Back to skill

Security audit

Solana + Polymarket + X Wallet Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent with its stated wallet, trading, and X/Twitter automation purpose, but it asks for high-impact financial and social-media authority with several under-enforced safety controls.

Install only if you are comfortable giving this skill control over funded wallets and an X/Twitter account. Start with empty or low-balance wallets, keep all strategies in dry-run first, avoid using the setup script in logged terminals or CI, verify any custom RPC and wallet storage paths, and do not enable live swaps, transfers, Polymarket orders, or auto-posting unless you can tolerate irreversible financial or public-account impact.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
src/swap.ts:181
Finding

Opaque Raydium Transaction Is Signed Without Intent Validation

Content
View full analysis
} if (!swapData.success) throw new Error(`Raydium tx build failed: ${swapData.msg ?? "unknown error"}`) if (!swapData.data?.length) throw new Error(`Raydium tx build returned no transactions`) const txBuf = Buffer.from(swapData.data[0].transaction, "base64") const transaction = VersionedTransaction.deserialize(txBuf) transaction.sign([keypair]) const signedBase64 = Buffer.from(transaction.serialize()).toString("base64") await simulateTx(rpc, signedBase64) const signature = await sendRawTx(rpc, signedBase64) ``` ### Technical Analysis The Raydium endpoint constructs and returns an opaque serialized Solana transaction. The Skill deserializes that transaction and signs it with the wallet keypair without inspecting its instructions or verifying that it implements the requested swap. The implementation does not validate: - Invoked program IDs against an allowlist. - The transaction fee payer. - Signer and writable-account privileges. - Source and destination token accounts. - Token mints and transferred quantities. - Maximum input and minimum output amounts. - Unexpected SOL or SPL token tra ...[truncated 1413 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup-master-key.ts:11
Finding

Master Encryption Password Is Printed and Recommended in a Shell Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/plugin.ts:173
Finding

Live Financial Actions Do Not Enforce Independent User Confirmation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
bin/solana-wallet.ts:353
Finding

Scanner Stop Fallback Can Terminate Unrelated Processes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:52
Finding

Undocumented Environment Variables Control Wallet Storage and Polygon RPC Destinations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/db.ts:13
Finding

Encrypted Wallet Stores Are Written Without Explicit Owner-Only Permissions

Content
View full analysis
=> { await writeFile(WALLET_STORE_PATH, JSON.stringify(store, null, 2), "utf-8") } ``` EVM wallet storage: ```ts const writeEvmStore = async (store: EvmWalletStore): Promise => { await writeFile(EVM_WALLET_STORE_PATH, JSON.stringify(store, null, 2), "utf-8") } ``` ### Technical Analysis Both wallet stores contain encrypted private keys and PBKDF2 salts, but files are created without an explicit `0600` mode. Their effective permissions therefore depend on the process umask and pre-existing file permissions. The implementation also does not explicitly demonstrate: - Owner-only permissions for the parent data directory. - Permission correction for an existing broadly readable file. - Symlink-resistant file creation. - Atomic replacement for wallet-store updates. Encryption reduces the immediate impact of local file disclosure. Nevertheless, copied ciphertext remains valuable because later compromise of the root encryption password permits offline wallet decryption. ### Attack Path 1. The Skill runs under a permissive umask or writes to a pre-existing file with broad permissions. 2. Another local user or process reads and copies `wallets.json` or `evm-wallets.json`. 3. The attacker later obtains `MASTER_ENCRYPTION_PASSWORD_CRYPTO`, `MASTER_ENCRYPTED`, and `MASTER_SALT`. 4. The attacker decrypts the master key and then decrypts the copied private-key records. 5. The recovered private keys are used independently of the original system. ### Impact Assessment The initial exposure is limited to encrypted wallet records and associated metadata. Combined with compromise of the root password and master-key material, it can ...[truncated 72 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (88)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The short description says 'post to X/Twitter' but the documented behavior is broader and more autonomous: mention monitoring, keyword polling, and auto-reply loops. Autonomous social actions can create reputational, spam, and abuse risk beyond simple one-off posting, so under-describing this scope is materially risky.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
These 13 tools are registered by [`src/plugin.ts`](https://github.com/inspi-writer001/raphael-solana/blob/main/src/plugin.ts), bundled in this skill package at

