Back to skill

Security audit

vybes.fun

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly documents a Solana launchpad API, but it also ships an undisclosed administrative reserve-changing page with wallet-signing code and weaker-than-expected safeguards around wallet identity and payments.

Review this carefully before installing. The public API functions may be useful, but the package includes an undisclosed admin reserve tool and asks users to rely on wallet-address identity, external website handoff, and irreversible SOL payment flows. Do not use the admin page or approve wallet prompts unless you control the named authority wallet and have independently verified the transaction details.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skill.md:24
Finding
State-Changing API Operations Rely on an Unsigned Wallet Address as Identity<![CDATA[ ## Vulnerability Details **File Location**: `skill.md`, lines 24-28; state-changing request examples at lines 47-60, 119-131, and 291-298 **Vulnerability Type**: Broken authentication and wallet impersonation **Risk Level**: High The documented authentication model states that no API key is required and that a wallet address is used as identity: ```markdown - **Base URL**: `https://vybes.fun` - **Auth**: No API keys. Wallet address is identity. Rate limiting prevents abuse. - **Token Launch Fee**: FREE (no cost) - **Website Fee**: 0.2 SOL - **Rate Limits**: 10 launches/hour per wallet, 10 predictions/day per wallet ``` State-changing requests consequently contain only a caller-supplied wallet address and no wallet signature, nonce, challenge, session credential, or other proof of key ownership. For example: ```http POST /api/agent/launch Content-Type: application/json { "agentWallet": "YOUR_WALLET_ADDRESS", "name": "My Token", "symbol": "MTK", "description": "A cool token", "imageUrl": "https://example.com/logo.png", "twitterUrl": "https://x.com/mytoken", "telegramUrl": "https://t.me/mytoken", "discordUrl": "https://discord.gg/mytoken" } ``` The website-linking operation is documented similarly: ```http POST /api/token/link-project Content-Type: application/json { "token_id": "TOKEN_UUID", "project_url": "https://my-token.aicre8.app", "wallet": "CREATOR_WALLET" } ``` ### Technical Analysis A Solana public address is public identification data, not an authentication secret. Any caller can learn another user's address from the blockchain and place it in an HTTP request. Rate limiting does not prove possession of the associated private key and cannot prevent impersonation. Under the declared protocol, operations such as token launch, prediction creation, build-job handoff, project linking, and activity lookup do not carry cryptographic proof that the requester controls the supplied wallet. Unless an undocumented server-sid ...[truncated 1973 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Require cryptographic proof of wallet ownership for every authenticated or state-changing operation. 2. Implement a Sign-In with Solana-style challenge flow: - Generate a server-side, single-use nonce. - Bind the challenge to the origin, wallet address, intended action, request digest, issuance time, and expiration time. - Require the wallet to sign the exact challenge. - Verify the Ed25519 signature server-side against the supplied public key. - Atomically consume the nonce to prevent replay. 3. Issue a short-lived, secure session token after successful signature verification and bind it to the verified wallet. 4. Never authorize an operation from a wallet address supplied in the request body alone. Derive the acting wallet from the authenticated session. 5. For high-impact operations such as project linking, require an action-specific signature and verify token ownership or creator authority server-side. 6. Retain independent on-chain validation for payments and bets, including destination, amount, mint or market identifier, memo, finality, and transaction uniqueness. 7. Apply rate limits only after authentication and key them to both the verified wallet and abuse-resistant network/device signals. 8. Document the required signature and replay-protection fields in every API example. ]]>

T03 · Remote Payload Retrieval and Execution

Error
Location
admin-set-reserves.html:38
Finding
Administrative Wallet Page Executes Mutable Third-Party JavaScript Without Integrity Pinning<![CDATA[ ## Vulnerability Details **File Location**: `admin-set-reserves.html`, line 38; privileged transaction submission at lines 173-186 **Vulnerability Type**: Remote code retrieval in a privileged wallet-signing context **Risk Level**: High The administrative page loads executable JavaScript directly from a third-party CDN: ```html <script src="https://unpkg.com/@solana/web3.js@1.95.3/lib/index.iife.min.js"></script> ``` The remotely supplied library executes in the same origin and JavaScript context as code that accesses Phantom and requests an administrative transaction signature: ```javascript log('Requesting Phantom signature...'); log('(Check your Phantom wallet for approval)'); try { const { signature } = await wallet.signAndSendTransaction(tx); log('Transaction sent: ' + signature); log('Waiting for confirmation...'); await connection.confirmTransaction(signature, 'confirmed'); log('CONFIRMED! Reserves updated to ' + label); setStatus('Success! Reserves set to ' + label, 'ok'); } catch (e) { log('ERROR: ' + e.message); setStatus('Transaction failed', 'err'); } ``` ### Technical Analysis Pinning a package version in a CDN URL is not equivalent to pinning the downloaded bytes. The script tag has no Subresource Integrity (`integrity`) attribute and no restrictive Content Security Policy was observed. If the CDN, package publisher account, DNS path, or package artifact is compromised, the returned JavaScript can change without any modification to this repository. Because the dependency runs in the administrative page's origin, it can redefine `solanaWeb3` classes and transaction methods, inspect the connected public key, alter transaction construction, replace recipient or program accounts, change instruction data, misrepresent the transaction in the page, and invoke wallet APIs. It can also transmit public wallet and transaction information to an attacker-controlled endpoint. The page requires the high-authority wallet `83ktg7 ...