Back to skill

Security audit

Agentic Lending Morpho Readonly

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only Morpho lending planning guide that clearly avoids signing, funding, deployment, or transaction submission.

Install this only if you want read-only Morpho/Api3 lending planning. Do not provide private keys, seed phrases, wallet signing access, or permission to broadcast transactions. If you run the suggested Node planner command, verify the local script first and ask the agent to separate live RPC results from cached or prior-run information.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.