Back to skill

Security audit

sol-deploy-engineer

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly coherent Solana deployment skill, but it gives agents high-impact setup and deployment guidance with unsafe installer patterns and under-specified handling of RPC credentials.

Review this skill before installing if it will run on a machine with wallets, RPC provider keys, or production deployment authority. Prefer pinned and verified tool installers, require explicit approval before replacing global tools or touching mainnet, and redact full RPC URLs or any API-bearing endpoint before writing reports or memory files.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:144
Finding

Mutable Remote Installer Is Downloaded and Executed Directly

Content
View full analysis
Remediation
View remediation
//" printf '%s %s\n' '' /tmp/agave-release.tar.bz2 | sha256sum --check - # Inspect and install only after successful verification and explicit approval. ``` ]]>

T08 · Insecure Dependencies

Error
Location
SKILL.md:145
Finding

AVM Installation Uses an Unpinned Git Revision and Unlocked Dependencies

Content
View full analysis
&& avm use ` ``` ```sh cargo install --git https://github.com/coral-xyz/anchor avm --force ``` ### Technical Analysis The installation command retrieves source from the current state of a remote Git repository without specifying a reviewed commit through `--rev`. It also omits `--locked`, allowing dependency resolution to differ across installations. As a result, future Skill invocations may compile source code or transitive dependencies that differ from those present at audit time. Cargo builds can execute dependency build scripts and procedural macros during compilation, so compromise does not require the resulting AVM binary to be launched before attacker-controlled code can run. The `--force` option additionally replaces an existing installation even when replacement has not been shown to be necessary. This increases the effect of an upstream compromise and weakens rollback and reproducibility. ### Attack Path 1. An attacker compromises the upstream Anchor repository, a maintainer account, or a dependency selected during Cargo resolution. 2. Malicious source, a build script, or a procedural macro is introduced into the revision or dependency graph retrieved by the command. 3. The Skill is invoked on a system that needs AVM installation or reinstallation. 4. Cargo retrieves the current remote repository revision and resolves dependencies without a locked dependency graph. 5. Attacker-controlled compilation-time code executes with the Agent user's privileges, or a compromised AVM binary is produced. 6. Because `--force` is specified, the compromised binar ...[truncated 925 chars]
Remediation
View remediation
\ --locked \ avm ``` 2. Record the expected commit SHA and AVM version in the Skill and version-decision log. 3. Verify that the pinned commit belongs to the expected signed release or reviewed tag. 4. Prefer a cryptographically signed release artifact with a published checksum when the upstream project provides one. 5. Review Cargo dependencies and build scripts associated with the pinned revision. 6. Avoid `--force` by default. Use it only after verifying the existing binary and obtaining explicit approval to replace it. 7. Install into a controlled user-scoped location and verify the final binary path so a stale or malicious binary cannot shadow it. 8. Record a digest of the installed executable and verify it before production deployment workflows. 9. Update pinned revisions through an explicit review process rather than automatically following the repository's default branch. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
templates/deploy-report.template.md:3
Finding

Deployment Records Can Persist Credential-Bearing RPC URLs

Content
View full analysis
-/` or commit to an ops repo. ``` ```md ## Network - RPC used (deploy): - RPC used (verification): - Provider (Helius / QuickNode / Triton / Alchemy / other): ``` The persistent deployment history also requests the RPC value: ```md - **RPC:** ``` The primary Skill instructs the Agent to record: ```md - RPC used ``` ### Technical Analysis Dedicated RPC provider URLs frequently contain API credentials in URL paths, query parameters, user-information components, or endpoint-specific tokens. The report template asks for the RPC used and explicitly allows the completed report to be committed to an operations repository. The deployment-history template similarly persists an unrestricted RPC value across sessions. The Skill contains general guidance not to store raw secrets, but the affected fields do not instruct the Agent to record only a redacted hostname or provider identifier. An Agent following the template literally may copy a complete configured endpoint into a release report or memory file. This is not evidence of intentional exfiltration. It is an insecure data-handling pattern that can disclose credentials when an RPC provider URL embeds a secret. ### Attack Path 1. An operator configures a dedicated RPC endpoint containing an API key, for example in its path or query string. 2. The Agent performs a deployment and is instructed to record the RPC used. 3. The full credential-bearing URL is copied into the deployment report or `memory/deploy-history.md`. 4. The report is saved in a release archive, committed to an operations repo ...[truncated 1066 chars]
Remediation
View remediation
``` 4. Record only the provider name, cluster, hostname, and a non-secret internal endpoint alias where operational traceability is required. 5. Prohibit committing reports that contain complete RPC URLs unless an automated sanitizer has verified that the URL contains no credentials. 6. Run secret scanning against deployment reports, memory files, release archives, and staged Git changes. 7. Store sensitive endpoint configuration in an approved secret manager and reference it by secret name rather than value. 8. Define rotation procedures for any RPC credential accidentally written to history. 9. If a credential has already been committed, revoke and rotate it, remove it from current files, and purge it from repository history and release archives where feasible. 10. Apply equivalent redaction to command logs and error messages, since CLI output may repeat configured URLs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The skill instructs use of shell-piped remote installers and forceful tool installation commands (sh -c "$(curl ...)" and cargo install --git ... --force). Even though the operational intent is legitimate, this pattern is dangerous because it normalizes execution of network-fetched code without an integrity check, version pinning, or provenance verification; a compromised endpoint, MITM, or repo supply-chain event could lead to arbitrary code execution on the developer machine.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
Install or configure as needed:

- **Rust** via `rustup` — use the repo's MSRV if pinned; otherwise latest stable. For `cargo-build-sbf` issues, sometimes pinning to a known-good stable (e.g. `1.75.x`–`1.79.x`) resolves edge cases depending on the Anchor/Solana pair.
- **Solana CLI (Agave)** via `sh -c "$(curl -sSfL https://release.anza.xyz/stable/install)"` — or pin to a specific version that matches the Anchor version the repo expects.
- **AVM + Anchor** — `cargo install --git https://github.com/coral-xyz/anchor avm --force`, then `avm install <repo_pinned_version>` and `avm use <repo_pinned_version>`. Never install Anchor directly with `cargo install anchor-cli` on a dev machine that works on multiple projects.
- **Node.js LTS** via `nvm` / `fnm` / `volta`.
- **pnpm** — prefer corepack (`corepack enable && corepack prepare pnpm@<version> --activate`) so the version matches `packageManager` in `package.json`.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 422)May include surrounding context.

md
- deploys to mainnet casually through public RPC
- assumes dependencies are installed
- runs `anchor build` without checking program-ID consistency
- overwrites config without inspection
- exposes sensitive key material
- mixes package managers

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.