[truncated 1727 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Do not load runtime code from a public CDN in an administrative wallet-signing page. 2. Vendor a reviewed copy of `@solana/web3.js` into the deployment and serve it from the same controlled origin. 3. Lock the dependency using a package lockfile and verify its checksum during the build and deployment process. 4. If external hosting is unavoidable, add a verified Subresource Integrity hash and `crossorigin="anonymous"`: ```html <script src="https://unpkg.com/@solana/web3.js@1.95.3/lib/index.iife.min.js" integrity="sha384-REPLACE_WITH_VERIFIED_HASH" crossorigin="anonymous"></script> ``` 5. Deploy a restrictive Content Security Policy, preferably allowing scripts only from the controlled origin and avoiding inline script through nonces or hashes. 6. Isolate the administrative interface from the public application and restrict access using authenticated administrative controls and network-level policy. 7. Display a human-verifiable summary of the program ID, instruction, reserve value, and every writable account before requesting a signature. 8. Prefer a dedicated hardware-backed administrative wallet with minimal on-chain privileges and low balance. 9. Require multisignature approval or a timelocked governance process for global reserve changes. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
admin-set-reserves.html:42
Finding
Hardcoded Helius RPC API Key Is Exposed in Public Client-Side Code<![CDATA[ ## Vulnerability Details **File Location**: `admin-set-reserves.html`, line 42 **Vulnerability Type**: Hardcoded credential exposure **Risk Level**: Medium The administrative page embeds a Helius RPC endpoint containing an API key: ```javascript const RPC_URL = 'https://devnet.helius-rpc.com/?api-key=a59878e8-c5f9-4916-a7f7-bd6879496f4c'; ``` The value is then used to create the Solana connection: ```javascript let connection = new solanaWeb3.Connection(RPC_URL, 'confirmed'); ``` ### Technical Analysis Secrets embedded in HTML or client-side JavaScript are delivered to every visitor and should be treated as public. The key can be recovered from the repository, the deployed page source, browser developer tools, intermediary logs, or request telemetry. An attacker does not need access to the administrative wallet to abuse this credential. They can copy the endpoint and issue their own RPC requests while consuming the project's provider quota. Although the endpoint targets Solana devnet and the key is not a wallet private key, it is still an account-bound service credential. ### Attack Path 1. An attacker downloads or views `admin-set-reserves.html`. 2. The attacker extracts the `api-key` query parameter from `RPC_URL`. 3. The attacker scripts high-volume requests against the Helius devnet RPC service using that key. 4. Requests consume the account's quota and may trigger provider throttling, billing, or abuse controls. 5. Legitimate administrative reserve operations may fail or become unreliable when the credential is throttled or revoked. ### Impact Assessment The exposed credential may permit unauthorized use of the associated Helius RPC allocation. Potential consequences include quota exhaustion, service degradation, unexpected cost where applicable, contamination of service telemetry, and provider suspension. The key does not by itself grant control of the specified Solana authority wallet and cannot sign blockchain transactions. Its scop ...[truncated 66 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Revoke and rotate the exposed Helius API key immediately. 2. Do not place reusable provider credentials in static client-side files. 3. Route required RPC requests through a controlled backend or edge proxy that stores the credential in a secret manager. 4. Restrict the replacement key by allowed origins, networks, methods, quotas, and rate limits wherever the provider supports such controls. 5. Add per-client throttling and abuse monitoring to the proxy. 6. Prevent secrets from entering source control by adding automated secret scanning to pre-commit and CI pipelines. 7. Review repository and deployment history for additional copies of the key and inspect provider logs for prior unauthorized use. 8. If direct browser RPC access is necessary, use an explicitly public, tightly restricted client identifier rather than a privileged reusable key. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (16)

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
This file exposes an administrative interface that can modify bonding-curve reserves, but the skill description presents the tool as a public token-launch/productivity skill and does not disclose embedded admin functionality. Hidden or undocumented privileged operations are dangerous because they can mislead users, reviewers, or downstream platforms about the skill’s real capabilities and create opportunities for unauthorized or deceptive use of economic controls.

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
The file hardcodes a privileged authority wallet, program ID, and a direct reserve-changing workflow for blockchain administration that is not justified by the advertised skill purpose. Even though the transaction still requires the privileged signer, bundling undisclosed admin operations into a general-purpose skill is dangerous because it normalizes sensitive economic interventions and could facilitate abuse, accidental execution, or concealment of market-manipulating controls.

