Back to skill

Security audit

Arbitrum Dapp Skill

Security checks for vulnerabilities and agentic risk

Overview

This is an on-topic Arbitrum development guide, but its install flow promotes mutable remote shell execution and opt-out install telemetry, so users should review it before installing.

Review the installer before running it. Prefer cloning a pinned tag or commit manually instead of using the curl-to-bash quick start, and avoid auto-updating the skill from a mutable main branch. Set ARBITRUM_SKILL_NO_ANALYTICS=1 if you do not want the installer to send the GoatCounter install-count request. For deployment examples, use throwaway local keys for devnodes, avoid putting real private keys directly on command lines, simulate before --broadcast, and treat Arbitrum One examples as real mainnet transactions that can spend funds and cannot be undone.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:41
Finding

Mutable Remote Installer Is Executed Directly by Bash

Content
View full analysis
# Installs to ~/.claude/skills/arbitrum-dapp
$ bash <(curl -s https://raw.githubusercontent.com/
  hummusonrails/arbitrum-dapp-skill/main/install.sh)
``` ### Technical Analysis The command retrieves `install.sh` from the mutable `main` branch of a personal GitHub repository and passes it directly to Bash through process substitution. It does not pin an immutable commit, verify a checksum or signature, or give the user an opportunity to inspect the downloaded content. Although the version of `install.sh` included in the audited artifact does not contain an overtly malicious payload, the command executes whatever content the remote repository serves at the time of installation. Consequently, the effective payload can change after this audit. The current installer also clones or updates content under `~/.claude/skills`, where it will subsequently be loaded by Claude Code: ```bash if [ -d "$SKILL_DIR" ]; then echo "Updating existing installation..." cd "$SKILL_DIR" git pull origin main else echo "Cloning skill..." git clone "$REPO_URL" "$SKILL_DIR" fi ``` Executing arbitrary remote shell code is not the minimum privilege necessary to install a documentation-based Skill. ### Attack Path 1. An attacker compromises the repository owner’s GitHub account, repository, release process, or `main` branch. 2. The attacker replaces `install.sh` with a malicious shell payload. 3. A user copies the documented one-line installation command. 4. `curl` retrieves the attacker-controlled version without integ ...[truncated 791 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
references/solidity-contracts.md:5
Finding

Foundry Installation Pipes an Unverified Remote Script into Bash

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:58
Finding

Installation Instructions Execute Unpinned Third-Party Packages

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
install.sh:23
Finding

Installer Embeds a Public Analytics Bearer Token and Sends Default Telemetry

Content
View full analysis
/dev/null 2>&1 || true fi ``` ### Technical Analysis The installer embeds a bearer token in a publicly distributed script. Any person who can read the repository can copy and reuse this credential. The comments state that the token can only record page views and cannot read analytics data, which limits its stated authority, but public bearer credentials cannot provide meaningful caller authentication. The installer also sends an outbound analytics request by default. Users must know about and set `ARBITRUM_SKILL_NO_ANALYTICS=1` before execution to opt out. An analytics request is not required to install the Skill and therefore exceeds the minimum network activity necessary for installation. The payload is fixed to a single `/install` hit and no source files, wallet keys, environment variables, or other project data are included in the request body. ### Attack Path 1. An attacker reads the bearer token from the public `install.sh`. 2. The attacker submits arbitrary or repeated compatible count requests to the GoatCounter endpoint using that token. 3. The analytics account receives fabricated installation even ...[truncated 686 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (27)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The prerequisites section recommends curl -L https://foundry.paradigm.xyz | bash && foundryup, which pipes a network-fetched script directly into a shell. This is dangerous because any compromise of the hosting endpoint, distribution path, or script contents results in immediate arbitrary code execution on the user's system, and README documentation materially increases the chance users will run it unquestioningly.

Content

Scanner excerpt · README.md (reported line 97)May include surrounding context.

md
- [Rust](https://rustup.rs/) 1.81+
- [cargo-stylus](https://github.com/OffchainLabs/stylus-sdk-rs): `cargo install --force cargo-stylus`
- [Foundry](https://book.getfoundry.sh/getting-started/installation): `curl -L https://foundry.paradigm.xyz | bash && foundryup`
- [Docker](https://www.docker.com/products/docker-desktop/) for the local devnode
- [Node.js](https://nodejs.org/) 20+ and [pnpm](https://pnpm.io/)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents the skill as a development guide for building Arbitrum dApps. The supplied code chunk does not implement that guidance; instead, it installs or updates the skill locally by cloning from GitHub. Additionally, it performs an undeclared outbound analytics call to GoatCounter. While cloning the skill repo is a supporting installation behavior, the telemetry and the fact that this code's primary function is installation/update rather than Arbitrum dApp guidance mean the chunk does not accurately match the declared purpose.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · docs/index.html (reported line 9)May include surrounding context.

