Back to skill

Security audit

Freysa Security

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed paid crypto-security API skill, but it also bundles CAPTCHA solving, arbitrary web fetching, broad AI endpoints, and optional wallet-key payment access that users should review carefully.

Install only if you intentionally want a paid external service with broad crypto, web, AI, and CAPTCHA capabilities. Use a tightly limited payment wallet, avoid storing a high-value private key in FREYSA_WALLET_KEY, set external budget and approval controls, and treat fetched web content and AI outputs as untrusted advisory data.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a narrowly scoped on-chain security intelligence tool, but its documented capabilities include unrelated general-purpose functions like web scraping and AI reasoning/research. That scope expansion increases the chance an agent will grant the skill broader trust or permissions than warranted, enabling misuse outside the advertised security context.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The `/api/fetch` endpoint allows fetching arbitrary URLs as structured markdown, which materially broadens the skill from security analysis into unrestricted remote content retrieval. In an agent setting, this can be abused for prompt injection delivery, data exfiltration workflows, or access to untrusted content under the guise of a trusted security tool.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
General-purpose endpoints for reasoning, research, and synthesis are broader than the skill's declared security purpose and can turn a specialized tool into a de facto general agent coprocessor. That mismatch can cause downstream systems to overtrust outputs, route sensitive tasks through the skill, or bypass governance that would apply to broader AI capabilities.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
Exposing CAPTCHA-solving as a marketed capability without misuse warnings is dangerous because CAPTCHA bypass is commonly used to evade anti-abuse controls, automate account creation, and defeat access restrictions. In the context of an autonomous-agent skill, this creates a direct abuse-enabling primitive that is unrelated to the core security-analysis purpose.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.