Back to skill

Security audit

ATXSwap

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent ATX/BSC wallet and trading skill, but it handles real wallet credentials and encrypted keystore backups in ways users should review before installing.

Install only if you are comfortable letting an agent manage a BSC wallet with real assets. Use a strong unique wallet password, keep balances limited, inspect every proposed transaction, prefer protected local keystore exports over chat/session delivery, and avoid non-interactive commands that place the wallet password in command-line arguments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_helpers.js:139
Finding

Wallet Password Exposure Through Command-Line Arguments

Content
View full analysis
or run in an interactive terminal"); } ``` The Skill instructions explicitly direct the agent to use this mechanism: ```text When the user asks to create a wallet: 1. Ask the user for a password first (do NOT generate one). 2. Pass it via `--password ` to the script when running non-interactively. 3. The password is auto-saved to secure storage after creation. 4. Never print the password back to the chat. ``` The same command-line password is also used while loading an existing wallet: ```js export async function loadWallet(client, address, args) { try { return await client.wallet.load(address); } catch { if (args.password) { return await client.wallet.load(address, args.password); } const ttyPassword = await promptHidden(`Password for ${address}: `); if (ttyPassword) { return await client.wallet.load(address, ttyPassword); } exitError(`Password required for ${address}: use --password or run in an interactive terminal`); } } ``` ### Technical Analysis Supplying a wallet password as `--password ` places the secret in the process argument vector. Depending on the operating system and execution environment, command-line arguments may be exposed through: - Process inspection facilities such as `/proc//cmdline` or process-monitoring tools. - Shell history. - Agent tool-call transcripts and execution logs. - CI/CD, terminal, audit, or endpoint-monitoring telemetry. - Error reports that capture the executed comma ...[truncated 1265 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wallet.js:74
Finding

Exported Keystore Files Are Created Without Explicit Restrictive Permissions

Content
View full analysis
--out `. 2. The process writes the encrypted keystore using the destination's existing permissions or permissions derived from the process umask. 3. Another local user or process reads the resulting file, or an attacker-controlled symbolic link redirects the write to an unintended accessible location. 4. The ...[truncated 781 chars]
Remediation
View remediation

other

Warning
Location
SKILL.md:101
Finding

Automatic Session Transmission of Encrypted Wallet Backup Material

Content
View full analysis
` to the script when running non-interactively. 3. The password is auto-saved to secure storage after creation. 4. Never print the password back to the chat. 5. After the wallet is created, export and send the encrypted keystore backup to the user who requested the wallet. 6. Clearly label it as encrypted keystore backup material, not the raw private key. 7. Do not upload it to any website or send it to any third party. ``` The mandatory handoff is repeated in the hard safety rules: ```text 13. After `wallet.js create` succeeds, export and send the encrypted keystore to the user who requested the wallet. Treat this as part of the wallet creation handoff, but only to that user. ``` ### Technical Analysis The instructions do not direct the keystore to an attacker-controlled endpoint or unrelated third party. They explicitly limit delivery to the requesting user. Therefore, the behavior is not confirmed private-key exfiltration. Nevertheless, automatically exporting and sending the encrypted keystore through the agent session moves sensitive wallet backup material beyond its protected local storage. Agent responses and file attachments may pass through or be retained by: - API gateways and model-service infrastructure. - Conversation history storage. - Agent observability and debugging systems. - Client-side logs, browser storage, or notification systems. - Session participants or integrations with access to the conversation. The transmission is not necessary for wallet creation or normal wallet operation. A protected local backup file and its path would satisfy the default backup requirement ...[truncated 1443 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is narrowly focused on transfer operations. It parses a transfer subcommand, loads an existing wallet, and sends BNB, ATX, USDT, or a specified token. While BNB/ERC20-style transfers are part of the declared description, the declared purpose presents the skill as a much broader management tool including wallet creation, market data, swaps, liquidity, and LP position features, none of which appear in this chunk. There are no obvious undeclared dangerous capabilities beyond transfers, but the actual behavior of this code chunk is materially narrower than the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad ATX/BSC/PancakeSwap management skill covering swaps, liquidity, LP positions, holdings, and transfers. The supplied code chunk is much narrower and focused on wallet administration. It includes sensitive capabilities not explicitly described, especially keystore export and wallet deletion, plus password-state management. While wallet creation and balance queries are consistent with the description, the primary behavior of this specific chunk does not match the broader declared functionality, and it exposes undeclared wallet-security operations.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
- **SDK**: [`atxswap-sdk`](https://www.npmjs.com/package/atxswap-sdk) on npm ([source](https://github.com/agentswapx/atxswap-sdk))
- **Docs (team / project)**: [Team introduction (EN)](https://docs.atxswap.com/guide/team) · [Team introduction (ZH)](https://docs.atxswap.com/zh/guide/team)
- **Keystore dir**: `~/.config/atxswap/keystore` (fixed, not configurable)
- **Secrets dir**: `~/.config/atxswap/` (master.key + secrets.json)