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Content
UjB4eIWzCBxPmRrmxyMaLIqnHQMdcFs2Xc6PmZnmPiuhyZbTgUhinNKb/NFZFcaXUM4QSzVmHSMRDhdlcTBaV0SbVRBnp2gbEZEowrTypzUeTARvQVZSm092MkIoP251MdzkWBcKq5lXAWNkoDJW16+UllZbXCUhB9UEF7UQ6UJNWPIYxGd+kOkQTz4zqucl5HjmOoc1TC2sMiGe7zIoGlOXgkOrWvNzDjge+W128PGnn3zjG9+YLs3sVKp2qr76kuflNTJenRIRKnKIL7RaTKnqBN1kUaXpq4SCkdDk7AzPcnmmXC7sHTTKs1MzE6ylD5MBZpMislBqz8fCTEkoRLkbEbyIioRCYOaSx18zgQJIjMKTIM1PVDbFsB9gT0uEZ5XgI7X9JEAik679PSPy9uRehAy2VIJ+8gt8l9J3QZrLgxMHAIul6NMzGNsPd5yoUkZ7TDVPToyhvRggusumCkH24/jxGoDVXUTpSYYTWgIC5ZTInpbcXvRu2KhH90gusi7VAh53VIo7EqNM6UiAv/v6nb/78U/UN0hd6+CrfKfV8/28U8W8LiHQFlswTDBhzMHgB1uoK/sGAvEjbx3tE0aK2ey/Kj+aTRMYXqNGF0uvNBZYnu/ub24S8/rrr+88eWpVLl4Cqk5RDSvWotJn/Xp/jivkvvNH37OqANANPhkR1lyVlM4LbcVR4nhMvUt1KdxUN0uGTF9htWuSkhOwzHYyy4m+QC+sUFjXYKuA2h+iDkAozBmkNsxztn6v0zrR1c5N9KTKaHsJJACiYoQLknRh/IgkLxEk7nY5Det6tTY/M+NyyByNyBmVI/2gzwk5VYG2mJ8nzz6JSWiE01S0rflSdJV4nJV3TGhWB0P5EWWd3wljMKzwMINFffEEvN5scja1PLWmtQ6lWTD54CAeMGBLCSur6rbz3elC/+MZOtFmwbY5WrhWTvDQNYCB7b2GTwaWLKTo+kZSmvghJ7qN6XjZCOGtZoMnrZSvS06P
Confidence
75% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Content
vIfR81SZGEUidOVldxKaxD27wJiXtx7cyom2H2WJUxR/YlUvcaKVX3aDcbEC+QQmQgjDxDqSb7e1dFTnmMUUlSkcg58w0X+EEk/jBheIrqucYZHBMcquN5zd59mfWhCu0GfssNXmEbg75fxWlWglZ3Y4LYmXgAlaq2s7N2+xZL1TeVoHLmO5nG2kKecx26C6mMX26CJSt0oNTiHmKGuB1/hpP6l80ubbq3h8IbKyND/DiiNgo90rhyUJcK/i8gRed8L20EdsFX2RhTrgS54T2qy0xa+y1QL9pYrjzdu3M5Y74uzEQ7ad1MLNOnYb2eVsjQujACYVDp43K8fMBThWfWS40CzlpC9VWbnz4uWgkvGIM+k2wMdbaPLZR18O+8/ZtScKRmlL2BwPFu5spSpYZOSBOda2hGMRyzmLY7ayRSpnzkEvRrl2i1Ta0T+XBaNlDK6rtGkXUeTSX54Cd22xzBibPHdooK9QuF1WMB4SzjNgnSN2bLbKfMV9FYws4r7NHPkicd0idaUpGLfB41MyfULbi4Jx/S4WjO8Pv/z976NgZPH3ppbEC6Q5DH+GgvFTFIzbKBjhwmG9swpG8EidXdAO7PtOm4JRq0PP+ovyMQpGwjDPU3RS/L+xrZQ87sGFlV20HlogzewOEfnIfo24/lLWLPqIe6MV40t3nXb49io5xzAVznaS+TMD25ZdnMTuT0sr7ETF9r03N29Ch6fDV1+oYPQMRvp0KYk8pXHl0+vnmExv9kobmnXK1+w4uwLY5nuf7fmLCygY70TB+CvDXSxM92mHTw73hlcolz37tnYdgE+BV7f5rkXzwEf7X7rJrgYoGG/fu8+im+3hxRdfDq+iYHTjW/vU4mMuqDmjIjwX9fb9b6GUfDTcQDE9B/0sssvYGvhYoG2codTcefYY5aJbBr+K1bA7DaSvpw0tym+d02EOawGjryXSWEaR6EL3nddsZfzsJ+Bxj3DI0syRlYIR/iSPavJKR1P1db0e
Confidence
75% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Content
