Back to skill

Security audit

Carbon DeFi

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for Carbon DeFi trading, but it uses an unpinned local MCP launcher and broad curl access in a high-risk financial workflow.

Install only if you are comfortable with a remote Carbon DeFi MCP service and local `npx` execution. Pin and verify the MCP client package where possible, restrict curl/network access to Carbon DeFi domains, and independently verify every unsigned transaction's destination, calldata, value, and token allowances before signing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party Package Execution via npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–25
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

markdown
## Connect to the MCP Server

Add to Claude Desktop config (`~/Library/Application Support/Claude/claude_desktop_config.json`):

```json
{
  "mcpServers": {
    "carbon-defi": {
      "command": "npx",
      "args": ["mcp-remote", "https://mcp.carbondefi.xyz/mcp"]
    }
  }
}
text

### Technical Analysis

The documented configuration launches `mcp-remote` through `npx` without specifying an exact package version. Depending on the local npm environment, `npx` may retrieve and execute the package version currently resolved from the configured package registry.

The project provides no lockfile, integrity hash, verified artifact, or package-version constraint for this command. Consequently, the code executed on a user's machine can change after the Skill has been reviewed. A compromised package publisher, npm account, registry, or newly published malicious release could turn the documented setup command into a local code-execution vector.

Connecting to the remote MCP endpoint is part of the Skill's declared functionality and is not, by itself, evidence of malicious behavior. The confirmed weakness is the unsafe, unpinned dependency execution mechanism.

### Attack Path

1. An attacker compromises the `mcp-remote` package publisher, its release process, or a package registry used by the victim.
2. The attacker publishes a malicious release that remains resolvable under the unversioned package name.
3. A user follows the Skill's instructions and adds the supplied `npx mcp-remote` configuration to Claude Desktop.
4. Claude Desktop invokes `npx`, which retrieves or resolves the attacker-controlled package release.
5. The malicious package executes with the privileges of the desktop user.
6. It may access files and creden
...[truncated 755 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin mcp-remote to an exact, reviewed version rather than resolving the latest available release.
  2. Install the dependency through a lockfile-controlled deployment process and verify the package integrity hash.
  3. Document the expected package publisher, version, checksum, and trusted registry.
  4. Prefer a locally installed and reviewed MCP client binary over implicit runtime downloads through npx.
  5. Disable npm lifecycle scripts where compatible with the package and deployment process.
  6. Run the MCP client under a dedicated, least-privileged account or sandbox with restricted filesystem, credential, and network access.
  7. Require users to verify unsigned transaction destination addresses and calldata against independently published Carbon DeFi contract addresses and encoding specifications before signing.
  8. Establish a controlled update process in which new dependency versions are reviewed and tested before deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger text is very broad, including phrases like 'any mention of Carbon DeFi' and generic trading intents across multiple chains. This can cause the skill to activate in conversations where the user did not clearly request this specific integration, increasing the chance of unnecessary wallet-related guidance or external tool use in a high-risk financial context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill explicitly permits Bash with unrestricted curl usage, enabling outbound network requests to external services. In a wallet and trading workflow, this broad egress capability can transmit sensitive wallet addresses, strategy details, or user-provided data to remote endpoints beyond the intended API surface if misused or combined with prompt injection.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
withdraw from a strategy", "full range liquidity", "provide liquidity and earn fees",
  or any mention of Carbon DeFi, maker orders, or on-chain automated trading strategies
  on Ethereum, Sei, Celo, TAC, or COTI.
allowed-tools: Bash(curl *)
---

# Carbon DeFi — On-Chain Maker Trading via MCP

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

Run multiple tools in parallel as a single request (counts against rate limit once):

bash
curl -X POST https://mcp.carbondefi.xyz/batch \
  -H "Content-Type: application/json" \
  -d '[
    {"tool": "get_strategies", "params": {"owner": "0x...", "chain": "ethereum"}},

Static analysis

No suspicious patterns detected.