Back to skill

Security audit

solana-skill

Security checks for vulnerabilities and agentic risk

Overview

This Solana wallet skill is mostly purpose-aligned, but it handles real wallet keys and on-chain transactions with weak key protection and insufficient transaction safety controls.

Review this carefully before installing. Do not use it with wallets holding meaningful funds unless key storage is changed to a real user passphrase, hardware wallet, OS keychain, or other strong secret store, and transaction signing is changed to show decoded details and require explicit confirmation. Treat swaps as especially risky because the current code signs a transaction returned by a remote API without independently verifying its instructions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wallet.ts:68
Finding

Predictable Machine-Derived Key Allows Wallet Private-Key Recovery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wallet.ts:78
Finding

Wallet Name Path Traversal Permits File Access Outside the Wallet Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/swap.ts:107
Finding

Remote Jupiter Transaction Is Signed Without Instruction Verification or Simulation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/send.ts:57
Finding

Transfers and Swaps Execute Without Mandatory Confirmation or Complete Numeric Bounds

Content
View full analysis
{ if (!isValidAddress(toAddress)) { throw new Error(`Invalid recipient address: ${toAddress}`); } if (amount <= 0) { throw new Error('Amount must be positive'); } const config = loadConfig(); const connection = new Connection(getRpcUrl(config), 'confirmed'); const fromWallet = loadWallet(fromWalletName); const toPubkey = new PublicKey(toAddress); ``` ```typescript const signature = await sendAndConfirmTransaction(connection, tx, [fromWallet], { commitment: 'confirmed' }); ``` SPL-token transfers do not apply the same explicit positive and finite amount validation: ```typescript export async function sendToken( fromWalletName: string, toAddress: string, mintAddress: string, amount: number ): Promise { if (!isValidAddress(toAddress)) { throw new Error(`Invalid recipient address: ${toAddress}`); } if (!isValidAddress(mintAddress)) { throw new Error(`Invalid mint address: ${mintAddress}`); } ``` ```typescript const amountRaw = BigInt(Math.floor(amount * Math.pow(10, decimals))); ``` Swap execution accepts caller-controlled slippage without enforcing a safe range: ```typescript const amount = parseFloat(amountStr); const slippageBps = slippageStr ? parseInt(slippageStr) : 100; const result = await executeSwap(wallet, inputToken, outputToken, amount, slippageBps); ``` No mandatory confirmation occurs before any of these irreversible operations. ### Technical Analysis The Skill documentation states that large transactions s ...[truncated 1989 chars]
Remediation
View remediation
0` for every transfer and swap entry point, including exported functions. 4. Enforce a conservative, configurable slippage range, such as `0 <= slippageBps <= 300`, with stricter defaults for major assets. 5. Parse decimal amounts as strings and convert them to integer base units without binary floating-point arithmetic. 6. Reject values with more fractional digits than the token supports instead of silently flooring them. 7. Require finalized confirmation for high-value operations where the additional latency is acceptable. 8. Ensure agent integrations cannot bypass confirmation merely by calling exported functions rather than the CLI. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (66)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code partially matches the description: it does manage wallets and check SOL/token balances, including using Helius-compatible RPC/DAS calls for full balance data. However, the declared purpose substantially overstates the implemented functionality. There is no code for sending transactions, transferring tokens, Jupiter integration, swaps, address monitoring, or general-purpose Solana operations. The actual code is a narrower wallet-management and balance-checking utility with local encrypted key storage and a CLI. This is a material description-to-behavior mismatch due to missing major advertised capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill encourages importing private keys or seed phrases without a prominent warning that these credentials grant full wallet control and should almost never be pasted into an agent workflow. In this context, exposing seed phrases to an LLM-integrated system can directly lead to irreversible theft of all associated assets.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes sending transactions and swaps on mainnet without an upfront warning that these actions are irreversible and affect real funds. In a blockchain wallet context, insufficient warnings and confirmation friction increase the likelihood of accidental transfers, bad swaps, or loss due to user misunderstanding.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
See [references/security.md](references/security.md) for detailed security practices.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
See [references/security.md](references/security.md) for detailed security practices.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises capabilities that require network access and likely access to locally stored secrets, but it does not declare any explicit tool scope or permission boundaries. In a wallet-management skill, missing scope declarations weakens least-privilege controls and can cause the agent to invoke the skill in broader contexts than intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation scope is excessively broad, covering essentially any Solana or crypto-wallet request. In an agent ecosystem, such breadth increases the chance the skill is auto-selected for sensitive actions involving wallets, trading, or monitoring even when a narrower, safer skill should be used.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The script invokes npx tsx rather than a fully pinned, locally resolved binary. If dependency resolution or the execution environment allows fetching a different tsx release, a compromised or unexpected package version could execute arbitrary code during wallet-management operations, which is especially sensitive in a blockchain skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This script also uses npx tsx without guaranteeing an exact local version. In a package that creates and lists wallets, any execution-time package substitution could expose secrets or alter blockchain operations before the user notices.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx tsx for the balance command introduces supply-chain and execution-path risk because the effective binary may not be a strictly pinned build. In a crypto context, even read-oriented commands can be a foothold for credential theft, address substitution, or malicious side effects.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The send-transaction script depends on npx tsx without an exact trusted version. Because this skill can transfer funds, any hijacked or substituted runtime dependency could directly tamper with transaction destinations, amounts, or signing flow, making the risk more severe than in a non-financial package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The swap script uses npx tsx with no exact version guarantee. In a DeFi swap workflow, a compromised execution tool could manipulate routes, token approvals, or destination accounts, potentially causing direct financial loss.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/helius-api.md (reported line 112)May include surrounding context.

Convert raw transactions to human-readable format.

typescript
const response = await fetch('https://api.helius.xyz/v0/transactions', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/helius-api.md (reported line 112)May include surrounding context.

Convert raw transactions to human-readable format.

typescript
const response = await fetch('https://api.helius.xyz/v0/transactions', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/helius-api.md (reported line 135)May include surrounding context.

Convert raw transactions to human-readable format.

typescript
const response = await fetch('https://api.helius.xyz/v0/transactions', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/jupiter.md (reported line 9)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/jupiter.md (reported line 10)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/jupiter.md (reported line 11)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/jupiter.md (reported line 34)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/jupiter.md (reported line 64)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/jupiter.md (reported line 137)May include surrounding context.

md
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/wallet.ts:73

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/wallet.ts:87