Back to skill

Security audit

DeFi

Security checks for vulnerabilities and agentic risk

Overview

This is an advisory-only DeFi analysis skill that is clear about not accessing wallets, signing transactions, or executing on-chain actions.

Install only if you want advisory DeFi risk and yield analysis. Do not paste seed phrases, private keys, wallet credentials, or anything needed to control funds; for tax summaries, provide only the transaction records you are comfortable sharing and have a qualified professional review filing decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes the skill as a protocol risk analyst and yield reality checker focused on protocol safety, real yield, and rug-risk patterns. Example 4 advertises analyzing user transaction logs for taxable events and producing an accountant-friendly summary, which is a separate tax-classification capability not covered by the stated description.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a manifest file, so vague-trigger review applies. Phrases like "bridge risk", "staking risk", and "liquidity pool analysis" are short, generic topic labels without explicit invocation constraints or negative examples, which could cause unintended activation during ordinary conversation about DeFi topics.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.