Back to skill

Security audit

Solana Scam Detector

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent read-only Solana token checker, but its advertised safety verdict can be misleading because the token-age check does not actually prove token age and can fail open.

Review this before relying on it for trading decisions. It does not ask for wallet keys or sign transactions, but its safe result should not be treated as proof that a token is old or low-risk; use a pinned dependency install and independently verify token creation age and liquidity before acting.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
lib/scam_check.js:65
Finding

Incorrect Token-Age Calculation Can Produce Unsafe Trading Guidance

Content
View full analysis
0 && sigs[0].blockTime) { const ageHours = (Date.now() / 1000 - sigs[0].blockTime) / 3600; if (ageHours < CONFIG.MIN_TOKEN_AGE_HOURS) { issues.push(`Token is <${CONFIG.MIN_TOKEN_AGE_HOURS}h old - high risk`); } } } ``` ### Technical Analysis `getSignaturesForAddress()` returns signatures in reverse chronological order, with the newest signature first. Requesting only one signature therefore retrieves the mint account's latest recorded activity, not its creation transaction. Consequently, `ageHours` measures the elapsed time since the most recent activity involving the address. It does not establish the token's age as advertised. The validation also fails open when: - The RPC returns no signatures. - The returned signature has no `blockTime`. - The available history is insufficient to identify the creation transaction. In those cases, no issue is added. If the ticker and local blacklist checks also pass, the function can return `safe: true` even though token age was never established. ### Attack Path 1. An attacker creates or promotes a risky token whose symbol is absent from the static ticker list and whose mint is absent from the initially empty mint blacklist. 2. The user submits that mint to `checkTokenSafety()`. 3. The RPC returns no usable signature timestamp, or returns data that does not represent account creation. 4. The age check adds no issue when the age cannot be determined. 5. The remaining local checks pass. 6. The function returns `safe: true`, potentially causing the user or an automated agent to treat an unverified token as safe. The same implementation can also falsely f ...[truncated 638 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:14
Finding

Unpinned Runtime Dependency Installation Creates Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
- `SKILL.md` — This file

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares environment variable usage (RPC_URL) in metadata but does not define an explicit tool scope such as permissions or allowed-tools. Even though the described functionality is read-only, undeclared capability boundaries reduce transparency for the agent/runtime and can permit broader-than-expected access patterns or unsafe deployment assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a read-only scam detector that checks token characteristics before trading. While blockchain access is read-only, this module also provides a public function to alter its scam-detection blacklists at runtime, which goes beyond pure checking behavior described in the manifest.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Comments at L088 and the agent instructions at L108 state this is a read-only module that only fetches blockchain data. However, addToBlacklist mutates BLACKLIST_EXACT, BLACKLIST_MINTS, and BLACKLIST_PATTERNS in memory, so the module is not purely read-only in its actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.