Back to skill

Security audit

stablecoin-depeg-scanner

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malware-like, but it should be reviewed because it gives fast, prescriptive real-money trading guidance and can recommend buying with incomplete or inconsistent collateral evidence.

Install only if you want a high-risk trading decision aid, not a safety scanner. Treat any BUY or position-size output as untrusted until you independently verify collateral status, exploit type, team response, API freshness, and whether the matched DefiLlama protocol is actually the right asset. Be aware that it queries public market APIs and may answer in Chinese even when the user did not ask for that language.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/depeg_eval.py:209
Finding

Fail-Open Collateral Scoring Can Produce Unsafe BUY Recommendations

Content
View full analysis
0: tvl_drop_pct = (tvl_prev - tvl) / tvl_prev * 100 if tvl > 0 and tvl_drop_pct < 50: tvl_status = "INTACT" # Collateral largely intact elif tvl > 0 and tvl_drop_pct < 90: tvl_status = "PARTIAL" # Some collateral lost else: tvl_status = "DRAINED" # Collateral gone # Scoring score = 0 reasons = [] # Factor 1: Odds ratio (higher = better opportunity) if odds_ratio >= 8: score += 40 reasons.append(f"Extreme discount: {odds_ratio:.1f}x odds (+40)") elif odds_ratio >= 5: score += 35 reasons.append(f"Very high discount: {odds_ratio:.1f}x odds (+35)") elif odds_ratio >= 3: score += 25 reasons.append(f"High discount: {odds_ratio:.1f}x odds (+25)") elif odds_ratio >= 2: score += 15 reasons.append(f"Moderate discount: {odds_ratio:.1f}x odds (+15)") elif odds_ratio >= 1.5: score += 10 reasons.append(f"Small discount: {odds_ratio:.1f}x odds (+10)") else: score += 0 reasons.append(f"Minimal discount: {odds_ratio:.1f}x odds (+0)") # Factor 2: TVL status if tvl_status == "INTACT": score += 40 reasons.append(f"TVL intact (drop {tvl_drop_pct:.1f}%) (+40)") elif tvl_status == "PARTIAL": score += 20 reasons.append(f"TVL partially lost (drop {tvl_drop_pct:.1f}%) (+20)") elif tvl_status == "DRAINED": score -= 50 reasons.append(f"TVL drained (drop {tvl_drop_pct:.1f}%) (-50)") else: score += 10 reasons.append("TVL unknown, needs manual check (+10)") # Factor 3: Mark ...[truncated 3257 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/depeg_eval.py:429
Finding

Unvalidated Numeric Inputs Permit Crashes and Invalid Position Calculations

Content
View full analysis
str: """ Main entry point. Args: coin_input: CoinGecko ID or symbol (e.g., "resolv-usr" or "USR") peg: Target peg price (default 1.0 for USD stablecoins) capital: Total available capital in USD Returns: Formatted assessment report string """ # Resolve symbol to coingecko id coin_id = coin_input.lower() upper = coin_input.upper() if upper in SYMBOL_MAP: coin_id = SYMBOL_MAP[upper] print(f"[1/4] Fetching coin data for '{coin_id}'...", file=sys.stderr) coin_info = get_coin_info(coin_id) if not coin_info: return f"ERROR: Could not find coin '{coin_input}' on CoinGecko. Try using the CoinGecko ID (e.g., 'resolv-usr')." price = coin_info["current_price"] if price <= 0: return f"ERROR: Price for {coin_info['symbol']} is ${price}. Cannot assess." deviation = abs(price - peg) / peg * 100 ``` ```python parser = argparse.ArgumentParser(description="Stablecoin Depeg Evaluator") parser.add_argument("coin", help="CoinGecko ID or symbol (e.g., resolv-usr, USR, DAI)") parser.add_argument("--peg", type=float, default=1.0, help="Target peg price (default: 1.0)") parser.add_argument("--capital", type=float, default=5000.0, help="Total capital in USD (default: 5000)") args = parser.parse_args() report = evaluate(args.coin, args.peg, args.capital) ``` Position sizing later uses the unvalidated capital value: ```python position_usd = capital * assessment["position_pct"] / 100 potential_profit = position_usd * (assessment["odds_ratio"] - 1) ``` ### Technical Analysis The CLI parser converts `--peg` and `--capital` to floating-point values but does not enforce valid ranges or finit ...[truncated 1737 chars]
Remediation
View remediation
None: if not math.isfinite(peg) or peg <= 0: raise ValueError("Peg must be a finite number greater than zero") if not math.isfinite(capital) or capital < 0: raise ValueError("Capital must be a finite, non-negative number") ``` 2. Invoke validation at the start of `evaluate`, ensuring that both CLI and programmatic callers are protected. 3. Add custom `argparse` validators so invalid values are rejected with a clear usage error. 4. Consider reasonable upper limits for peg and capital values to catch accidental or abusive inputs. 5. Catch expected validation exceptions in `main` and return a nonzero exit status without a traceback. 6. Add tests covering zero, negative, NaN, positive infinity, negative infinity, extremely large values, and valid boundary values. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/depeg_eval.py (reported line 25)May include surrounding context.

python
# ============================================================
# Config
# ============================================================
COINGECKO_BASE = "https://api.coingecko.com/api/v3"
DEFILLAMA_BASE = "https://api.llama.fi"

# Common stablecoin mappings (symbol -> coingecko id)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script produces explicit trading recommendations such as BUY/WATCH/AVOID, suggested position sizing, profit targets, and execution steps for real-money crisis arbitrage. In the context of a skill triggered by depegs, exploits, and hacks, the lack of a strong user-facing disclaimer and the presence of authoritative scoring can push users toward hazardous financial actions based on incomplete or rapidly changing incident data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is overly broad and includes common, ambiguous phrases such as 'should I buy', 'black swan', and generic exploit/hack terms, which can cause the skill to activate in unrelated financial or security discussions. In this skill’s context, unintended activation is more dangerous because it can steer users into rapid crisis-arbitrage advice and encourage speculative trading during stressful market events.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The mandated Chinese-only output format can cause the model to respond in a language the user did not request or understand, increasing the chance of misunderstanding time-sensitive financial risk guidance. In a crisis-trading skill, reduced clarity is especially risky because users may misread position sizing, stop conditions, or the final BUY/WATCH/AVOID recommendation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.