html
<title>Arbitrum dApp Skill — Claude Code Skill for Building on Arbitrum</title>
  <meta name="description" content="A Claude Code skill for building dApps on Arbitrum with Stylus Rust and Solidity. Scaffold, test, deploy, and integrate with viem.">
  <link rel="icon" type="image/svg+xml" href="assets/arbitrum-logomark.svg">
  <!-- Privacy-friendly analytics: no cookies, no personal data. See https://goatcounter.com -->
  <script data-goatcounter="https://arbitrum-dapp-skill.goatcounter.com/count"
          async src="//gc.zgo.at/count.js"></script>
  <link rel="preconnect" href="https://fonts.googleapis.com">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · docs/index.html (reported line 644)May include surrounding context.

html
</div>
  </nav>

  <!-- HERO -->
  <section class="hero">
    <div class="hero-glow"></div>
    <div class="container">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · docs/index.html (reported line 676)May include surrounding context.

html
</div>
          <div class="hero-feature">
            <div class="hero-feature-icon">
              <!-- LayoutDashboard icon -->
              <svg viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect width="7" height="9" x="3" y="3" rx="1"/><rect width="7" height="5" x="14" y="3" rx="1"/><rect width="7" height="9" x="14" y="12" rx="1"/><rect width="7" height="5" x="3" y="16" rx="1"/></svg>
            </div>
            <div class="hero-feature-text">

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deployment.md (reported line 14)May include surrounding context.

Environment Setup

bash
# .env (never commit this file)
PRIVATE_KEY=0x...
ARBITRUM_SEPOLIA_RPC_URL=https://sepolia-rollup.arbitrum.io/rpc
ARBITRUM_ONE_RPC_URL=https://arb1.arbitrum.io/rpc

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The guide instructs users to execute a remote script directly with curl ... | bash, which runs code fetched over the network without prior inspection or integrity verification. If the upstream host, transport path, or installation script is compromised, users could execute arbitrary commands on their machine, making this a strong supply-chain risk.

Content

Scanner excerpt · references/solidity-contracts.md (reported line 5)May include surrounding context.

md
## Prerequisites

- Foundry: `curl -L https://foundry.paradigm.xyz | bash && foundryup`
- Solidity 0.8.x (managed by Foundry)

## Project Setup

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation includes a raw private key directly in deploy and transaction commands, which normalizes unsafe secret handling and creates a high risk that users will reuse the key pattern, accidentally expose real credentials in shell history, logs, screenshots, or copied scripts. Even if intended for a local devnode, the file provides no warning that the key is only for ephemeral local testing, so users may misapply it to non-local environments or train insecure operational habits.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

md
This skill gives Claude Code deep knowledge of the Arbitrum development stack so it can help you:

- **Scaffold** a monorepo with Stylus Rust contracts, Solidity contracts, and a React frontend
- **Write and test** smart contracts using the Stylus Rust SDK or Foundry
- **Run** a local Arbitrum devnode for development
- **Build** frontend interfaces with viem and wagmi
- **Deploy** contracts to Arbitrum Sepolia and Arbitrum One

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The quick start instructs users to run bash <(curl -s https://raw.githubusercontent.com/.../install.sh), which downloads and immediately executes remote code with no review step or warning. In a developer tooling skill, this is especially risky because users are primed to trust setup commands, so a compromised repo, MITM in weaker environments, or malicious update could lead to arbitrary code execution on the developer machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README recommends npx clawhub@latest install arbitrum-dapp-skill, which executes code fetched at install time without pinning to a specific version or integrity value. That creates a supply-chain risk: if the package is compromised or a breaking/malicious release is published, users may execute unexpected code during installation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill includes shell commands and operational setup steps but does not declare any tool scope or allowed tools. In an agent environment, this creates an authorization gap where the agent may execute shell actions without explicit user-visible constraints, increasing the risk of unintended command execution.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · docs/index.html (reported line 671)May include surrounding context.

html
</div>
            <div class="hero-feature-text">
              <h4>Stylus Rust + Solidity</h4>
              <p>Write contracts in Rust or Solidity. Full interop.</p>
            </div>
          </div>
          <div class="hero-feature">

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · docs/index.html (reported line 816)May include surrounding context.

html
<!-- ONE-LINER -->
              <div class="terminal-panel active" id="tab-one-liner">
                <code>
