Back to skill

Security audit

Yield Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a legitimate-looking DeFi yield tool, but it handles irreversible blockchain transaction workflows with under-scoped safeguards that users should review carefully before installing.

Review this skill as a high-risk financial integration. Only use it with a wallet that shows decoded transaction details, confirm the exact chain, asset, amount, contract, spender, allowance, and destination before signing, avoid custom YIELDS_API_URL values unless you fully trust them, and do not rely on its position-balance check as proof that your wallet has spendable funds.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/enter-position.sh:14
Finding

Authenticated Financial Requests Can Be Redirected to an Arbitrary Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:104
Finding

API-Controlled Blockchain Transactions Are Passed to Wallets Without Independent Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skill.json:67
Finding

Shared API Credential Is Hardcoded in the Distributed Manifest

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:27
Finding

Installation Instructions Execute a Mutable Unpinned Third-Party Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/safety.md:29
Finding

Documented Deposit Balance Check Does Not Verify the Wallet's Spendable Input-Token Balance

Content
View full analysis
# If balance < amount, abort and inform the user ``` The script actually requests a yield-specific position balance: ```bash # Check balances for a yield position — POST /v1/yields/{yieldId}/balances # Returns YieldBalancesDto with balances, pending actions, and validator info. PAYLOAD=$(jq -n --arg addr "$ADDRESS" '{address: $addr}') RESPONSE=$(curl -s -X POST "${API_URL}/v1/yields/${YIELD_ID}/balances" \ -H "x-api-key: ${API_KEY}" -H "Content-Type: application/json" -d "$PAYLOAD") ``` ### Technical Analysis The endpoint queries balances associated with a particular yield position. It does not necessarily return the wallet's liquid balance for the input token that will fund a new deposit. A yield position balance and a spendable wallet balance are different security properties. For example, a user may have an existing Aave USDC position but no liquid USDC available for another deposit. Conversely, the user may have liquid USDC but no existing position. The check also does not establish whether the wallet has enough native token to pay network fees. ### Attack Path 1. The Agent prepares an enter action for a specified token and amount. 2. It follows the documented safety workflow and invokes `check-portfolio.sh`. 3. The response contains a balance for the existing yield position rather than the liquid input token. 4. The Agent incorrectly treats that value as spendable deposit capacity. 5. It builds or attempts to submit a transaction the wallet cannot fund. 6. The ...[truncated 432 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (26)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section instructs the agent how to enter, manage, and exit yield positions and describes transaction signing/broadcast flow, but it does not present a clear user-facing warning about irreversible financial risk, possible loss of funds, approvals, slippage, validator choice risk, or chain-specific execution consequences. In the context of an on-chain transaction skill, omission of these warnings makes accidental or insufficiently informed execution materially more dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This example chains a swap and a deposit, then responds 'All done!' without demonstrating an explicit confirmation and signing checkpoint before executing two fund-moving on-chain actions. Combining conversion and redeployment of assets amplifies risk because a mistaken amount, route, token, or destination can immediately and irreversibly move substantial funds.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/openapi.yaml (reported line 7)May include surrounding context.

yaml
openapi: 3.0.0
paths:
  /v1/yields:
    get:
      operationId: YieldsController_getYields
      summary: List all yield opportunities
      description: >-
        Retrieve a paginated list of available yield opportunities across all
        supported networks and protocols.
      parameters:
        - name: offset
          required: false
          in: query
          description: Offset for pagination
          example: 0
          schema:
            minimum: 0
            default: 0
            type: number
        - name: limit
          required: false
          in: query
          description: Number of items per page
          example: 20
          schema:
            minimum: 1
            maximum: 100
            defaul

Missing User Warnings

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The transaction submission endpoints are explicitly designed to broadcast signed blockchain transactions, which can produce immediate and irreversible financial effects. In an agent-skill context, failing to prominently warn about irreversible submission and user-approval requirements increases the risk of unsafe automation, accidental fund movement, or signing/submission without informed consent.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
90% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · references/safety.md (reported line 5)May include surrounding context.

md
*Transaction guardrails, approval workflows, and risk controls for on-chain yield operations.*

