Back to skill

Security audit

Aavegotchi Baazaar

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly transparent about Aavegotchi marketplace operations, but it includes high-impact crypto approval commands that can broadcast without the safety gates the skill itself says are mandatory.

Review carefully before installing. Use only a wallet with funds you are willing to put at risk, keep DRY_RUN enabled by default, and do not run the approval recipes unless you manually verify the chain, signer, token or NFT contract, spender, amount, and explicit confirmation gates. Be especially cautious with setApprovalForAll because it grants collection-wide operator authority until revoked.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/recipes.md:42
Finding

Approval Transactions Bypass Mandatory Dry-Run and Confirmation Gates

Content
View full analysis

Vulnerability Details

File Location: references/recipes.md:42-68
Vulnerability Type: Missing transaction safety controls
Risk Level: Medium

The approval recipes directly broadcast three security-sensitive transactions:

bash
Approve GHST (broadcast; do this only when explicitly instructed):
```bash
~/.foundry/bin/cast send "$GHST" 'approve(address,uint256)' "$DIAMOND" "<AMOUNT_GHST_WEI>" \
  --private-key "$PRIVATE_KEY" \
  --rpc-url "$BASE_MAINNET_RPC"

Approve USDC (broadcast; do this only when explicitly instructed):

bash
~/.foundry/bin/cast send "$USDC" 'approve(address,uint256)' "$DIAMOND" "<AMOUNT_USDC_6DP>" \
  --private-key "$PRIVATE_KEY" \
  --rpc-url "$BASE_MAINNET_RPC"

Set approval (broadcast; do this only when explicitly instructed):

bash
~/.foundry/bin/cast send "<NFT_CONTRACT_ADDRESS>" 'setApprovalForAll(address,bool)' "$DIAMOND" true \
  --private-key "$PRIVATE_KEY" \
  --rpc-url "$BASE_MAINNET_RPC"
text

This conflicts with the mandatory policy in `SKILL.md:34-38`, which states that every `cast send` must first be simulated and must require both `DRY_RUN=0` and `BROADCAST_CONFIRM=CONFIRM_SEND`.

### Technical Analysis

The approval commands call `cast send` directly. They do not:

- Simulate the exact transaction with `cast call`.
- Enforce the default dry-run setting.
- Verify `BROADCAST_CONFIRM=CONFIRM_SEND`.
- Ensure the transaction arguments still match what the user confirmed.
- Unset the confirmation token after broadcast.
- Locally enforce chain-ID, signer-address, or canonical contract-address validation.

The surrounding phrase “only when explicitly instructed” is advisory text rather than an executable control. An agent that selects an allowlisted recipe can therefore broadcast it despite `DRY_RUN` retaining its safe default or no confirmation token being present.

ERC20 approvals authoriz
...[truncated 1930 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add an exact cast call simulation before every approval broadcast.

  2. Display a transaction summary containing the chain ID, signer, token or NFT contract, spender/operator, amount, RPC endpoint, and whether blanket NFT approval is being granted.

  3. Add fail-closed checks immediately before each cast send:

    bash
    test "${DRY_RUN:-1}" = "0" || {
      echo "Refusing broadcast: DRY_RUN must be 0"
      exit 1
    }
    test "${BROADCAST_CONFIRM:-}" = "CONFIRM_SEND" || {
      echo "Refusing broadcast: explicit confirmation is required"
      exit 1
    }
    
  4. Revalidate that the Base chain ID is 8453 and that the private key derives the expected FROM_ADDRESS.

  5. Validate every address as exactly 0x followed by 40 hexadecimal characters, and verify critical addresses against canonical allowlisted values.

  6. Bind confirmation to the complete transaction arguments. Invalidate confirmation if the asset, spender, amount, operator flag, sender, chain, or RPC endpoint changes.

  7. Unset BROADCAST_CONFIRM immediately after the send attempt.

  8. Prefer exact, minimal ERC20 allowances rather than unlimited approvals.

  9. Warn prominently that setApprovalForAll grants collection-wide authority, and offer revocation through setApprovalForAll(operator, false).

  10. Consolidate all broadcasts behind one guarded wrapper so recipes cannot omit mandatory controls.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (14)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/recipes.md (reported line 100)May include surrounding context.

If GHST_USD_PRICE is unset, fetch it:

bash
curl -s 'https://api.coingecko.com/api/v3/simple/price?ids=aavegotchi&vs_currencies=usd' \
  | python3 -c 'import json,sys; print(json.load(sys.stdin)["aavegotchi"]["usd"])'

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/usdc-swap-math.md (reported line 64)May include surrounding context.

If GHST_USD_PRICE is unset, fetch it:

bash
curl -s 'https://api.coingecko.com/api/v3/simple/price?ids=aavegotchi&vs_currencies=usd' \
  | python3 -c 'import json,sys; print(json.load(sys.stdin)["aavegotchi"]["usd"])'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
Allowlisted command templates:
- `~/.foundry/bin/cast chain-id|wallet address|call|send ...` using fixed ABI signatures from this skill.
- `curl -s "$SUBGRAPH_URL" -H 'content-type: application/json' --data '...static GraphQL query...'`.
- `curl -s "$COINGECKO_SIMPLE_PRICE_URL"` for GHST/USD only.
- `python3` inline snippets from this skill/references for validation and deterministic math only.
- Disallow `eval`, `bash -c`, `sh -c`, backticks, and `$(...)` with untrusted input.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

Get ERC721 listing by id:

bash
curl -s "$SUBGRAPH_URL" -H 'content-type: application/json' --data '{
  "query":"query($id: ID!){ erc721Listing(id:$id){ id category erc721TokenAddress tokenId seller priceInWei cancelled timeCreated timePurchased } }",
  "variables":{"id":"1"}
}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
# Subgraph Queries (Base)

Endpoint:
- `SUBGRAPH_URL=https://api.goldsky.com/api/public/project_cmh3flagm0001r4p25foufjtt/subgraphs/aavegotchi-core-base/prod/gn`

Notes:
- `seller`, `erc721TokenAddress`, `erc1155TokenAddress` are `Bytes` fields; use `0x...` hex strings (lowercase is safest).

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
# Subgraph Queries (Base)

Endpoint:
- `SUBGRAPH_URL=https://api.goldsky.com/api/public/project_cmh3flagm0001r4p25foufjtt/subgraphs/aavegotchi-core-base/prod/gn`

Notes:
- `seller`, `erc721TokenAddress`, `erc1155TokenAddress` are `Bytes` fields; use `0x...` hex strings (lowercase is safest).

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/addresses.md (reported line 15)May include surrounding context.

md
# Subgraph Queries (Base)

Endpoint:
- `SUBGRAPH_URL=https://api.goldsky.com/api/public/project_cmh3flagm0001r4p25foufjtt/subgraphs/aavegotchi-core-base/prod/gn`

Notes:
- `seller`, `erc721TokenAddress`, `erc1155TokenAddress` are `Bytes` fields; use `0x...` hex strings (lowercase is safest).

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/addresses.md (reported line 23)May include surrounding context.

md
# Subgraph Queries (Base)

Endpoint:
- `SUBGRAPH_URL=https://api.goldsky.com/api/public/project_cmh3flagm0001r4p25foufjtt/subgraphs/aavegotchi-core-base/prod/gn`

Notes:
- `seller`, `erc721TokenAddress`, `erc1155TokenAddress` are `Bytes` fields; use `0x...` hex strings (lowercase is safest).

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/subgraph.md (reported line 4)May include surrounding context.

md
# Subgraph Queries (Base)

Endpoint:
- `SUBGRAPH_URL=https://api.goldsky.com/api/public/project_cmh3flagm0001r4p25foufjtt/subgraphs/aavegotchi-core-base/prod/gn`

Notes:
- `seller`, `erc721TokenAddress`, `erc1155TokenAddress` are `Bytes` fields; use `0x...` hex strings (lowercase is safest).

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/subgraph.md (reported line 108)May include surrounding context.

}

text

Example curl (seller should be lowercase):
```bash
curl -s "$SUBGRAPH_URL" -H 'content-type: application/json' --data '{
  "query":"query($seller: Bytes!, $first: Int!){ erc721Listings(first: $first, orderBy: timeCreated, orderDirection: desc, where:{seller: $seller}){ id erc721TokenAddress tokenId priceInWei timeCreated cancelled timePurchased } }",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

