment exposed to arbitrary package behavior. A malicious or changed package could falsify outputs, mislead downstream decisions, or exfiltrate wallet/session information.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Multicall batches several on-chain actions, so using an unpinned npx @cavos/cli here magnifies the blast radius of any malicious package change. A compromised CLI could inject, reorder, or mutate batched calls and cause multiple unauthorized transactions in a single workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Even for simulation, an unpinned package introduces supply-chain risk because the downloaded code can execute arbitrarily and potentially present misleading previews. In a wallet management context, false simulation results can cause the operator to trust unsafe transactions or workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The transaction-status command uses unpinned npx, so reviewed behavior is not stable across executions and arbitrary code may run when checking transaction state. Misreported status can trigger incorrect operational decisions, especially in financial workflows where retries or follow-up actions depend on accurate state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.