Back to skill

Security audit

LI.FI Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent LI.FI swap and bridge integration, but it handles real wallet transactions with weak required safeguards that users should review carefully.

Review before installing if this will control a real wallet. Use conservative slippage, avoid unlimited approvals, verify spender and transaction details, and require an explicit confirmation step before any wallet signs or broadcasts a transaction.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:26
Finding

Mandatory Transaction Simulation Bypass

Content
View full analysis
0x0): Use `defi_send_transaction` with the quote's `transactionRequest` fields: **to, value, data, chainId, and gasLimit** (ALWAYS pass `gasLimit` from the quote). **NEVER construct approve calldata hex yourself.** The `defi_approve` and `defi_approve_and_send` tools handle ABI encoding correctly. **Sui:** For quotes where `fromChain` or `toChain` is Sui, use `defi_send_sui_transaction` with the quote's transaction bytes. No approval step. ``` ### Technical Analysis The Skill requires every LI.FI quote request to disable provider-side simulation. It then instructs the agent to pass transaction fields or transaction bytes returned by the external API into wallet execution tools. The instructions do not require an equivalent independent simulation or comprehensive validation of the returned destination, chain, value, calldata, token addresses, recipient, and expected asset changes. Simulation is an important defense against reverted transactions and unexpected contract behavior. Although the documented reason is compatibility with EIP-7702 delegated wallets, disabling the control globally exceeds what is necessary: the exception is applied to all quote requests rather than only affected wallet types and is not replaced by another verification mechanism. ### Attack Path 1. A user requests a swap or bridge. 2. The Skill sends a quote request with `skipSimulation=true`. 3. LI.FI or an upstream routing component returns a transaction payload. 4. The response is malformed, comprom ...[truncated 949 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:24
Finding

Overly Permissive Default Slippage

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:82
Finding

Unlimited ERC-20 Approval Permitted Without Mandatory Safeguards

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- LI.FI supports **Sui** for same-chain swaps and bridging to/from EVM and Solana.
- For Sui quotes, use the user's **suiAddress** from `defi_get_wallet` as `fromAddress`.
- **Execute Sui quotes with `defi_send_sui_transaction`** — pass the transaction bytes (hex) from the LI.FI quote. Do **not** use `defi_send_transaction` or `defi_approve_and_send` for Sui.
- Sui does not use ERC-20 approvals; there is no approval step for Sui swaps.

## Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

GET /v1/chains — List supported chains

bash
curl -s --request GET \
  --url https://li.quest/v1/chains \
  --header "x-lifi-api-key: $LIFI_API_KEY"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
**NEVER construct approve calldata hex yourself.** The `defi_approve` and `defi_approve_and_send` tools handle ABI encoding correctly.

**Sui:** For quotes where `fromChain` or `toChain` is Sui, use `defi_send_sui_transaction` with the quote's transaction bytes. No approval step.

### POST /v1/advanced/routes — Get multiple route options

Static analysis

No suspicious patterns detected.