> **Critical: The agent must NEVER bypass safety checks.**

---

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/safety.md (reported line 5)May include surrounding context.

md
*Transaction guardrails, approval workflows, and risk controls for on-chain yield operations.*

> **Critical: The agent must NEVER bypass safety checks.**

---

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description advertises transaction building and portfolio management but does not warn that these actions are financial, may move funds, and can be irreversible on-chain. In the context of a DeFi skill spanning 80+ networks, the absence of an explicit warning increases the chance users or orchestrators treat the capability as routine automation rather than high-risk financial tooling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx clawhub@latest install yield-agent, which pulls and executes the latest package version at install time without pinning an exact version. If the upstream package, dependency chain, or publisher account is compromised, users could execute unintended code during installation. In the context of an agent skill that later helps construct on-chain transactions, installation-time compromise is especially sensitive because it could tamper with scripts, API keys, or transaction-building behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill exposes shell-backed tools (curl, jq, and multiple scripts/*.sh entries) but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, this weakens containment and increases the chance the skill can be invoked with broader execution capability than intended, especially when paired with transaction-building workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description is broad enough to match generic requests like yield discovery, staking, lending, portfolio management, and balance checks across many networks. That increases the likelihood the skill is auto-selected in situations where the user did not clearly intend to authorize on-chain or financially sensitive actions, creating a pathway to accidental transaction preparation or misleading financial guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The rewards-claim example proceeds from a simple 'Yes, claim my rewards' to submitted transaction language without showing an explicit signing warning, transaction summary, or final confirmation step. Because claiming rewards is still an on-chain state-changing action with gas cost and asset movement implications, this normalizes silent execution and weakens transaction consent hygiene.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The withdrawal example prepares a withdrawal and asks 'Ready to sign and submit?' but does not prominently warn that this is an irreversible on-chain transaction affecting custody and incurring gas. In a skill centered on moving assets across protocols, weak transaction warnings can lead agents or users to underappreciate the consequences of approval and submission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The rebalance example treats 'Yes, do it' as authorization for a withdrawal followed by redeposit, but does not show clear per-transaction warnings or confirmation before each signature. Multi-step asset migrations are especially sensitive because failure or mismatch in any step can strand funds, leave assets idle, or expose users to unintended protocol risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The safety example claims to verify the wallet's USDC balance before depositing all funds, but the shown command checks a position-specific Aave portfolio instead of the wallet's liquid USDC balance. In a transaction-building skill, this mismatch can mislead an agent into believing it performed a prerequisite safety check when it did not, increasing the chance of overcommitting funds or presenting false assurances to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This manifest/OpenAPI file documents portfolio endpoints that accept wallet addresses and return user-specific balances across networks and yields, which is privacy-relevant behavior. The descriptions explain the mechanics of the scan but do not warn that submitting addresses discloses user portfolio data to the service or may trigger broad address-based scanning when yieldId is omitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The /v1/actions endpoint is described as retrieving all actions performed by a user and requires a wallet address, which exposes user activity history tied to that address. The specification does not disclose this privacy impact or remind integrators to obtain user consent before querying activity for an address.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Declaring some actions as 'Auto-execute' creates autonomous behavior in a financial/on-chain skill, which can be risky if action classification is wrong, inputs are manipulated, or supposedly read-only operations have side effects in integrated tooling. In a wallet/yield-management context, even low-risk automation increases the chance of unintended API calls, privacy leakage, or unsafe workflow chaining without user awareness.

Content

Scanner excerpt · references/safety.md (reported line 13)May include surrounding context.

md
| Risk Level | Actions | Default Behavior |
|------------|---------|------------------|
| **Safe** | Discovery, balance checks, rate lookups | Auto-execute |
| **Review** | Enter position, exit position, claim rewards | Show details, ask confirmation |
| **Caution** | Large amounts, new protocols | Require explicit approval |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents persistent storage of wallet addresses, positions, rewards, alerts, and historical activity in a local state file, but it does not present a clear user-facing notice about retention, sensitivity, access controls, or deletion. This creates privacy and security risk because financial metadata and wallet mappings can reveal user behavior and holdings, and persistent storage expands the blast radius if the host environment, logs, backups, or other skills are compromised.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad enough that ordinary portfolio-related requests could activate higher-impact superskills such as transaction preparation, monitoring, or portfolio analysis without clear user intent boundaries. In a yield-management skill that can build on-chain transactions and persist state, ambiguous activation increases the risk of unintended data access, unwanted state changes, or prompting the agent into sensitive workflows the user did not explicitly request.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/check-portfolio.sh (reported line 29)May include surrounding context.

