Back to skill

Security audit

Aavegotchi GBM Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing Aavegotchi GBM auctions, but it asks for a wallet private key and uses it in command-line transaction broadcasts that could expose the key.

Install only if you are comfortable giving the skill access to a dedicated, low-balance wallet for Base mainnet auction activity. Do not use a primary wallet or treasury key. Prefer a hardware wallet, keystore, or external signer instead of raw PRIVATE_KEY command arguments, and keep DRY_RUN enabled until you explicitly choose to broadcast a transaction.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:180
Finding

Wallet Private Key Exposed Through Command-Line Arguments

Content
View full analysis
,,1,,0x73ad2146,,,)" \ "" "" \ --private-key "$PRIVATE_KEY" \ --rpc-url "$BASE_MAINNET_RPC" ``` The same `--private-key "$PRIVATE_KEY"` pattern is repeated in the documented commands for creating, cancelling, bidding on, and claiming auctions, as well as token and NFT approval operations. ### Technical Analysis Although the private key is read from an environment variable and the instructions explicitly prohibit printing or logging it, passing it to `cast` using the `--private-key` option places the expanded secret in the process argument vector. Depending on the operating system, container configuration, process-monitoring software, shell instrumentation, and CI/CD environment, command-line arguments may be observable through: - Process inspection utilities and `/proc//cmdline`. - Endpoint monitoring or process-accounting systems. - CI/CD command telemetry and diagnostic collectors. - Shell wrappers, debugging modes, or audit frameworks that record executed commands. - Other processes operating under the same user identity or with elevated process-inspection privileges. The private key is the primary credential for this Skill and authorizes irreversible Base mainnet transactions. The safety measures involving `DRY_RUN`, chain-ID checks, address alignment, simul ...[truncated 2278 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
requires:
      bins:
        - cast
        - curl
        - python3
      env:
        - FROM_ADDRESS

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/subgraph.md (reported line 14)May include surrounding context.

Auction By ID

bash
curl -s "$GBM_SUBGRAPH_URL" -H 'content-type: application/json' ${GOLDSKY_API_KEY:+-H "Authorization: Bearer $GOLDSKY_API_KEY"} --data '{
  "query":"query($id:ID!){ auction(id:$id){ id type contractAddress tokenId quantity seller highestBid highestBidder totalBids lastBidTime startsAt endsAt claimAt claimed cancelled presetId category buyNowPrice startBidPrice bidDecimals stepMin incMin incMax bidMultiplier dueIncentives auctionDebt } }",
  "variables":{"id":"<AUCTION_ID>"}
}'

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/swap-math.md (reported line 21)May include surrounding context.

If GHST_USD_PRICE / ETH_USD_PRICE are unset, fetch them:

bash
curl -s 'https://api.coingecko.com/api/v3/simple/price?ids=aavegotchi,ethereum&vs_currencies=usd' \
  | python3 -c 'import json,sys; j=json.load(sys.stdin); print(\"GHST_USD\", j[\"aavegotchi\"][\"usd\"]); print(\"ETH_USD\", j[\"ethereum\"][\"usd\"])'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
requires:
      bins:
        - cast
        - curl
        - python3
      env:
        - FROM_ADDRESS

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

~/.foundry/bin/cast call "$GBM_DIAMOND" 'getTokenKind(uint256)(bytes4)' "<AUCTION_ID>" --rpc-url "$BASE_MAINNET_RPC"

text

## Create Auction

Onchain method:
- `createAuction((uint80,uint80,uint56,uint8,bytes4,uint256,uint96,uint96),address,uint256)(uint256)`

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description limits the skill to viewing, creating, canceling, bidding, and claiming GBM auctions. This section documents buyNow and swapAndBuyNow, which are distinct auction-purchase capabilities not mentioned in the manifest and materially expand what the skill can do onchain.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 356)May include surrounding context.