## Use This Skill For

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
- **SDK**: [`atxswap-sdk`](https://www.npmjs.com/package/atxswap-sdk) on npm ([source](https://github.com/agentswapx/atxswap-sdk))
- **Docs (team / project)**: [Team introduction (EN)](https://docs.atxswap.com/guide/team) · [Team introduction (ZH)](https://docs.atxswap.com/zh/guide/team)
- **Keystore dir**: `~/.config/atxswap/keystore` (fixed, not configurable)
- **Secrets dir**: `~/.config/atxswap/` (master.key + secrets.json)

## Use This Skill For

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
1. Open the skill directory where this `SKILL.md` is installed.

Known Vulnerable Dependency: ws==8.18.3 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile pins a known vulnerable version of the ws WebSocket library (8.18.3) via viem, and the cited advisories indicate memory disclosure and memory-exhaustion denial of service issues. In a blockchain trading/wallet skill, WebSocket connectivity is commonly used for RPC/event subscriptions, so an attacker-controlled or malicious upstream endpoint could potentially crash the process or expose memory contents during network interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes natural-language content stating that SKILL.md is "English-only." Per the policy, forcing a specific language without user opt-in is a reportable locale/language policy violation unless clearly justified as region-specific, which is not shown here.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 128)May include surrounding context.

md
5. Before deleting a wallet, require the user to export and back up the encrypted keystore first.
6. Wallet deletion requires a second confirmation: the user must explicitly send `force delete wallet`.
7. For transfers, always treat `(asset, from, to, amount)` as one unique transfer intent and restate it before execution.
8. Once a transfer command returns a `txHash`, treat that transfer as already sent; do not automatically send the same transfer again unless the user explicitly asks for another send.
9. If transfer submission status is ambiguous due to timeout, RPC failure, or interrupted output, do not retry blindly; first inspect chain state or wallet state, then ask the user whether to retry.
10. For present-tense questions about balances, holdings, LP positions, pending fees, or remaining assets, always refresh from live on-chain queries first; never answer from earlier chat output, memory, or cached values alone.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill performs sensitive wallet and blockchain operations while declaring no explicit tool scope or permissions boundaries. In an agent runtime, this increases the chance the skill can access environment-derived paths and invoke broader capabilities than a reviewer or user expects, reducing containment for high-risk asset-handling workflows.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The skill is explicitly designed to create and retain a single persistent wallet and associated credentials across sessions. Persistent wallet state in an agent skill raises security risk because compromise of the host, runtime, or associated secret store could enable unauthorized future transactions involving real assets.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
## Use This Skill For

- Create the single wallet used by this skill instance (importing an existing private key is not supported)
- Query ATX price, balances, LP positions (see **Required agent reply for holdings** under `query.js`), quotes, and arbitrary ERC20 token info
- Buy or sell ATX against USDT on PancakeSwap V3
- Add liquidity (full range or a custom **price range in USDT per ATX** or **tick** bounds), remove liquidity, collect fees, or burn empty LP NFTs

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The burn command directly executes client.liquidity.burnPosition(wallet, BigInt(tokenId)) after only checking that a tokenId was provided, with no confirmation, dry-run, or explicit warning that the action is irreversible. In a wallet-management skill for on-chain liquidity positions, this increases the chance of accidental destruction of a position NFT or user misuse through ambiguous prompting, especially because blockchain transactions cannot be undone once signed and broadcast.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The export command writes a wallet keystore containing highly sensitive recovery material to any caller-supplied filesystem path, with no safety checks, path restrictions, permission hardening, or explicit warning/confirmation before doing so. In a wallet-management skill, this is especially dangerous because a mistaken or manipulated output path can leak credentials to shared, synced, web-served, or otherwise monitored locations, enabling wallet compromise if the attacker can obtain the file and password.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
85% confidence
Finding

The dependency is version-ranged with a caret, which allows newer minor and patch releases of atxswap-sdk to be installed without explicit review. In a wallet and token-trading skill, a compromised or malicious upstream release could alter transaction logic, exfiltrate secrets, or redirect funds, making supply-chain drift materially risky.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
"check:wallets": "node scripts/wallet.js list"
  },
  "dependencies": {
    "atxswap-sdk": "^0.0.15"
  }
}

Static analysis

No suspicious patterns detected.