Back to skill

Security audit

Goldrush Streaming API

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for using GoldRush real-time blockchain streams, with ordinary API-key and SDK-install cautions but no hidden or destructive behavior.

Installers should treat this as API integration documentation: use a dedicated GoldRush API key, avoid hardcoding secrets, pin SDK versions with a lockfile, and be careful that wallet activity monitoring can expose sensitive behavioral information about real people or organizations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:48
Finding

Unpinned npm Dependency Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:48
  • references/overview.md:140-150
  • references/overview.md:401-404
  • references/sdk-guide.md:3-6

Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:48:

markdown
**Install:** `npm install @covalenthq/client-sdk`

references/overview.md:140-150:

markdown
The recommended approach is to use the official [TypeScript Client SDK](https://www.npmjs.com/package/@covalenthq/client-sdk) which supports the Streaming API and manages all WebSocket connections.

```bash npm
npm install @covalenthq/client-sdk
bash
yarn add @covalenthq/client-sdk
text

`references/overview.md:401-404`:

```markdown
The recommended approach is to use the official [GoldRush TypeScript Client SDK](https://www.npmjs.com/package/@covalenthq/client-sdk) which handles authentication automatically and provides a simplified interface for managing stream subscriptions.

```bash
npm install @covalenthq/client-sdk
text

`references/sdk-guide.md:3-6`:

```markdown
With the official [TypeScript Client SDK](https://www.npmjs.com/package/@covalenthq/client-sdk), developers can access the Streaming API and leverage the following advanced features described in this guide.

```bash
npm install @covalenthq/client-sdk
text

### Technical Analysis

The documented installation commands do not specify an exact dependency version or integrity constraint. Consequently, users following the instructions receive whichever package release currently satisfies npm's default resolution behavior rather than the release reviewed when this Skill was audited.

npm packages can define lifecycle scripts that execute during installation. The installed library will also execute with application privileges when imported at runtime. If the publisher account, registry distribution path, pac
...[truncated 1798 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace floating installation commands with a reviewed exact version, for example:

    bash
    npm install --save-exact @covalenthq/client-sdk@X.Y.Z
    

    The placeholder must be replaced with a specific version that has undergone review.

  2. Commit package-lock.json or the corresponding package-manager lockfile and use deterministic installation in CI:

    bash
    npm ci
    
  3. Review the selected package version, its transitive dependencies, provenance information, published integrity hashes, and lifecycle scripts before approving it.

  4. Where package lifecycle scripts are unnecessary, consider installing with:

    bash
    npm ci --ignore-scripts
    

    Confirm first that this does not prevent legitimate package setup.

  5. Configure automated dependency scanning and update review so version changes are introduced through explicit, auditable pull requests rather than silently resolved during installation.

  6. Run dependency installation and builds in an isolated, least-privileged environment without production credentials. Expose only the secrets required for the specific build stage.

  7. Apply the same exact-version guidance consistently in SKILL.md, references/overview.md, and references/sdk-guide.md.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description says to use this skill whenever the user needs a wide range of live feeds, monitoring, analytics, token discovery, or profitability analysis. Although domain-specific, the trigger scope is very broad and lacks negative examples or tighter constraints beyond a brief historical-data exclusion, which increases the chance of unintended invocation versus adjacent skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Wallet Activity stream enables monitoring of specific wallet addresses and returns detailed transaction, transfer, and contract interaction data, but the documentation does not warn users about the privacy, surveillance, and compliance implications of tracking wallet activity. In this skill's context—intended for trading bots, alerting, copy-trading, and automation—the omission makes misuse more likely because it normalizes high-fidelity monitoring without guardrails.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file describes using the service to stream wallet information for AI agents, which is user- or third-party data with privacy implications. The document presents the capability as a use case but does not include any warning or disclosure about handling potentially sensitive wallet activity data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown advertises live tracking of wallet transactions, token transfers, and smart contract interactions, which can affect privacy expectations and involve sensitive behavioral data. No accompanying warning explains appropriate consent, authorization, or responsible handling of streamed wallet activity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Python example contradicts the documented authentication contract by defining GOLDRUSH_API_KEY but sending init_payload={"apiKey": API_KEY} with an undefined variable and the wrong key name. In practice this causes authentication failure and can push developers to bypass, hardcode, or debug credential handling unsafely, especially in production integrations built from the sample.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The complete subscription query documents the field as decoded_details with typed fragment spreads and log fields as emitter_address/log_offset (L1224-L1315), while the example response instead uses decoded and emitter and omits log_offset. This is an active documentation contradiction about the actual response shape, which can mislead consumers about what the stream returns.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.