Back to skill

Security audit

EdgeBets

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed sports simulation SDK, but it can automatically spend real USDC from a Solana wallet with weak confirmation and inconsistent price information.

Review carefully before installing. Do not connect a main wallet or expose a long-lived private key. Use a small, dedicated wallet only if you accept that simulations can spend real USDC on Solana mainnet, and require a manual confirmation flow that verifies the exact amount, recipient, network, and quote before every payment.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
src/services/simulation.ts:52
Finding

Irreversible Payment Is Sent Before Simulation Request Validation

Content
View full analysis
({})); throw new ApiError( errorData.message || `Simulation request failed: ${response.status}`, response.status, errorData ); } const data = await response.json(); return this.normalizeJobResponse(data); } catch (error) { ``` The same unsafe ordering is exposed through `startSimulation()` at `src/cli ...[truncated 2864 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/services/simulation.ts:212
Finding

Quote and Documentation Can Understate the Actual USDC Charge

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (67)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises simulation services but also exposes external betting-pick and track-record retrieval that is not central to Monte Carlo analysis. While not inherently malicious, bundling unrelated remote content features under a narrower description obscures the true data flows and external dependencies of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill advertises simulation services but also exposes external betting-pick and track-record retrieval that is not central to Monte Carlo analysis. While not inherently malicious, bundling unrelated remote content features under a narrower description obscures the true data flows and external dependencies of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill advertises simulation services but also exposes external betting-pick and track-record retrieval that is not central to Monte Carlo analysis. While not inherently malicious, bundling unrelated remote content features under a narrower description obscures the true data flows and external dependencies of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises simulation services but also exposes external betting-pick and track-record retrieval that is not central to Monte Carlo analysis. While not inherently malicious, bundling unrelated remote content features under a narrower description obscures the true data flows and external dependencies of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises simulation services but also exposes external betting-pick and track-record retrieval that is not central to Monte Carlo analysis. While not inherently malicious, bundling unrelated remote content features under a narrower description obscures the true data flows and external dependencies of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises simulation services but also exposes external betting-pick and track-record retrieval that is not central to Monte Carlo analysis. While not inherently malicious, bundling unrelated remote content features under a narrower description obscures the true data flows and external dependencies of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises simulation services but also exposes external betting-pick and track-record retrieval that is not central to Monte Carlo analysis. While not inherently malicious, bundling unrelated remote content features under a narrower description obscures the true data flows and external dependencies of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises simulation services but also exposes external betting-pick and track-record retrieval that is not central to Monte Carlo analysis. While not inherently malicious, bundling unrelated remote content features under a narrower description obscures the true data flows and external dependencies of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill advertises simulation services but also exposes external betting-pick and track-record retrieval that is not central to Monte Carlo analysis. While not inherently malicious, bundling unrelated remote content features under a narrower description obscures the true data flows and external dependencies of the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The exported createClient(secretKey, ...) helper encourages direct ingestion of a Solana private key into the SDK process. For an agent skill described as betting simulation, accepting raw secret keys is unnecessarily sensitive and creates a high-risk path for key theft, logging exposure, memory scraping, or misuse of funds through automated transaction signing.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: bigint-buffer==1.1.5 — 1 advisory(ies): CVE-2025-3194 (bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function)

High
Category
Supply Chain
Confidence
93% confidence
Finding

bigint-buffer 1.1.5 is reported vulnerable to a buffer overflow in toBigIntLE(), and it is pulled into runtime Solana-related code rather than only dev tooling. Because this skill includes blockchain/web3 dependencies that may parse binary data, the context makes memory-safety issues in serialization helpers more concerning.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.11 — 3 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
80% confidence
Finding

nanoid 3.3.11 is flagged for denial-of-service style flaws involving negative, zero, or overflowing size values. In this lockfile it is a dev dependency through PostCSS/Vite, so practical impact is mostly limited to build or tooling workflows that accept attacker-controlled parameters, rather than core runtime execution.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.8 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more