O+4yDlJz55PPFv/v3xjc/M79Q4NRsDmBzX3/K4oyqYVR2evgaC31vQ6Shsx92xd4d92/vfdXzED1L+o1+Jg5R2wZ+1jzD/2jgw6gcpfzvekRKiCrGN/afnvXzEet1AfKUPfDztCJQbxZNB/Z1PGVeuGzEzZAEVJjOKFcFzce2wbvtNPnz2zVdu+oti506q217vocdAu82AEThLkXWO+2bU2YEmMGuQD9jo0Qxh2ESAui/cCUNhRSN6YSXPdkeBFWA4VCYJgG0rvBWIt+C7Z8Ry7jwOhJecNhkKHdT6ZQNNXHonGx7vCkNEaMnqRgKEAxgO3JueOeaP9h5KNmTvm39wZpu9r52DfWkdYPs28y7hroqf6XT/rE1s9o0+7IcJ05p+sMzwKniCCoCP1QPsPYHvsSFhs3Y/tq9n/Nl/pgOG+LwS6zk6hjgrPD9A+Zuf/87lg5QO9mePnCya1kxEGDnr8DI354FTIPRkIuwOfqw4TwA2sZreCOWqg17KH8SqM+kpWH5wHrd94yv/iHk48FJze7jwxyoc+Fzxj+rhsY4SUqfh/XVlcKJvnrDR2/rv/GyEcqJo0yJ3pu39n8XJSx+9HuI8UYXtTUQi1aFNTlQ2uCwMf64xhbhkwVxxAcM3BjtgVW9yY7C6rqWbT4TkG6ui9vSMdqwJS1Ff8Me6ziGvpcG4brYdX8wN/ubH0a5n1XOmQz0RB888JHvWlxoMHfCqV47c8IuQeOEHzzyUTptWZwLhkabPR35t1jqRj/veQArnRosCoZT1exkjYravqj9Qpcf95KgZOMgTkbngR0drBICRT3OQQ4TcwDsTTv+62A/whS5R7niFk8f940B3KZ5M2YmvASWg4yZ7UOzbrCsWA8GRhVPnIFlM+Sdd34KjLHAbA0DyWXAXjwhrIFQmg5UjcLwg0vWEvlWuwD03TV7tUGevG/xWXieQdfN3RYBXrfASh4k+9PSfhXXD0sgmF4Jcb2SvvSoxheFAIf3kT5
Confidence
75% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Content
7y95PzCtAUo7/slDnixPBnIbz6f2EEfsYtf8+M6e/0V/z5tSgrd/bRBweKOL7mc7zEtPJwFVvG966ps6d2WR/+ui7RUnU69PrAJ2L9nKCHQlMxgYhnPFi4W7bkxdzRvlwtL1Ib2gn/Tgi277tQ3tYO1rk1M+qbPhf0spr1QKw9RS07nPGwaty6y4WncRRyfEvFcMAnaAu/AiRN/LkuXs0sI6BmzrovcuDxwUZ1wINr8RSTsS0cGiNWNdEjjo8WcXzNEy9xJSaKw4ssvFKrh835Hl511c8axPJa/5ynXz+HWmNbl6yy6l4ViZ/3UbKJE4t83T++8oh3bC4DNS2nqumv+vOwAE2S9JedMkecGP5E8ttwvP/necR/MzfmmJHEYtZyFm0s0VJ1kq0PfCpSPyfURqGpKL2Chbtl0QPT5o725Wp5kaRU7Xj/b895fed0enCztUkz8Anawq8AC8+kNGvhZEotUGRbOWKKnTlEQa31MwYENbJd0Eu0hVuy/ZVqokccHyXi+JonXuJKTBSHF1l4pVYPm/M9vOqqnzWI5bX+OU+//vzQGtu6ZJVV96pI/LyPkk2cWOTr/vGVR7xjcxmoaTlVTX/Vr4MCNEnSX3bKHHFi+BPJb8Px/p/nEf/N3JhjRhKLWctZtLFES9VJtj7wqUj9nFAbhaai9AoW7pZFD0ybO9qXq+VFklK14/2/Pef1ndPpwc3WJs3AJ2gLvwIsPJPSrIWTKbVAkW3liCl25hAFtdbPGBDUyHZBL9EWbsn2V6qJHnF8lIjja554iSsxURxeZOGVWj1szvfwqqt+1iCW1/rnPP3680NrbOuSVVbdqyLx8z5KNnFika/7x1ce8Y7NZaCm5VQ1/VW/DgrQJEl/2SlzxInhTyS/Dcf7f55H/DdzY44ZSSxmLWfRxhItVSfZ+sCnIvVzQm0UmorSK1i4WxY9MG3uaF+ulhdJStWO9//2nNd3TqcHN1ubNAOfoC38CrDwTEqzFk6m1A
Confidence
75% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Content
YLN9a6erRqlX6rZRSPRX8Ogsc0fPCamjahx0nAR+vnrughsGmJ6fC+rZTj2N+E8QqYDVrktX6euIAahq+879ewF7m+P+ZgfKlFkn8Kn6L0XWsvAe1TLBHcBZQdt6Fo8ODbtr5y+Z8qpsC4bd2NlhFosBq00tLWZzoLvHnXj3QzeDT9vIL+XXVv5V1VRH3U+eTIyOWT96uc8GenrJV7MCrCYdlDpfAVZTDvmUXt7h/rrFfaSwnt+Ba/TOK/pEYdFFfvhPHEWSiCoN0jy4fFR/brbChMRjKmxQnH4P4F19lE31LVhnjNOL9+DB6R9b/4pXbm0tlhT3M26f75++2K6wiveVQT8DAYBidiL/ZhJju8mkuF4fWzxfvl1fLjyGa71RrK8gFe+jo3zRSV79PsPy0uP6llfe117aD4X243q9hcJ0H1vars+ZV74wPVtvYbq/io8pu/4ybSg1jnH54Cz//vEG0yX89cOl59f78dhPj0/aLel0X2t8fLj+efvZen0ND2s/sJNv39dTeFxqfl/64cuV6G+qgtSlb8aij3+q8qXndfEuJP7MKJ4hJzbZzxWF1Rwn/ZlErwCrj+hA/sUBq+E4zQBDDrFlt+DD+ckBU8OUYmo1UNdaU8ZkwZQPKF4JUyDkeN9pyz8J3CmwzbZGRz1RwOoqADZBdlJg7QcUE8DaLqALtdJ1qDAKgNSizb27tw22kxKrtqzXluG1bCeufFlg9T+jsDrt2tly3CusSllyevi6GweQlNIqRlGCeMGAVSk0rgWQ86qIBmMCxd25NUXbz7m+M782IFD9qtt4oABYlT8GL71lAK+gvHJAz+btzxlEZ0qLBtrJH3wrGoBTyqPazlxQokA81SvAT355UJDt+Wm2Juv+yABZgahbn/meKdUK3PSAnOzKN1J+7TvzioGCDZsPGVgsSHJ9VZP5dBUgpwBkU8DFVwKQh6++z8uJPmyh3gUo2LqbrdIBMIuFuwvzBsfOoZ4piFHjVt0c
