Back to skill

Security audit

Etherscan Transaction Debugger

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Etherscan transaction-analysis helper, and I found no hidden exfiltration, destructive behavior, or persistence.

Install only if you are comfortable with the agent querying Etherscan or an Etherscan-family explorer for transaction data and using any configured Etherscan CLI credentials. Review generated reports for uncertainty around partial internal transaction data, traces, labels, and decoded token metadata.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code’s behavior is narrower and materially different from the declared description. It is a summarizer over an already collected bundle, not a live Etherscan-backed transaction analysis skill. It performs useful transaction summarization tasks consistent with part of the description—status, fees, some token events, native movements, and warnings—but it lacks several core declared capabilities: no network/Etherscan access, no evidence-link generation, no plain-English explanatory output, no full execution-path reconstruction, no proxy analysis, and no detailed revert-site identification. This is more than an implementation detail because the declared primary purpose emphasizes live Etherscan investigation and explanatory evidence-based analysis, while the code is an offline post-processing component.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/transaction-report-template.md (reported line 3)May include surrounding context.

md
# Etherscan Transaction Verdict

<!-- Lead with the outcome and note that it was reconstructed from live Etherscan evidence. Remove unused sections. -->

## Transaction Summary

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill references local scripts and guidance documents and explicitly prefers a CLI workflow, but it does not declare any tool restrictions or allowed-tools scope. In a tool-enabled agent environment, that ambiguity can permit broader-than-necessary file and shell access, increasing the chance of unintended command execution, unsafe file writes, or data exposure through supporting scripts.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/collect_transaction_data.py (reported line 50)May include surrounding context.

python
) -> tuple[Any, str | None]:
    command = [executable, *args, "--chain", chain, "--output", "json"]
    try:
        completed = subprocess.run(
            command,
            capture_output=True,
            text=True,

Static analysis

No suspicious patterns detected.