If GHST_USD_PRICE is unset, fetch it:

bash
curl -s 'https://api.coingecko.com/api/v3/simple/price?ids=aavegotchi&vs_currencies=usd' \
  | python3 -c 'import json,sys; print(json.load(sys.stdin)["aavegotchi"]["usd"])'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

If GHST_USD_PRICE is unset, fetch it:

bash
curl -s 'https://api.coingecko.com/api/v3/simple/price?ids=aavegotchi&vs_currencies=usd' \
  | python3 -c 'import json,sys; print(json.load(sys.stdin)["aavegotchi"]["usd"])'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/recipes.md (reported line 100)May include surrounding context.

If GHST_USD_PRICE is unset, fetch it:

bash
curl -s 'https://api.coingecko.com/api/v3/simple/price?ids=aavegotchi&vs_currencies=usd' \
  | python3 -c 'import json,sys; print(json.load(sys.stdin)["aavegotchi"]["usd"])'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/usdc-swap-math.md (reported line 64)May include surrounding context.

If GHST_USD_PRICE is unset, fetch it:

bash
curl -s 'https://api.coingecko.com/api/v3/simple/price?ids=aavegotchi&vs_currencies=usd' \
  | python3 -c 'import json,sys; print(json.load(sys.stdin)["aavegotchi"]["usd"])'

Static analysis

No suspicious patterns detected.