Confidence
75% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Content
Mm/6XUs+TFit8zHlvGLeOHUkOE44dbpgAbzGE2BIqub7cECQJyJ2DnkSnami1OGHavECUtbx5P3vB+3gMwURWgFimIJ+RmK9cHYO24TPykMX5wC0nAKNUS5rMssomwB/tnAyMisBmlXeu3ZTmdKCHVoAPWsxmoGMTi9c/PYP3Tc9vKpugiYQ7RjAyiHBlUcdAExxYmtX5hVYqZEuc8AK+hc2VTCeBdsyzfc5F/obu42M/g3+cLfEohPMLI2YRVLwqwKEXRcnAM4horIN8O00nMa7Yu60bsc6rABAU2EE1oGsbXTkzcu78p3XNuRr31yV6x8BgI/nPce/fPA5VwVwvDbPyG/wdXtHfex89jyAQW6DV3iqA+kFpkVGvx2KVLAVu50piIwxo3WxdKxcpspyQTLIRT0T2EbJJpFN86IBdmdnUuQmjeAujWqJm9hT9QUYVGOc+C5r7Xhpon8iQzET1ZXUFLlGS9H+3HxjDwkU4zuT7+E+3sf6/oRRcetzH+eiO0YbKFPcvolyzlASnMhf4ptUnCQfm7OMFzMAnVNMsX0X2Bg7ZVKTpBelx3EWDTuO3+uLUndrp8xpNriecRYpzcUC4wh/dkNMVJGvGJHPVxby1nCcl4W6cYUSvz9w8qxsHPTImesT34gVvgABuFw5e06eVcBlVa68/Y6s3rwpHWwpfoTtwuOLCv2OXadCLSCjeW1GW+b8MZJ9SxJwya3EN7vbmmb+sFyxnC+FfOxXvkwvsYyrP1y0ddphdK3T935VZgF9PFVZ0RRfpZBCv+kXPMPtW4jdQD7IGo118BL+jTY3OC1n+0/KUv+CTPeX5U7turwKwOVBZVcudF6WM73PyoneU7JfXZd3Zv5cNhsfSFNOysLwaTk9+EVpVE/KfmNNNqrfk5vDv5RerSNLjV+E7qbs9F5FnMo1RHBu4gRgsYYI/3if6XMIXRlW8QzCM4mvG3pW/7DMz58KvhPwQ4tKZ1tqOzek2tlFn7JvAvaA
Confidence
75% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Content
BHT9porAxTVuBW5sTu4V4GvMc9CGjBZXms4ftaYQRtCwivqL+mPK+SU7aPrJsF+7eYGqvXLO1LYeyPzn71/85X9vrFL0Ol98mwE02QbYkVkqUzjr8Rfp4Qx1l/JGZz3CDLWWqpqv9KxtWFq5pZ7Lm7dqBQhvPoY3q2EFCG82fjfcewUIlwFsbngS3sjdlztuV1tOlI6Rq4A6qPpb8N1IPPgIDFQ1T4EEpUMoVKKm6zQwUFClHFO+trFi86KyWQ66LOftFKDp8kN1PNTZeobpyqnIQzRArRTuNMlSFpYR5RBOBY8W0NllpA1QtaOiHnu2FNm6FC4VNY19RnFtqzKqbLngTb66msi3NOGhpYVpEbY6zggW01bDRQsjDAtey+NWANsC2qnKKQEJAaGypspyykiasNbynpZnlLxCGz6axGLQznBhNdjWnwwj5SJf7TcAV8JHXUQMu/T8PIdSAuJSZXXIslWcKjJnDZ3KJg7D++jU97D27rtwvIphBIGLF8+w+dH70k6GjjKf8OJJC2dPflgKSywvlB1hzcLaruRrBdUNdE+/geuHaB/9XADhuN0Ea+b+yhCy3RsEtA4FgTgK2l9ac3AMQ9fDWriDLNxEywlx4ocIm3uQiMmkAjeIsPb+Zk7TkhksXhOQ6SwURvk7t6sUR2X5b1hBliEzSJaw9eRzATOaGziU3MHq2gMBGWQKyQyyP/GwAy+sYf39B+p1mNA/EKjt1GVqnn1xjKBJYJih/ejMADWIGik3L6qhcY91ZeidtNA/e4Z42DWsIH30CpEcNV4P5NznHoM2v48+ezZH0NrdGBsKc6GouFHKEFrzKoJsW/7Wprg3yf1DyikbWIisWMEZVZiVlyeVsrBVwfjpiVELF3ud6nWnALgs3HL5cVHcqZTxlIBs9UYVZpAMoR5XrUB001BRywza12mA5ysg5JwpQhMchM0d1LY1lPgX/9d/gyQmQC98HC+36zY+MTY5S6v6NgHTDHWPAaIZ
Confidence
75% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Content