Subgraph Convenience: Auction By ID

bash
curl -s "$GBM_SUBGRAPH_URL" -H 'content-type: application/json' ${GOLDSKY_API_KEY:+-H "Authorization: Bearer $GOLDSKY_API_KEY"} --data '{
  "query":"query($id:ID!){ auction(id:$id){ id type contractAddress tokenId quantity seller highestBid highestBidder totalBids startsAt endsAt claimAt claimed cancelled presetId category buyNowPrice startBidPrice } }",
  "variables":{"id":"<AUCTION_ID>"}
}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/recipes.md (reported line 29)May include surrounding context.

Subgraph Convenience: Auction By ID

bash
curl -s "$GBM_SUBGRAPH_URL" -H 'content-type: application/json' ${GOLDSKY_API_KEY:+-H "Authorization: Bearer $GOLDSKY_API_KEY"} --data '{
  "query":"query($id:ID!){ auction(id:$id){ id type contractAddress tokenId quantity seller highestBid highestBidder totalBids startsAt endsAt claimAt claimed cancelled presetId category buyNowPrice startBidPrice } }",
  "variables":{"id":"<AUCTION_ID>"}
}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
# Subgraph Queries (Base GBM Auctions)

Endpoint:
- `GBM_SUBGRAPH_URL=https://api.goldsky.com/api/public/project_cmh3flagm0001r4p25foufjtt/subgraphs/aavegotchi-gbm-baazaar-base/prod/gn`

Notes:
- `Bytes` fields (addresses) are lowercase in responses; when filtering, use lowercase addresses.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/addresses.md (reported line 15)May include surrounding context.

md
# Subgraph Queries (Base GBM Auctions)

Endpoint:
- `GBM_SUBGRAPH_URL=https://api.goldsky.com/api/public/project_cmh3flagm0001r4p25foufjtt/subgraphs/aavegotchi-gbm-baazaar-base/prod/gn`

Notes:
- `Bytes` fields (addresses) are lowercase in responses; when filtering, use lowercase addresses.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/addresses.md (reported line 36)May include surrounding context.

md
# Subgraph Queries (Base GBM Auctions)

Endpoint:
- `GBM_SUBGRAPH_URL=https://api.goldsky.com/api/public/project_cmh3flagm0001r4p25foufjtt/subgraphs/aavegotchi-gbm-baazaar-base/prod/gn`

Notes:
- `Bytes` fields (addresses) are lowercase in responses; when filtering, use lowercase addresses.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/subgraph.md (reported line 4)May include surrounding context.

md
# Subgraph Queries (Base GBM Auctions)

Endpoint:
- `GBM_SUBGRAPH_URL=https://api.goldsky.com/api/public/project_cmh3flagm0001r4p25foufjtt/subgraphs/aavegotchi-gbm-baazaar-base/prod/gn`

Notes:
- `Bytes` fields (addresses) are lowercase in responses; when filtering, use lowercase addresses.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/subgraph.md (reported line 14)May include surrounding context.

Auction By ID

bash
curl -s "$GBM_SUBGRAPH_URL" -H 'content-type: application/json' ${GOLDSKY_API_KEY:+-H "Authorization: Bearer $GOLDSKY_API_KEY"} --data '{
  "query":"query($id:ID!){ auction(id:$id){ id type contractAddress tokenId quantity seller highestBid highestBidder totalBids lastBidTime startsAt endsAt claimAt claimed cancelled presetId category buyNowPrice startBidPrice bidDecimals stepMin incMin incMax bidMultiplier dueIncentives auctionDebt } }",
  "variables":{"id":"<AUCTION_ID>"}
}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/swap-math.md (reported line 21)May include surrounding context.

If GHST_USD_PRICE / ETH_USD_PRICE are unset, fetch them:

bash
curl -s 'https://api.coingecko.com/api/v3/simple/price?ids=aavegotchi,ethereum&vs_currencies=usd' \
  | python3 -c 'import json,sys; j=json.load(sys.stdin); print(\"GHST_USD\", j[\"aavegotchi\"][\"usd\"]); print(\"ETH_USD\", j[\"ethereum\"][\"usd\"])'

Static analysis

No suspicious patterns detected.