Back to skill

Security audit

Chainstream Data

Security checks for vulnerabilities and agentic risk

Overview

The skill is a blockchain analytics integration, but it also brings wallet setup, private-key import, unpinned command execution, persistent auth, and real crypto payment flows into a read-oriented skill.

Review before installing. Prefer API-key or preconfigured MCP access for read-only analytics. Do not import production private keys into the CLI, avoid running the Tempo `curl | bash` installer without independent verification, and require explicit confirmation before any wallet signing, subscription purchase, webhook change, or transaction-related action. Use a low-balance wallet if payment flows are needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
shared/authentication.md:204
Finding

Mutable Remote Installer Is Executed Directly Through Bash

Content
View full analysis
Remediation
View remediation
tempo-installer.sh" | sha256sum --check - ``` 5. Prefer signed release artifacts and verify the publisher's signature using a separately distributed trusted key. 6. Let the user inspect the downloaded file before executing it. 7. Execute installation with the least-privileged account and avoid granting administrator privileges. 8. Prefer installation through a package manager that supports version pinning, integrity metadata, and reproducible packages. 9. Keep optional payment-tool installation separate from the read-only analytics workflow. ]]>

T01 · Skill Instruction Hijacking

Error
Location
shared/authentication.md:201
Finding

Agent Behavior Is Delegated to Mutable External Skill Instructions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:89
Finding

Security-Sensitive CLI Is Downloaded and Executed Without Version Pinning

Content
View full analysis
# Option B: Create ChainStream Wallet (for DeFi + auto x402 payment) npx @chainstream-io/cli login # Option C: Import existing key (dev/testing) npx @chainstream-io/cli wallet set-raw --chain base # EVM (Base) key npx @chainstream-io/cli wallet set-raw --chain sol # Solana key ``` Other documented invocations use the same unpinned package for real payment authorization: ```bash npx @chainstream-io/cli plan purchase --plan --json ``` ### Technical Analysis The documentation repeatedly invokes `npx @chainstream-io/cli` without specifying an exact version or integrity digest. Depending on the local npm configuration and cache state, `npx` can download the currently published package and execute it immediately. This CLI is given unusually sensitive capabilities. The documented workflows entrust it with: - API-key configuration. - Creation and storage of wallet-related authentication state. - Import of raw EVM and Solana private keys. - SIWX message signing. - Wallet balance inspection. - EIP-3009 authorization for real USDC transfers. - Automatic storage of returned API keys. A compromised publisher account, malicious future release, dependency compromise, or registry-level attack could therefore execute attacker-controlled code in a context containing valuable credentials and signing authority. The issue is especially significant because importing private keys and authorizing payments exceed the minimum privileges necessary for the Skill's declared read-only analy ...[truncated 1421 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (173)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
# ChainStream Data

On-chain data intelligence for AI agents. Access token analytics, market trends, wallet profiling, and compliance screening across Solana, BSC, and Ethereum.

- **MCP Server**: `https://mcp.chainstream.io/mcp` (streamable-http, 17 tools)
- **CLI**: `npx @chainstream-io/cli`

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill embeds real-money subscription purchase flows involving USDC/x402/MPP even though its stated purpose is analytics. This broadens the blast radius from information retrieval to financial execution, creating risk of unauthorized purchases, phishing-like plan manipulation, or coercing users into payment flows unnecessarily.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill includes wallet creation and raw private-key import instructions despite being framed as an analytics tool. This creates unnecessary exposure of highly sensitive key material and enables the agent workflow to handle credentials that are unrelated to simple on-chain data analysis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Red packet create/claim/send operations are transactional capabilities unrelated to an analytics-focused skill and materially change the risk profile from read-only analysis to value-affecting actions. If an agent can invoke these endpoints, prompt injection or user confusion could lead to unauthorized transfers, claims, or social-engineering workflows using the skill under the guise of analytics.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The document recommends curl -fsSL https://tempo.xyz/install | bash, which downloads a remote script and pipes it directly into a shell without inspection, integrity verification, or version pinning. This is a classic arbitrary code execution pattern: if the site, CDN, TLS termination, or publisher is compromised, users immediately run attacker-controlled code in a wallet bootstrap context.

Content

Scanner excerpt · shared/authentication.md (reported line 207)May include surrounding context.

bash
# Set up Tempo Wallet (one-time — requires browser passkey auth)
curl -fsSL https://tempo.xyz/install | bash
tempo wallet login

# View plans (no auth required)

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash pattern explicitly chains network retrieval into immediate shell execution, removing any opportunity for review or validation. In this skill's authentication and wallet setup context, the danger is amplified because compromise could lead to credential theft, malicious wallet tooling installation, or persistent host compromise.

