Back to skill

Security audit

Api3 Feed Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill’s purpose is legitimate and mostly disclosed, but it handles blockchain signing through raw private-key command arguments and can report a submitted transaction as complete before confirmation.

Install only if you are comfortable reviewing transaction plans and using it in dry-run mode first. Do not pass a valuable wallet private key on the command line; prefer an isolated test wallet or a safer signer flow. Treat any submitted transaction hash as pending until you independently verify a successful receipt and feed readiness on-chain.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/api3-feed-manager.js:135
Finding

Private Key Exposed Through Command-Line Arguments

Content
View full analysis
api3-feed-manager execute-buy-subscription \ --dapi-name ETH/USD \ --rpc-url https://arb1.arbitrum.io/rpc \ --chain arbitrum \ --execution-mode wrapper \ --private-key api3-feed-manager deploy-communal-proxy \ --dapi-name ETH/USD \ --rpc-url https://arb1.arbitrum.io/rpc \ --chain arbitrum \ --private-key ``` The value is parsed from the process argument list and used directly to construct a wallet: ```js async function executePreparedContractCall({ preparedContractCall, rpcUrl, privateKey, submit, acknowledgement, simulationFromAddress }) { // ... if (!rpcUrl || !privateKey) { executionSummary.failureReason = 'Execution requires rpcUrl and privateKey.'; return { executionSummary, transactionRequest: null, callResult: null }; } if (submit && acknowledgement !== SEND_ACKNOWLEDGEMENT) { executionSummary.failureReason = `Submitting requires acknowledgement=${SEND_ACKNOWLEDGEMENT}.`; return { executionSummary, transactionRequest: null, callResult: null }; } const provider = new JsonRpcProvider(rpcUrl); const wallet = new Wallet(privateKey, provider); const signerAddress = await wallet.getAddress(); executionSummary.signerAddress = signerAddress; ``` The proxy deployment path uses the same pattern: ```js if (!options.privateKey) { executionSummary.failureReason = 'Execution requires ...[truncated 2685 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/api3-feed-manager.js:1533
Finding

Subscription Transaction Reported Complete Before Receipt Confirmation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises network-dependent behavior and potentially signer-backed execution, but it does not declare an explicit tool scope such as allowed tools or permissions. That creates an authorization ambiguity where a host agent may grant broader capabilities than intended, increasing the risk of unintended external calls or transaction-related actions under a loosely bounded runtime.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
## Operating rules

1. Do not pretend a feed is active without checking.
2. Distinguish clearly between:
   - feed missing
   - feed present but unfunded

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill’s documented scope expands from Api3 feed management into downstream EVK and Morpho deployment orchestration, including sequencing live transactions and post-send verification. Scope expansion increases the attack surface and raises the chance that a caller invokes sensitive deployment behavior through a skill that appears narrower and safer from its title and primary description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The spec defines execution-capable actions such as ensuring activation and topping up feeds, which can trigger on-chain transactions and spend funds, but it does not require an explicit user-facing warning or confirmation at the action level. In an agent setting, this creates a real risk of unintended asset expenditure, especially if a downstream implementation treats these commands as routine maintenance rather than financially sensitive operations.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency uses a caret range, which allows npm to install newer minor or patch releases than the version originally tested. This can introduce supply-chain risk or unexpected behavior if an upstream package ships a compromised or breaking update, and this skill interacts with blockchain/oracle tooling where dependency integrity matters.

Content

Scanner excerpt · package.json (reported line 31)May include surrounding context.

json
"check": "node --check scripts/api3-feed-manager.js && node --check scripts/bin/api3-feed-manager.js"
  },
  "dependencies": {
    "@api3/contracts": "^37.0.0",
    "@api3/dapi-management": "^4.15.0",
    "ethers": "^6.15.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency is specified with a caret version range, so installations may resolve to newer upstream releases without explicit review. In a skill that manages Api3 feed activation and funding workflows, this raises supply-chain and reliability risk because changed package behavior could affect blockchain transaction preparation or execution.

Content

Scanner excerpt · package.json (reported line 32)May include surrounding context.

json
},
  "dependencies": {
    "@api3/contracts": "^37.0.0",
    "@api3/dapi-management": "^4.15.0",
    "ethers": "^6.15.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Using a caret range for ethers permits automatic adoption of later compatible releases, which can still contain regressions or maliciously introduced code if the upstream supply chain is compromised. Because ethers is a core library for signer and transaction handling, unexpected changes could affect transaction safety or execution paths in this skill.

Content

Scanner excerpt · package.json (reported line 33)May include surrounding context.

json
"dependencies": {
    "@api3/contracts": "^37.0.0",
    "@api3/dapi-management": "^4.15.0",
    "ethers": "^6.15.0"
  }
}

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.secret_argv_exposure

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/api3-feed-manager.js:3247

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
README.md:43