cz7DG70CqLelGgV9BbrG+4noLddwbPSLovnQSg9QsDukRwjDUw7LvOSLySiZl19mv1jr7Yq1pVyaXDJsipRyd2ZfCmAohKiOYBsYqvFPkSlJOl+ir2jUpSbWE2UdOsZxt27WW3dOvOL+Ea8vMq1JQUquLfnR9QHBNLytgnoVHnFBQKlBSF6eF4uEhZeCiBbLzjM4IwVHAFN2AKV+k2EWykISoEq62PWLuxyIB72nPwiktCkgnS/S8ESY9dgtKhe46ExVF1TLhVY5Ug3MeXSsoB9OukW6VKDlwMgtr1jDM7mJxXTDVMKOdnbytmzrFhqCNYuKDVG6rhZiZupbqgErCjyWNFRmCgLllEK71jraNFoa/knaHP0dQ+Ymz5RLA6AL/ADkiJSyQ2byHFoUpspyDN3bnpFwxbOQk2FtVHS5izJBWhy5CDqbxURcq1F0k3Cr8zBi3J5PyyO1UgBVzpe8XLBDbaQslShyTbT2x9SkhtbNgdb5kiKKypCgkWv6YCSyNTwTf3GMXfJO8vUMMOvZGa3JJDab2HaMupeFvHupWIPFU5NNQwzOyiho+ytGnQ2NvthY7YliEYZ3pcD1xLikdlVmUrsbDIpYSr2WJhn5ggyaFDXug6m/SOG8Zj0XQkjrfDH1VyX2AD77LJc2ZYDmVoUXqZX5ynOrUkad0KA9oiAcuvMVEqJvyBglm/wASQkKJW6XkATK40Q+1fSyXWV6/CBosBXkynQO6BaN3o96Ymt1G1rRdFN3NecX0uyrISm1vOvflFuwkqaOY6EaxkJZogWSrKi1vtjbJbFPB8Ue6rtEWuNCnWK6GUOujvJcI5IV19Ee3QCQ0pNlX5DrFNLKA6HQspCVXOgh4BaVFkeUS5Sz2aVFVxflpHxKA3m7O2Q8rjWKlSsudlkoXdBQVkj0x8baWSixLeVNswgeDD1mIVcBCQRrpqox6SLyykklS0nMkeMenEpbydofzSRaKK3W0Kv2mS3MlQ0gk9hO6ex+
Confidence
75% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Content
cz7DG70CqLelGgV9BbrG+4noLddwbPSLovnQSg9QsDukRwjDUw7LvOSLySiZl19mv1jr7Yq1pVyaXDJsipRyd2ZfCmAohKiOYBsYqvFPkSlJOl+ir2jUpSbWE2UdOsZxt27WW3dOvOL+Ea8vMq1JQUquLfnR9QHBNLytgnoVHnFBQKlBSF6eF4uEhZeCiBbLzjM4IwVHAFN2AKV+k2EWykISoEq62PWLuxyIB72nPwiktCkgnS/S8ESY9dgtKhe46ExVF1TLhVY5Ug3MeXSsoB9OukW6VKDlwMgtr1jDM7mJxXTDVMKOdnbytmzrFhqCNYuKDVG6rhZiZupbqgErCjyWNFRmCgLllEK71jraNFoa/knaHP0dQ+Ymz5RLA6AL/ADkiJSyQ2byHFoUpspyDN3bnpFwxbOQk2FtVHS5izJBWhy5CDqbxURcq1F0k3Cr8zBi3J5PyyO1UgBVzpe8XLBDbaQslShyTbT2x9SkhtbNgdb5kiKKypCgkWv6YCSyNTwTf3GMXfJO8vUMMOvZGa3JJDab2HaMupeFvHupWIPFU5NNQwzOyiho+ytGnQ2NvthY7YliEYZ3pcD1xLikdlVmUrsbDIpYSr2WJhn5ggyaFDXug6m/SOG8Zj0XQkjrfDH1VyX2AD77LJc2ZYDmVoUXqZX5ynOrUkad0KA9oiAcuvMVEqJvyBglm/wASQkKJW6XkATK40Q+1fSyXWV6/CBosBXkynQO6BaN3o96Ymt1G1rRdFN3NecX0uyrISm1vOvflFuwkqaOY6EaxkJZogWSrKi1vtjbJbFPB8Ue6rtEWuNCnWK6GUOujvJcI5IV19Ee3QCQ0pNlX5DrFNLKA6HQspCVXOgh4BaVFkeUS5Sz2aVFVxflpHxKA3m7O2Q8rjWKlSsudlkoXdBQVkj0x8baWSixLeVNswgeDD1mIVcBCQRrpqox6SLyykklS0nMkeMenEpbydofzSRaKK3W0Kv2mS3MlQ0gk9hO6ex+
Confidence
75% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Hidden Instructions

High
Category
Prompt Injection
Content
<div class="dot dot-6"></div>
  <div class="dot dot-7"></div>

  <!-- 3D Green Arrow - replaces mascot position -->
  <div class="arrow-wrap">
    <svg class="arrow-3d" viewBox="0 0 280 280" xmlns="http://www.w3.org/2000/svg">
      <defs>
Confidence
70% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
<pattern id="pattern0_4571_15380" patternContentUnits="objectBoundingBox" width="1" height="1">
