T09 · Insecure Skill Coding Practices
- Location
scripts/enter-position.sh:14- Finding
Authenticated Financial Requests Can Be Redirected to an Arbitrary Endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a legitimate-looking DeFi yield tool, but it handles irreversible blockchain transaction workflows with under-scoped safeguards that users should review carefully before installing.
Review this skill as a high-risk financial integration. Only use it with a wallet that shows decoded transaction details, confirm the exact chain, asset, amount, contract, spender, allowance, and destination before signing, avoid custom YIELDS_API_URL values unless you fully trust them, and do not rely on its position-balance check as proof that your wallet has spendable funds.
scripts/enter-position.sh:14Authenticated Financial Requests Can Be Redirected to an Arbitrary Endpoint
SKILL.md:104API-Controlled Blockchain Transactions Are Passed to Wallets Without Independent Verification
skill.json:67Shared API Credential Is Hardcoded in the Distributed Manifest
README.md:27Installation Instructions Execute a Mutable Unpinned Third-Party Package
references/safety.md:29Documented Deposit Balance Check Does Not Verify the Wallet's Spendable Input-Token Balance
This section instructs the agent how to enter, manage, and exit yield positions and describes transaction signing/broadcast flow, but it does not present a clear user-facing warning about irreversible financial risk, possible loss of funds, approvals, slippage, validator choice risk, or chain-specific execution consequences. In the context of an on-chain transaction skill, omission of these warnings makes accidental or insufficiently informed execution materially more dangerous.
This example chains a swap and a deposit, then responds 'All done!' without demonstrating an explicit confirmation and signing checkpoint before executing two fund-moving on-chain actions. Combining conversion and redeployment of assets amplifies risk because a mistaken amount, route, token, or destination can immediately and irreversibly move substantial funds.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
openapi: 3.0.0
paths:
/v1/yields:
get:
operationId: YieldsController_getYields
summary: List all yield opportunities
description: >-
Retrieve a paginated list of available yield opportunities across all
supported networks and protocols.
parameters:
- name: offset
required: false
in: query
description: Offset for pagination
example: 0
schema:
minimum: 0
default: 0
type: number
- name: limit
required: false
in: query
description: Number of items per page
example: 20
schema:
minimum: 1
maximum: 100
defaul
The transaction submission endpoints are explicitly designed to broadcast signed blockchain transactions, which can produce immediate and irreversible financial effects. In an agent-skill context, failing to prominently warn about irreversible submission and user-approval requirements increases the risk of unsafe automation, accidental fund movement, or signing/submission without informed consent.
Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.
*Transaction guardrails, approval workflows, and risk controls for on-chain yield operations.*
> **Critical: The agent must NEVER bypass safety checks.**
---
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
*Transaction guardrails, approval workflows, and risk controls for on-chain yield operations.*
> **Critical: The agent must NEVER bypass safety checks.**
---
The manifest description advertises transaction building and portfolio management but does not warn that these actions are financial, may move funds, and can be irreversible on-chain. In the context of a DeFi skill spanning 80+ networks, the absence of an explicit warning increases the chance users or orchestrators treat the capability as routine automation rather than high-risk financial tooling.
The README instructs users to run npx clawhub@latest install yield-agent, which pulls and executes the latest package version at install time without pinning an exact version. If the upstream package, dependency chain, or publisher account is compromised, users could execute unintended code during installation. In the context of an agent skill that later helps construct on-chain transactions, installation-time compromise is especially sensitive because it could tamper with scripts, API keys, or transaction-building behavior.
The skill exposes shell-backed tools (curl, jq, and multiple scripts/*.sh entries) but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, this weakens containment and increases the chance the skill can be invoked with broader execution capability than intended, especially when paired with transaction-building workflows.
The description is broad enough to match generic requests like yield discovery, staking, lending, portfolio management, and balance checks across many networks. That increases the likelihood the skill is auto-selected in situations where the user did not clearly intend to authorize on-chain or financially sensitive actions, creating a pathway to accidental transaction preparation or misleading financial guidance.
The rewards-claim example proceeds from a simple 'Yes, claim my rewards' to submitted transaction language without showing an explicit signing warning, transaction summary, or final confirmation step. Because claiming rewards is still an on-chain state-changing action with gas cost and asset movement implications, this normalizes silent execution and weakens transaction consent hygiene.
The withdrawal example prepares a withdrawal and asks 'Ready to sign and submit?' but does not prominently warn that this is an irreversible on-chain transaction affecting custody and incurring gas. In a skill centered on moving assets across protocols, weak transaction warnings can lead agents or users to underappreciate the consequences of approval and submission.
The rebalance example treats 'Yes, do it' as authorization for a withdrawal followed by redeposit, but does not show clear per-transaction warnings or confirmation before each signature. Multi-step asset migrations are especially sensitive because failure or mismatch in any step can strand funds, leave assets idle, or expose users to unintended protocol risk.
The safety example claims to verify the wallet's USDC balance before depositing all funds, but the shown command checks a position-specific Aave portfolio instead of the wallet's liquid USDC balance. In a transaction-building skill, this mismatch can mislead an agent into believing it performed a prerequisite safety check when it did not, increasing the chance of overcommitting funds or presenting false assurances to the user.
