T09 · Insecure Skill Coding Practices
- Location
src/swap.ts:181- Finding
Opaque Raydium Transaction Is Signed Without Intent Validation
- Content
View full analysis
} if (!swapData.success) throw new Error(`Raydium tx build failed: ${swapData.msg ?? "unknown error"}`) if (!swapData.data?.length) throw new Error(`Raydium tx build returned no transactions`) const txBuf = Buffer.from(swapData.data[0].transaction, "base64") const transaction = VersionedTransaction.deserialize(txBuf) transaction.sign([keypair]) const signedBase64 = Buffer.from(transaction.serialize()).toString("base64") await simulateTx(rpc, signedBase64) const signature = await sendRawTx(rpc, signedBase64) ``` ### Technical Analysis The Raydium endpoint constructs and returns an opaque serialized Solana transaction. The Skill deserializes that transaction and signs it with the wallet keypair without inspecting its instructions or verifying that it implements the requested swap. The implementation does not validate: - Invoked program IDs against an allowlist. - The transaction fee payer. - Signer and writable-account privileges. - Source and destination token accounts. - Token mints and transferred quantities. - Maximum input and minimum output amounts. - Unexpected SOL or SPL token tra ...[truncated 1413 chars]- Remediation
View remediation