<use xlink:href="#image0_4571_15380" transform="scale(0.000919118 0.00204918)"/>
</pattern>
<image id="image0_4571_15380" width="1088" height="488" preserveAspectRatio="none" xlink:href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABEAAAAHoCAYAAABJiJprAAAAAXNSR0IArs4c6QAAAMZlWElmTU0AKgAAAAgABgESAAMAAAABAAEAAAEaAAUAAAABAAAAVgEbAAUAAAABAAAAXgEoAAMAAAABAAIAAAExAAIAAAAVAAAAZodpAAQAAAABAAAAfAAAAAAAAABIAAAAAQAAAEgAAAABUGl4ZWxtYXRvciBQcm8gMy42LjkAAAAEkAQAAgAAABQAAACyoAEAAwAAAAEAAQAAoAIABAAAAAEAAARAoAMABAAAAAEAAAHoAAAAADIwMjU6MDc6MjQgMTU6MjI6MzEAh2athwAAAAlwSFlzAAALEwAACxMBAJqcGAAAA7NpVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6bnM6bWV0YS8iIHg6eG1wdGs9IlhNUCBDb3JlIDYuMC4wIj4KICAgPHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4KICAgICAgPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIKICAgICAgICAgICAgeG1sbnM6dGlmZj0iaHR0cDovL25zLmFkb2JlLmNvbS90aWZmLzEuMC8iCiAgICAgICAgICAgIHhtbG5zOmV4aWY9Imh0dHA6Ly9ucy5hZG9iZS5jb20vZXhpZi8xLjAvIgogICAgICAgICAgICB4bWxuczp4bXA9Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC8iPgogICAgICAgICA8dGlmZjpZUmVzb2x1dGlvbj43MjAwMDAvMTAwMDA8L3RpZmY6WVJlc29sdXRpb24+CiAgICAgICAgIDx0aWZmOlhSZXNvbHV0aW9uPjcyMDAwMC8xMDAwMDwvdGlmZjpYUmVzb2x1dGlvbj4KICAgICAgICAgPHRpZmY6UmVzb2x1dGlvblVuaXQ+MjwvdGlmZjpSZXNvbHV0aW9uVW5pdD4KICAgICAgICAgPHRpZmY6T3JpZW50YXRpb24+MTwvdGlmZjpPcmllbnRhdGlvbj4KICAgICAgICAgPGV4aWY6UGl4ZWxZRGltZW5zaW9uPjQ4ODwvZXhpZjpQaXhlbFlEaW1lbnNpb24+CiAgICAgICAgIDxleGlmOlBpeGVsWERpbWVuc2lvbj4xMDg4PC9leGlmOlBpeGVsWERpbWVuc2lvbj4KICAgICAgICAgPHhtcDpNZXRhZGF0YURhdGU+MjAyNS0wNy0yNFQxNToyMzozNSswMzozMDwveG1wOk1ldGFkYXRhRGF0ZT4KICAgICAgICAgPHhtcDpDcmVhdGVEYXRlPjIwMjUtMDctMjRUMTU6MjI6MzErMDM6MzA8L3htcDpDcmVhdGVEYXRlPgogICAgICAgICA8eG1wOkNyZWF0b3JUb29sPlBpeGVsbWF0b3IgUHJvIDMuNi45PC94bXA6Q3JlYXRvclRvb2w+CiAgICAgIDwvcmRmOkRlc2NyaXB0aW9uPgogICA8L3JkZjpSREY+CjwveDp4bXBtZXRhPgqg54PCAABAAElEQVR4Ae3dB7gsWVkv/DN5hkmAMwQxhw8+LoiifCg
...[truncated 27 chars]
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Context Window Stuffing

Medium
Category
Memory Poisoning
Content
<pattern id="pattern0_4571_15380" patternContentUnits="objectBoundingBox" width="1" height="1">
<use xlink:href="#image0_4571_15380" transform="scale(0.000919118 0.00204918)"/>
</pattern>