                  <span class="comment"># Installs to ~/.claude/skills/arbitrum-dapp</span><br>
                  <span class="prompt">$ </span>bash &lt;(curl -s https://raw.githubusercontent.com/<br>&nbsp;&nbsp;hummusonrails/arbitrum-dapp-skill/main/install.sh)<br>
                  <br>
                  <span class="comment"># Then start Claude Code</span><br>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The quick-start prominently recommends executing a remote script via bash <(curl -s ...) without any warning, review step, or integrity verification. This pattern trains users to run unaudited code directly from the network, so a repo compromise, DNS issue, or upstream account takeover could immediately translate into arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install.sh (reported line 11)May include surrounding context.

sh
echo "Installing $SKILL_NAME skill for Claude Code..."

# Create skills directory if it doesn't exist
mkdir -p "$HOME/.claude/skills"

# Clone or update
if [ -d "$SKILL_DIR" ]; then

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installer makes an outbound analytics request during installation that is unrelated to the core function of installing the skill. Even if the payload is minimal and documented in comments, undisclosed install-time network activity creates a privacy and trust risk because users may not expect telemetry from a local installer and the behavior is not part of the skill's stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Install-time telemetry is not necessary to clone or update the skill, so it expands the script's capabilities beyond its declared purpose. That mismatch is security-relevant because unnecessary network behavior increases attack surface, weakens user consent, and normalizes hidden side effects in installer scripts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The script performs an external POST request to a third-party analytics endpoint and includes an authorization bearer token. Any installer that transmits data off-host introduces privacy risk and a supply-chain trust concern, especially when the network call is not essential to installation and may occur silently by default.

Content

Scanner excerpt · install.sh (reported line 29)May include surrounding context.

sh
# See: https://www.goatcounter.com
# To opt out: set ARBITRUM_SKILL_NO_ANALYTICS=1 before running this script.
if [ -z "${ARBITRUM_SKILL_NO_ANALYTICS:-}" ]; then
  curl -s -X POST "https://arbitrum-dapp-skill.goatcounter.com/api/v0/count" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer s8p7jjjeclhc1gs76e5ry1zm4pgm5e1qlxz11uwr6zslbpr4h" \
    --data '{"no_sessions": true, "hits": [{"path": "/install"}]}' \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The mainnet cargo stylus deploy example instructs use of a private key against Arbitrum One without any explicit warning that it will submit a real transaction and spend real funds. In a deployment guide aimed at developers, omission of this warning increases the chance of accidental irreversible mainnet deployment, especially when users may copy-paste commands verbatim.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Forge mainnet example includes --broadcast, which will send signed transactions to mainnet, but the documentation does not clearly warn that this spends real funds and cannot be undone. Because CLI deployment guides are often followed by copy-paste, this creates a realistic risk of unintended live deployment or configuration mistakes causing financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file includes examples for writeContract that trigger on-chain state changes, but the surrounding documentation does not warn users that these actions can create real wallet prompts, spend gas, and cause irreversible state changes. Although the button text shows transaction status, it does not disclose the safety impact of initiating a write operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The troubleshooting instructions include docker compose down -v, which removes containers and associated volumes. In a markdown file, destructive operations that can affect local data or environment state should be accompanied by a clear warning, but the surrounding text does not explicitly disclose that this may delete persisted devnode data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The deployment examples include --broadcast against Sepolia and Arbitrum One and accept a live private key, but they do not explicitly warn that these commands submit real transactions and can spend funds from the keyed account. In a developer guide, this omission increases the chance of accidental mainnet execution or misuse by less experienced users, especially because the examples are copy-paste ready.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The deployment examples instruct users to pass a raw private key directly on the command line and include a live deploy command without any warning about secret exposure, shell history leakage, process-list visibility, or the irreversible nature of on-chain deployment. In a developer guide for Arbitrum dApps, readers are likely to copy-paste these commands, which makes accidental credential compromise or unintended mainnet deployment more plausible.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.generated_source_template_injection

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
install.sh:31

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/local-devnode.md:33

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
references/solidity-contracts.md:39