Back to skill

Security audit

DanceArc

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only DanceArc payment-protocol skill with disclosed testnet payment and credential guidance.

Install this only if you intend to work with DanceArc or Arc Testnet payment flows. Verify the external repository before manual installation, keep Circle secrets and private keys out of browser or agent-visible contexts, and confirm chain, recipient, and amount before sending any USDC.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.