This manifest/OpenAPI file documents portfolio endpoints that accept wallet addresses and return user-specific balances across networks and yields, which is privacy-relevant behavior. The descriptions explain the mechanics of the scan but do not warn that submitting addresses discloses user portfolio data to the service or may trigger broad address-based scanning when yieldId is omitted.
The /v1/actions endpoint is described as retrieving all actions performed by a user and requires a wallet address, which exposes user activity history tied to that address. The specification does not disclose this privacy impact or remind integrators to obtain user consent before querying activity for an address.
Declaring some actions as 'Auto-execute' creates autonomous behavior in a financial/on-chain skill, which can be risky if action classification is wrong, inputs are manipulated, or supposedly read-only operations have side effects in integrated tooling. In a wallet/yield-management context, even low-risk automation increases the chance of unintended API calls, privacy leakage, or unsafe workflow chaining without user awareness.
| Risk Level | Actions | Default Behavior |
|------------|---------|------------------|
| **Safe** | Discovery, balance checks, rate lookups | Auto-execute |
| **Review** | Enter position, exit position, claim rewards | Show details, ask confirmation |
| **Caution** | Large amounts, new protocols | Require explicit approval |
The skill documents persistent storage of wallet addresses, positions, rewards, alerts, and historical activity in a local state file, but it does not present a clear user-facing notice about retention, sensitivity, access controls, or deletion. This creates privacy and security risk because financial metadata and wallet mappings can reveal user behavior and holdings, and persistent storage expands the blast radius if the host environment, logs, backups, or other skills are compromised.
The trigger phrases are broad enough that ordinary portfolio-related requests could activate higher-impact superskills such as transaction preparation, monitoring, or portfolio analysis without clear user intent boundaries. In a yield-management skill that can build on-chain transactions and persist state, ambiguous activation increases the risk of unintended data access, unwanted state changes, or prompting the agent into sensitive workflows the user did not explicitly request.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
PAYLOAD=$(jq -n --arg addr "$ADDRESS" '{address: $addr}')
RESPONSE=$(curl -s -X POST "${API_URL}/v1/yields/${YIELD_ID}/balances" \
-H "x-api-key: ${API_KEY}" -H "Content-Type: application/json" -d "$PAYLOAD")
if echo "$RESPONSE" | jq -e '.error // .message' > /dev/null 2>&1; then
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
PAYLOAD=$(jq -n --arg yieldId "$YIELD_ID" --arg address "$ADDRESS" --argjson arguments "$ARGS_JSON" \
'{yieldId: $yieldId, address: $address, arguments: $arguments}')
RESPONSE=$(curl -s -X POST "${API_URL}/v1/actions/enter" \
-H "x-api-key: ${API_KEY}" -H "Content-Type: application/json" -d "$PAYLOAD")
if echo "$RESPONSE" | jq -e '.error // .message' > /dev/null 2>&1; then
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
PAYLOAD=$(jq -n --arg yieldId "$YIELD_ID" --arg address "$ADDRESS" --argjson arguments "$ARGS_JSON" \
'{yieldId: $yieldId, address: $address, arguments: $arguments}')
RESPONSE=$(curl -s -X POST "${API_URL}/v1/actions/exit" \
-H "x-api-key: ${API_KEY}" -H "Content-Type: application/json" -d "$PAYLOAD")
if echo "$RESPONSE" | jq -e '.error // .message' > /dev/null 2>&1; then
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
--arg passthrough "$PASSTHROUGH" --argjson arguments "$ARGS_JSON" \
'{yieldId: $yieldId, address: $address, action: $action, passthrough: $passthrough, arguments: $arguments}')
RESPONSE=$(curl -s -X POST "${API_URL}/v1/actions/manage" \
-H "x-api-key: ${API_KEY}" -H "Content-Type: application/json" -d "$PAYLOAD")
if echo "$RESPONSE" | jq -e '.error // .message' > /dev/null 2>&1; then
The trigger list includes broad phrases like 'stake', 'lend', 'deposit', 'withdraw', and 'check balance' that can appear in many normal conversations, increasing the chance this finance skill activates when the user did not intend to invoke it. In a skill that can drive on-chain yield actions and transaction building, accidental activation is materially risky because it may steer the agent toward financial workflows and irreversible blockchain operations.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
YieldAgent is a software tool designed to help users discover yield opportunities and construct transactions using the Yield.xyz infrastructure. It is not a financial advisor, broker, dealer, or fiduciary. Yield.xyz does not provide financial, investment, tax, accounting, or legal advice. Nothing in this repository, within the YieldAgent interface, or in any related materials constitutes a recommendation, solicitation, endorsement, or offer to buy, sell, hold, or otherwise transact in any digital asset or to pursue any particular investment strategy.
All actions taken through YieldAgent are initiated and executed at your sole discretion. You are fully responsible for evaluating and understanding the risks involved, including but not limited to smart contract vulnerabilities, protocol failures, counterparty exposure, market volatility, liquidity constraints, loss of private keys, technical errors, and changing regulatory requirements. Digital assets and decentralized finance involve substantial risk, including the potential for total loss of funds. Only use funds you can afford to lose. You should conduct your own research and consult qualified professional advisors before making financial decisions.
By using YieldAgent, you acknowledge and accept these risks.
No suspicious patterns detected.