<image id="image0_4571_15380" width="1088" height="488" preserveAspectRatio="none" xlink:href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABEAAAAHoCAYAAABJiJprAAAAAXNSR0IArs4c6QAAAMZlWElmTU0AKgAAAAgABgESAAMAAAABAAEAAAEaAAUAAAABAAAAVgEbAAUAAAABAAAAXgEoAAMAAAABAAIAAAExAAIAAAAVAAAAZodpAAQAAAABAAAAfAAAAAAAAABIAAAAAQAAAEgAAAABUGl4ZWxtYXRvciBQcm8gMy42LjkAAAAEkAQAAgAAABQAAACyoAEAAwAAAAEAAQAAoAIABAAAAAEAAARAoAMABAAAAAEAAAHoAAAAADIwMjU6MDc6MjQgMTU6MjI6MzEAh2athwAAAAlwSFlzAAALEwAACxMBAJqcGAAAA7NpVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6bnM6bWV0YS8iIHg6eG1wdGs9IlhNUCBDb3JlIDYuMC4wIj4KICAgPHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4KICAgICAgPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIKICAgICAgICAgICAgeG1sbnM6dGlmZj0iaHR0cDovL25zLmFkb2JlLmNvbS90aWZmLzEuMC8iCiAgICAgICAgICAgIHhtbG5zOmV4aWY9Imh0dHA6Ly9ucy5hZG9iZS5jb20vZXhpZi8xLjAvIgogICAgICAgICAgICB4bWxuczp4bXA9Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC8iPgogICAgICAgICA8dGlmZjpZUmVzb2x1dGlvbj43MjAwMDAvMTAwMDA8L3RpZmY6WVJlc29sdXRpb24+CiAgICAgICAgIDx0aWZmOlhSZXNvbHV0aW9uPjcyMDAwMC8xMDAwMDwvdGlmZjpYUmVzb2x1dGlvbj4KICAgICAgICAgPHRpZmY6UmVzb2x1dGlvblVuaXQ+MjwvdGlmZjpSZXNvbHV0aW9uVW5pdD4KICAgICAgICAgPHRpZmY6T3JpZW50YXRpb24+MTwvdGlmZjpPcmllbnRhdGlvbj4KICAgICAgICAgPGV4aWY6UGl4ZWxZRGltZW5zaW9uPjQ4ODwvZXhpZjpQaXhlbFlEaW1lbnNpb24+CiAgICAgICAgIDxleGlmOlBpeGVsWERpbWVuc2lvbj4xMDg4PC9leGlmOlBpeGVsWERpbWVuc2lvbj4KICAgICAgICAgPHhtcDpNZXRhZGF0YURhdGU+MjAyNS0wNy0yNFQxNToyMzozNSswMzozMDwveG1wOk1ldGFkYXRhRGF0ZT4KICAgICAgICAgPHhtcDpDcmVhdGVEYXRlPjIwMjUtMDctMjRUMTU6MjI6MzErMDM6MzA8L3htcDpDcmVhdGVEYXRlPgogICAgICAgICA8eG1wOkNyZWF0b3JUb29sPlBpeGVsbWF0b3IgUHJvIDMuNi45PC94bXA6Q3JlYXRvclRvb2w+CiAgICAgIDwvcmRmOkRlc2NyaXB0aW9uPgogICA8L3JkZjpSREY+CjwveDp4bXBtZXRhPgqg54PCAABAAElEQVR4Ae3dB7gsWVkv/DN5hkmAMwQxhw8+LoiifCg
...[truncated 27 chars]
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs users to make irreversible on-chain SOL transfers for website fees and betting, but does not present any explicit warning about financial loss, transfer irreversibility, destination verification, or the risk of mistaken or malicious payment instructions. In a web3 agent context, users may treat the flow as trusted automation, so omission of these warnings materially increases the chance of accidental loss or socially engineered payments.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes sending wallet address and token metadata to a third-party domain, aicre8.dev, including through URL query parameters or cross-platform auth, without clearly warning that this data is being shared outside vybes.fun. This creates privacy and tracking risk, and using direct build URLs can additionally expose token and wallet-associated data via browser history, logs, referrers, and intermediary infrastructure.

Static analysis

No suspicious patterns detected.