Back to skill

Security audit

stock-bloc

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but it tells an agent to authorize USDC payments from a wallet without clear approval, price validation, or spending-limit controls.

Install only if you are comfortable giving the agent wallet-based payment authority for Stock Bloc calls. Configure strict local limits, verify network/asset/destination/amount against the published price catalog, and require human approval before any USDC signature.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:9
Finding

Remote Payment Metadata Can Trigger Unbounded USDC Authorization

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 9–10
Vulnerability Type: Unvalidated remote payment authorization
Risk Level: High

Vulnerable snippet:

markdown
## Step 2: Pay per call with x402 (USDC on Base)
Priced endpoints return HTTP 402 with a PAYMENT-REQUIRED header (x402 v2, network eip155:8453, asset USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913). Sign the exact amount with your agent wallet (EIP-3009 transferWithAuthorization) and retry with the PAYMENT-SIGNATURE header. Coinbase CDP facilitator verifies and settles.

Technical Analysis

The instructions direct the agent to sign the exact payment amount supplied through a remote HTTP 402 payment challenge. The remote Stock Bloc service controls the PAYMENT-REQUIRED response, but the Skill does not require the agent to validate the requested amount against a trusted local price catalog, enforce a per-call or cumulative spending limit, or obtain explicit operator approval before signing.

This crosses a trust boundary from remotely supplied payment metadata into the user’s wallet authority. Although the documented catalog lists expected prices, the payment procedure does not make those values enforceable constraints. A compromised, malicious, or misconfigured endpoint could therefore return an inflated amount that the agent is instructed to authorize.

Attack Path

  1. The agent requests one of the documented priced Stock Bloc endpoints.
  2. The remote service returns HTTP 402 with attacker-controlled or incorrectly configured payment metadata.
  3. The payment challenge specifies an amount greater than the documented endpoint price.
  4. Following the Skill instructions, the agent signs an EIP-3009 transferWithAuthorization for the exact remotely requested amount without mandatory human confirmation or local price validation.
  5. The agent retries the request with the resulting PAYMENT-SIGNATURE.
  6. The facilitator verifies an ...[truncated 752 chars]
Remediation
View remediation

Remediation Suggestions

  • Require explicit operator approval before every payment signature, displaying the endpoint, network, asset, amount, and payment destination.
  • Validate the requested network and asset against strict local constants: Base (eip155:8453) and the expected USDC contract.
  • Maintain a trusted local endpoint-to-price allowlist and reject payment requests whose amount differs from the configured price.
  • Enforce configurable per-transaction, per-session, and cumulative daily spending limits.
  • Default to refusing payment when any required payment field is missing, malformed, unexpected, or inconsistent with the original request.
  • Bind each authorization to the intended request and prevent replay or reuse.
  • Provide a dry-run mode that reports the proposed payment without signing it.
  • Record approved payments in a local audit log while excluding private keys and reusable authorization material.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to install and execute a package via npx skills without pinning an exact version. This creates a supply-chain risk because future package updates or package compromise could cause consumers to run unexpected code at install/use time. In a skill intended for agents, this is more dangerous because automated systems may follow install instructions non-interactively and with broad environment access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description at L03 frames the skill around API key registration plus buying real-time market data, SB quant scores, SEC 13F whale filings, and research memos. However, the documented operations also include deep SEC 10-K/10-Q audit jobs, forecasts, strategy backtests, and earnings prep packs, which are materially broader financial-analysis capabilities not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.