Back to skill

Security audit

Solana Swaps

Security checks for vulnerabilities and agentic risk

Overview

The skill is meant for Solana swaps, but its documented swap flow can execute using terms the user did not explicitly approve.

Review before installing. Only use this with a wallet you are prepared to trade from, and require the agent to build the swap from the exact quote you approved or show any refreshed quote and ask again before signing. Avoid running it on a shared machine unless the temporary-file handling is fixed, and do not proceed unless the missing signer script is supplied and reviewed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:82
Finding

User-approved swap quote is replaced without renewed confirmation

Content
View full analysis
"$QUOTE_FILE" ``` ### Technical Analysis The workflow displays an initial Jupiter quote and obtains user approval for its terms. After approval, however, it makes a second quote request and uses that new response to build the swap transaction. The second response can differ in route, expected output, price impact, or minimum received because of market movement, liquidity changes, or a changed API response. It is neither shown to the user nor subjected to renewed confirmation. Consequently, the object approved by the user is not necessarily the object used to construct the transaction. This is a time-of-check/time-of-use flaw in a financially consequential operation and contradicts the skill's stated guarante ...[truncated 1115 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:105
Finding

Predictable shared temporary files expose swap data to race and symlink attacks

Content
View full analysis
"$QUOTE_FILE" # Request swap transaction curl -s -X POST \ -H "x-api-key: $JUPITER_API_KEY" \ -H "Content-Type: application/json" \ "https://api.jup.ag/swap/v1/swap" \ -d "{ \"quoteResponse\": $(cat $QUOTE_FILE), \"userPublicKey\": \"${USER_PUBKEY}\", \"dynamicComputeUnitLimit\": true, \"prioritizationFeeLamports\": { \"priorityLevelWithMaxLamports\": { \"maxLamports\": 5000000, \"priorityLevel\": \"high\" } } }" > /tmp/jupiter_swap.json # Extract the swap transaction SWAP_TX=$(cat /tmp/jupiter_swap.json | jq -r '.swapTransaction') ``` ```bash node "$(dirname "$0")/scripts/jupiter-swap.mjs" \ --keypair "$SOLANA_KEYPAIR_PATH" \ --transaction "$SWAP_TX" ``` ### Technical Analysis The workflow stores security-sensitive quote and serialized transaction data under fixed names in the globally shared `/tmp` directory: - `/tmp/jupiter_quote.json` - `/tmp/jupiter_swap.json` Fixed paths permit another local process or user to predict the filenames. Depending on host permissions and operating-system protections, an attacker may pre-create a symbolic link at one of these paths or replace a file between its write and read operations. The quote file is read into the swap-construction request, while the swap response is read and passed as an opaque transaction to a command that is instructed to sign and submit it. Therefore, tampering with either file can affect transaction construction or the transaction presented to the signer. Redirection through a malicious symbolic link ...[truncated 1813 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

Get quote with API key authentication

curl -s -H "x-api-key: $JUPITER_API_KEY"
"https://api.jup.ag/swap/v1/quote?inputMint=${INPUT_MINT}&outputMint=${OUTPUT_MINT}&amount=${AMOUNT}&slippageBps=${SLIPPAGE_BPS}" | jq .

text

### Step 2: Display Quote and Request Confirmation

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

Get quote with API key authentication

curl -s -H "x-api-key: $JUPITER_API_KEY"
"https://api.jup.ag/swap/v1/quote?inputMint=${INPUT_MINT}&outputMint=${OUTPUT_MINT}&amount=${AMOUNT}&slippageBps=${SLIPPAGE_BPS}" | jq .

text

### Step 2: Display Quote and Request Confirmation

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

Get quote with API key authentication

curl -s -H "x-api-key: $JUPITER_API_KEY"
"https://api.jup.ag/swap/v1/quote?inputMint=${INPUT_MINT}&outputMint=${OUTPUT_MINT}&amount=${AMOUNT}&slippageBps=${SLIPPAGE_BPS}" | jq .

text

### Step 2: Display Quote and Request Confirmation

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
# Save quote response to file
QUOTE_FILE="/tmp/jupiter_quote.json"
curl -s -H "x-api-key: $JUPITER_API_KEY" \
  "https://api.jup.ag/swap/v1/quote?inputMint=${INPUT_MINT}&outputMint=${OUTPUT_MINT}&amount=${AMOUNT}&slippageBps=${SLIPPAGE_BPS}" > "$QUOTE_FILE"

# Request swap transaction

Static analysis

No suspicious patterns detected.