T09 · Insecure Skill Coding Practices
- Location
SKILL.md:26- Finding
Mandatory Transaction Simulation Bypass
- Content
View full analysis
0x0): Use `defi_send_transaction` with the quote's `transactionRequest` fields: **to, value, data, chainId, and gasLimit** (ALWAYS pass `gasLimit` from the quote). **NEVER construct approve calldata hex yourself.** The `defi_approve` and `defi_approve_and_send` tools handle ABI encoding correctly. **Sui:** For quotes where `fromChain` or `toChain` is Sui, use `defi_send_sui_transaction` with the quote's transaction bytes. No approval step. ``` ### Technical Analysis The Skill requires every LI.FI quote request to disable provider-side simulation. It then instructs the agent to pass transaction fields or transaction bytes returned by the external API into wallet execution tools. The instructions do not require an equivalent independent simulation or comprehensive validation of the returned destination, chain, value, calldata, token addresses, recipient, and expected asset changes. Simulation is an important defense against reverted transactions and unexpected contract behavior. Although the documented reason is compatibility with EIP-7702 delegated wallets, disabling the control globally exceeds what is necessary: the exception is applied to all quote requests rather than only affected wallet types and is not replaced by another verification mechanism. ### Attack Path 1. A user requests a swap or bridge. 2. The Skill sends a quote request with `skipSimulation=true`. 3. LI.FI or an upstream routing component returns a transaction payload. 4. The response is malformed, comprom ...[truncated 949 chars]- Remediation
View remediation
