Back to skill

Security audit

Masumi Network Warranty Vault

Security checks for vulnerabilities and agentic risk

Overview

This skill does not appear to execute malicious code, but it makes high-impact warranty, blockchain, and payment claims that the shipped scripts do not actually support.

Review carefully before installing. Treat this as a prototype or misleading demo, not a reliable warranty, blockchain, or payment integration. Do not rely on its output as proof of an on-chain record or completed payment, and avoid using real receipts or sensitive purchase data until the documentation and implementation are reconciled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
This finding reflects a material mismatch between the declared purpose and the actual behavior surface, especially around real Cardano interaction, OCR, immutable logging, and wallet/payment operations. In a warranty-verification and payment context, misleading descriptions can cause operators to expose receipts, trust nonexistent audit trails, or assume charges/logging happened when they did not.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This finding reflects a material mismatch between the declared purpose and the actual behavior surface, especially around real Cardano interaction, OCR, immutable logging, and wallet/payment operations. In a warranty-verification and payment context, misleading descriptions can cause operators to expose receipts, trust nonexistent audit trails, or assume charges/logging happened when they did not.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description invites broad use for warranty claims, product verification, service payments, and audit trails without defining constraints, preconditions, or safe invocation boundaries. Overly broad invocation guidance increases the chance that an agent will trigger the skill in inappropriate contexts involving payments, sensitive purchase data, or irreversible recordkeeping.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The markdown promotes blockchain logging and smart wallet charging but does not warn users that these actions may create irreversible public records or trigger financial impact. In this context, receipt data and proof-of-purchase metadata may be sensitive, and users need clear notice before any on-chain publication or payment processing is attempted.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow explicitly includes logging to a Cardano transaction and charging a fee via smart wallet, yet provides no user-facing warning or consent checkpoint. Because these actions are potentially irreversible and financial, omitting disclosure materially increases the risk of unintended payments, privacy harm, and unauthorized publication of purchase-related metadata.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The code claims to log proof-of-purchase data to Cardano, but it only fabricates a pseudo transaction hash locally with no blockchain interaction or persistence. In the stated skill context of immutable audit trails, warranty claims, and proof-of-purchase verification, this can cause users or agents to falsely believe an auditable, immutable record exists when it does not, undermining non-repudiation and enabling fraud or dispute abuse.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The script advertises an --image option and receipt scanning capability, but it never defines or processes image input. In a warranty-verification skill, this is a security-relevant integrity issue because operators or downstream agents may rely on nonexistent OCR/image handling and make trust decisions based on misleading functionality claims.

Static analysis

No suspicious patterns detected.