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
| `PUMPPORTAL_WS` | `wss://pumpportal.fun/api/data` | pump.fun WebSocket (public, no key needed) | pump.fun scanner |
| `X_API_KEY` | — | OAuth 1.0a consumer key | X writes (tweets, replies) |
| `X_API_SECRET` | — | OAuth 1.0a consumer secret | X writes |
| `X_ACCESS_TOKEN` | — | OAuth 1.0a user access token | X writes |
| `X_ACCESS_TOKEN_SECRET` | — | OAuth 1.0a user access token secret | X writes |
| `X_BEARER_TOKEN` | — | OAuth 2.0 app-only bearer token | X reads (search, timelines) |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
| `PUMPPORTAL_WS` | `wss://pumpportal.fun/api/data` | pump.fun WebSocket (public, no key needed) | pump.fun scanner |
| `X_API_KEY` | — | OAuth 1.0a consumer key | X writes (tweets, replies) |
| `X_API_SECRET` | — | OAuth 1.0a consumer secret | X writes |
| `X_ACCESS_TOKEN` | — | OAuth 1.0a user access token | X writes |
| `X_ACCESS_TOKEN_SECRET` | — | OAuth 1.0a user access token secret | X writes |
| `X_BEARER_TOKEN` | — | OAuth 2.0 app-only bearer token | X reads (search, timelines) |

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · bin/solana-wallet.ts (reported line 182)May include surrounding context.

ts
// --- X / Twitter ---
  if (cmd === "x") {
    const xConfig: XConfig = {
      apiKey:            process.env["X_API_KEY"]             ?? "",
      apiSecret:         process.env["X_API_SECRET"]          ?? "",
      accessToken:       process.env["X_ACCESS_TOKEN"]        ?? "",
      accessTokenSecret: process.env["X_ACCESS_TOKEN_SECRET"] ?? "",

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · bin/solana-wallet.ts (reported line 280)May include surrounding context.

ts
// --- X / Twitter ---
  if (cmd === "x") {
    const xConfig: XConfig = {
      apiKey:            process.env["X_API_KEY"]             ?? "",
      apiSecret:         process.env["X_API_SECRET"]          ?? "",
      accessToken:       process.env["X_ACCESS_TOKEN"]        ?? "",
      accessTokenSecret: process.env["X_ACCESS_TOKEN_SECRET"] ?? "",

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · bin/solana-wallet.ts (reported line 183)May include surrounding context.

ts
if (cmd === "x") {
    const xConfig: XConfig = {
      apiKey:            process.env["X_API_KEY"]             ?? "",
      apiSecret:         process.env["X_API_SECRET"]          ?? "",
      accessToken:       process.env["X_ACCESS_TOKEN"]        ?? "",
      accessTokenSecret: process.env["X_ACCESS_TOKEN_SECRET"] ?? "",
      bearerToken:       process.env["X_BEARER_TOKEN"]        ?? "",

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · bin/solana-wallet.ts (reported line 281)May include surrounding context.

ts
if (cmd === "x") {
    const xConfig: XConfig = {
      apiKey:            process.env["X_API_KEY"]             ?? "",
      apiSecret:         process.env["X_API_SECRET"]          ?? "",
      accessToken:       process.env["X_ACCESS_TOKEN"]        ?? "",
      accessTokenSecret: process.env["X_ACCESS_TOKEN_SECRET"] ?? "",
      bearerToken:       process.env["X_BEARER_TOKEN"]        ?? "",

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
bin/solana-wallet.ts:333

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/polymarketClob.ts:12

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/xClient.ts:26