Content

Scanner excerpt · shared/authentication.md (reported line 207)May include surrounding context.

bash
# Set up Tempo Wallet (one-time — requires browser passkey auth)
curl -fsSL https://tempo.xyz/install | bash
tempo wallet login

# View plans (no auth required)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · shared/x402-payment.md (reported line 256)May include surrounding context.

md
| USDC on **Base** | x402 | CLI auto-handles, or `@x402/fetch` |
| USDC on **Solana** | x402 | CLI with `walletChain: "sol"` |
| USDC.e on **Tempo** | MPP | `tempo request .../mpp/purchase?plan=<PLAN>` |
| **No crypto wallet** | — | Get API Key from [Dashboard](https://app.chainstream.io) |

If unsure, ask the user which chain their wallet is on. If they say "Tempo" or "Stripe" → MPP. If they say "Base", "Solana", or "USDC" → x402.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The trigger for chainstream-data is extremely broad: terms like token info, price, holders, trends, wallet PnL, and 'any read-only on-chain query' overlap with many ordinary crypto-related prompts. In agent-routing systems, broad activation criteria can cause over-invocation of external tools, unnecessary data exposure, unintended network access, and reduced user-intent precision.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The chainstream-defi trigger covers swapping, bridging, token creation, trades, and 'any on-chain transaction' with little activation scoping. Because this skill is associated with financial execution, an overly broad trigger materially raises the risk of routing ambiguous user requests into transaction-capable flows, potentially leading to unintended or premature execution steps.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs execution through npx @chainstream-io/cli without pinning an exact package version, which means the agent may fetch and run whatever package version is current at execution time. In a security-sensitive environment, this creates a supply-chain risk: a compromised upstream release, typosquatted dependency path, or breaking behavior change could result in arbitrary code execution or unsafe workflow changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command again references the ChainStream CLI without a pinned version, but here it is used in an authentication and subscription-check flow. Because these steps may handle credentials, wallet creation, and billing-related interactions, executing an unpinned remote package increases the blast radius of a malicious or unexpected package update.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README initially says transaction execution belongs to chainstream-defi, but later mixes execution-oriented examples into the same general usage flow. This inconsistency can cause agents or users to misclassify capabilities, eroding guardrails around high-risk actions and enabling accidental escalation from data access to transaction execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The README instructs users to execute npx @chainstream-io/cli without pinning an exact package version. Because npx fetches the latest published package by default, a compromised upstream package, malicious update, or account takeover could cause users to run attacker-controlled code during install/execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The repository presents chainstream-data as a read/query skill, but the shared authentication instructions include wallet creation and raw private-key import. That scope mismatch is dangerous because users may grant or expose signing material in a context they reasonably believe is read-only, increasing the chance of credential overreach and accidental key disclosure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The usage examples shown in the context of the data skill include swap and job-status operations that are outside the stated analytics-only scope. This can mislead users or agent integrators into invoking execution-capable workflows under a supposedly read-oriented skill boundary, weakening least-privilege assumptions and making unintended on-chain actions more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The swap example describes a state-changing on-chain action without any explicit warning that blockchain transactions are irreversible and may spend user funds. In an AI-skill context, omission of that warning increases the risk that users or agents trigger real financial actions without informed consent or adequate confirmation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This CLI example uses npx @chainstream-io/cli without a pinned version, which means users may execute whatever package version is current at invocation time. In a tool that handles authentication and wallet-related operations, this increases supply-chain risk because any malicious or compromised release could immediately affect end users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The documentation tells users to run an unpinned package through npx, which introduces a classic remote package execution risk. If the npm package or publisher is compromised, users following the README could unknowingly run malicious code in their environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This example relies on npx fetching the latest CLI package at runtime, which is unsafe for a package that interfaces with wallets, APIs, and potentially sensitive user data. The lack of version pinning exposes users to supply-chain compromise through package tampering or malicious updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Running npx @chainstream-io/cli without pinning creates a non-deterministic execution path and exposes readers to npm supply-chain attacks. Because this project operates in the crypto/on-chain domain, compromise could lead to credential theft, wallet misuse, or deceptive analytics output.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This command example executes a remote npm package without fixing the version, so the behavior can change over time or be hijacked by a malicious release. Since users may run these commands in trusted shells with access to credentials, the resulting impact can extend beyond simple command failure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The GraphQL CLI example is also invoked through unpinned npx, which carries the same supply-chain execution risk as the other examples. Users following the README could execute a compromised package version with immediate access to their environment and configured secrets.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation description is broad and overlaps with many common crypto-analysis requests, making the skill likely to trigger in situations beyond narrow intended scope. Over-broad activation becomes dangerous here because the skill contains payment, wallet, and transactional instructions, so accidental invocation could expose users to higher-risk workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill repeatedly instructs the agent to execute npx @chainstream-io/cli without pinning an exact package version. npx will fetch the latest published package at runtime, so a compromised publisher account, typosquat, or malicious update could cause arbitrary code execution in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This line directs use of an unpinned npx package, which creates a supply-chain execution risk. Because the skill is meant to be followed by an autonomous agent, the package may be downloaded and run automatically with no human verification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.