sh
PAYLOAD=$(jq -n --arg addr "$ADDRESS" '{address: $addr}')

RESPONSE=$(curl -s -X POST "${API_URL}/v1/yields/${YIELD_ID}/balances" \
  -H "x-api-key: ${API_KEY}" -H "Content-Type: application/json" -d "$PAYLOAD")

if echo "$RESPONSE" | jq -e '.error // .message' > /dev/null 2>&1; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/enter-position.sh (reported line 32)May include surrounding context.

sh
PAYLOAD=$(jq -n --arg yieldId "$YIELD_ID" --arg address "$ADDRESS" --argjson arguments "$ARGS_JSON" \
  '{yieldId: $yieldId, address: $address, arguments: $arguments}')

RESPONSE=$(curl -s -X POST "${API_URL}/v1/actions/enter" \
  -H "x-api-key: ${API_KEY}" -H "Content-Type: application/json" -d "$PAYLOAD")

if echo "$RESPONSE" | jq -e '.error // .message' > /dev/null 2>&1; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/exit-position.sh (reported line 32)May include surrounding context.

sh
PAYLOAD=$(jq -n --arg yieldId "$YIELD_ID" --arg address "$ADDRESS" --argjson arguments "$ARGS_JSON" \
  '{yieldId: $yieldId, address: $address, arguments: $arguments}')

RESPONSE=$(curl -s -X POST "${API_URL}/v1/actions/exit" \
  -H "x-api-key: ${API_KEY}" -H "Content-Type: application/json" -d "$PAYLOAD")

if echo "$RESPONSE" | jq -e '.error // .message' > /dev/null 2>&1; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/manage-position.sh (reported line 35)May include surrounding context.

sh
--arg passthrough "$PASSTHROUGH" --argjson arguments "$ARGS_JSON" \
  '{yieldId: $yieldId, address: $address, action: $action, passthrough: $passthrough, arguments: $arguments}')

RESPONSE=$(curl -s -X POST "${API_URL}/v1/actions/manage" \
  -H "x-api-key: ${API_KEY}" -H "Content-Type: application/json" -d "$PAYLOAD")

if echo "$RESPONSE" | jq -e '.error // .message' > /dev/null 2>&1; then

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases like 'stake', 'lend', 'deposit', 'withdraw', and 'check balance' that can appear in many normal conversations, increasing the chance this finance skill activates when the user did not intend to invoke it. In a skill that can drive on-chain yield actions and transaction building, accidental activation is materially risky because it may steer the agent toward financial workflows and irreversible blockchain operations.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · README.md (reported line 130)May include surrounding context.

md
YieldAgent is a software tool designed to help users discover yield opportunities and construct transactions using the Yield.xyz infrastructure. It is not a financial advisor, broker, dealer, or fiduciary. Yield.xyz does not provide financial, investment, tax, accounting, or legal advice. Nothing in this repository, within the YieldAgent interface, or in any related materials constitutes a recommendation, solicitation, endorsement, or offer to buy, sell, hold, or otherwise transact in any digital asset or to pursue any particular investment strategy.

All actions taken through YieldAgent are initiated and executed at your sole discretion. You are fully responsible for evaluating and understanding the risks involved, including but not limited to smart contract vulnerabilities, protocol failures, counterparty exposure, market volatility, liquidity constraints, loss of private keys, technical errors, and changing regulatory requirements. Digital assets and decentralized finance involve substantial risk, including the potential for total loss of funds. Only use funds you can afford to lose. You should conduct your own research and consult qualified professional advisors before making financial decisions.

By using YieldAgent, you acknowledge and accept these risks.

Static analysis

No suspicious patterns detected.