High
Category
Supply Chain
Confidence
86% confidence
Finding

postcss 8.5.8 has multiple advisories including arbitrary file read/information disclosure and XSS-related issues. In this repository it is present as dev/build tooling, so the main exposure is during local or CI processing of attacker-controlled styles or source map inputs, which lowers but does not nullify the risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.20.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
93% confidence
Finding

ws 8.20.0 is affected by memory disclosure and memory exhaustion DoS issues, and it is used by rpc-websockets in runtime networking code. Since Solana/web3 stacks commonly maintain websocket connections to remote RPC endpoints, this context makes a websocket-layer flaw more relevant than a purely dormant dependency issue.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vite==8.0.3 — 5 advisory(ies): CVE-2026-39365 (Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling); CVE-2026-53571 (vite: `server.fs.deny` bypass on Windows alternate paths); CVE-2026-39363 (Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket) +2 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

vite 8.0.3 has several advisories involving path traversal and arbitrary file read in dev-server features. Because Vite is a dev dependency, exploitation generally requires the development server to run in a reachable environment or process attacker-controlled project content, so production risk is lower but developer/CI exposure remains meaningful.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==7.5.10 — 1 advisory(ies): CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
92% confidence
Finding

ws 7.5.10 is vulnerable to memory exhaustion DoS from fragmented data chunks and is included through jayson, a runtime JSON-RPC library. If this skill communicates over websocket-capable RPC channels or can be induced to handle hostile websocket traffic, an attacker may degrade availability through resource exhaustion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file implements real wallet inspection, token balance checks, USDC transfer construction, transaction signing, and generation of a payment proof for on-chain settlement. That is materially beyond a 'sports betting simulation' scope and creates a direct financial action path where users may be induced to send funds; in this context, the mismatch between advertised purpose and actual capability makes the behavior especially dangerous.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code can sign and submit a live USDC transfer to a treasury wallet using either a raw Keypair or wallet adapter, which gives the skill the ability to move real assets. For a tool described as Monte Carlo sports-betting simulations, this capability is not justified by the stated purpose and could enable deceptive monetization, unauthorized charges, or social-engineering-driven fund transfers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README instructs users to load a local Solana secret key file directly in code without any warning about secure handling of private keys. This encourages unsafe credential practices that can lead to wallet compromise, accidental exposure through source control, logs, screenshots, or insecure file permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly promotes paid simulations using real USDC on Solana mainnet but does not clearly warn users that requests can trigger irreversible on-chain spending. In an agent-integration context, this increases the risk of unintended financial loss if a user or agent runs simulations without understanding that real funds will be spent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares network-dependent behavior and payment-backed API usage but does not declare any explicit tool scope or allowed-tools boundary. That weakens reviewability and can let an agent invoke external network actions without clear user-visible permission constraints, which is especially risky because the skill also involves wallet-backed paid operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill notes pricing and wallet setup, but it does not provide a strong, upfront warning that invoking a simulation can trigger a paid on-chain transaction using wallet credentials. In a conversational agent context, users may request analysis casually and unintentionally authorize irreversible financial actions, making the missing warning materially dangerous.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The SDK description centers on sports betting simulations, but the exposed API includes wallet configuration, transaction signing, balance checks, payment flows, and a hardcoded treasury recipient. That is a meaningful expansion of capability into cryptocurrency payment handling, which increases the risk that users or agents invoke sensitive wallet operations without clearly understanding they are authorizing on-chain value transfer.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The secret-key-based client creation implies the SDK may retain highly sensitive wallet credentials in process memory across the session, enabling persistent access for future signed operations. In the context of a betting simulation skill, persistent possession of a private key is more dangerous because the skill also exposes payment and transaction-signing functionality tied to a treasury wallet.

Content

Scanner excerpt · dist/index.d.ts (reported line 604)May include surrounding context.

ts
getPrice(): number;
}
/**
 * Create an EdgeBets client from a secret key
 *
 * @param secretKey - Solana wallet secret key (Uint8Array or number array)
 * @param config - Additional configuration

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This skill transmits data and initiates paid actions against a hard-coded third-party API endpoint and, elsewhere in the file, sends on-chain USDC payments to a hard-coded treasury wallet. In the context of an agent skill, this is security-relevant because user queries can trigger external network requests and financial transactions to infrastructure the user may not independently verify.

Content

Scanner excerpt · dist/index.js (reported line 45)May include surrounding context.

js
var import_web32 = require("@solana/web3.js");

// src/constants.ts
var EDGEBETS_API_URL = "https://api.edgebets.fun/api/v1";
var TREASURY_WALLET = "DuDLnnPzzRo8Yi9AKFEE7rsESVyTzQVPgC6h3FXYaDB4";
var USDC_MINT = "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v";
var USDC_DECIMALS = 6;

Static analysis

No suspicious patterns detected.