Back to skill

Security audit

RumbleTipAI

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about autonomous crypto tipping, but it gives persistent wallet authority for irreversible payments and needs careful review before use.

Review before installing. Use a separate low-balance wallet, avoid importing a primary seed phrase, set strict daily and per-tip caps, keep autonomous mode off unless needed, and confirm that you are comfortable with irreversible crypto transfers based on browser activity and configured rules.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill exposes broad natural-language commands that map to sensitive wallet and payment operations, including creating rules, deleting rules, wallet setup, and sending funds. In an agentic or conversational environment, overly permissive trigger phrases can cause accidental invocation from ordinary chat or prompt-injected page content, leading to unintended financial actions.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill states it silently extracts creator wallet addresses from Rumble pages, but this background collection is not prominently surfaced as a user-facing consent and transparency control near setup. Silent extraction from page activity increases privacy and trust risk, especially in a browser extension that already handles wallet material and autonomous actions.

Static analysis

No suspicious patterns detected.