T09 · Insecure Skill Coding Practices
- Location
SKILL.md:59- Finding
Misleading Guidance About Resource Consumption by Failed TRON Transactions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13 and 59
Vulnerability Type: Insecure and financially unsafe transaction guidance
Risk Level: MediumAffected content:
markdown - Transactions fail without sufficient resources — no partial executionmarkdown - Failed transactions don't consume resources — unlike Ethereum gasTechnical Analysis
The unconditional statement that failed TRON transactions do not consume resources is inaccurate. A failed or reverted smart-contract transaction can consume bandwidth and energy for work performed before failure. Depending on the account's available resources and transaction configuration, the corresponding cost may be paid by burning TRX.
Atomic rollback of contract state does not imply that transaction execution is free. The statement at line 13 may reinforce this misunderstanding by discussing failure without distinguishing reverted state changes from resource accounting.
Because the skill provides financial transaction guidance, an agent relying on these instructions may incorrectly assure users that failed TRC-20 transfers or decentralized-application interactions have no resource or monetary cost.
Attack Path
- A user asks the agent for guidance about a TRC-20 transfer or smart-contract interaction.
- The agent loads
SKILL.mdand relies on the claim that failed transactions consume no resources. - The user submits a transaction that reverts, runs out of energy, or otherwise fails during contract execution.
- Bandwidth or energy is consumed, and TRX may be burned when the account lacks sufficient allocated resources.
- Based on the incorrect assurance, the user may retry the transaction repeatedly and incur additional costs.
This is primarily a transaction-safety failure rather than a privilege-escalation vulnerability. It does not provide an attacker with system privileges, wallet credentials, or direct account a ...[truncated 715 chars]
- Remediation
View remediation
Remediation Suggestions
Replace the unconditional claims with technically accurate guidance that distinguishes state rollback from resource charging. For example:
markdown - Transactions can fail when resources or fee limits are insufficient. Contract state changes normally revert, but bandwidth and energy consumed during execution may still be charged. - Failed smart-contract transactions may consume bandwidth and energy, and TRX may be burned when allocated resources are insufficient. Review the execution result and resource usage before retrying.Additional hardening measures:
- Clearly distinguish simple TRX transfers from smart-contract and TRC-20 transactions.
- Avoid absolute statements about fees or resource consumption because behavior can depend on transaction type, failure mode, fee limits, and current network rules.
- Advise users to estimate energy, inspect available resources, and configure an appropriate fee limit before signing.
- Warn users not to retry a failed transaction until they have reviewed its receipt, contract error, and recorded resource consumption.
- Periodically validate numerical and behavioral claims against current official TRON documentation.
