Back to skill

Security audit

Chia SplitXCH

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent, but it should be reviewed because it can send payment split details to SplitXCH and create live Chia split addresses without a mandatory confirmation step.

Install only if you are comfortable sending recipient names, XCH wallet addresses, and allocation details to SplitXCH. Before any API call, ask the agent for a dry-run preview and explicitly confirm the final recipients, percentages, basis points, nested fee impact, and generated-address purpose.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes shell execution via bash <skill_dir>/scripts/splitxch.sh /tmp/split-payload.json but does not declare any tool scope or permission boundary. This creates an undeclared capability mismatch: an agent or reviewer may treat the skill as low-risk content generation while it can actually execute local commands and interact with external systems, increasing the chance of unsafe or unintended execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad phrases like 'revenue share' and 'payment split', which can match user requests outside the narrow SplitXCH blockchain context. Unintended invocation is risky here because the skill is capable of creating live on-chain payout addresses, so a misfire could push a user into a financial workflow they did not intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow directs the agent to parse user instructions and call the API to generate a live split address, but it does not require an explicit warning or confirmation that this creates a real on-chain payment destination with irreversible consequences. In a financial context, missing this checkpoint can cause users to create or use an incorrect payout configuration, potentially misdirecting funds or silently accepting recurring platform fees.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This curl invocation posts the complete payload to an external API endpoint, creating a direct data exfiltration path from local input to a remote service. In the context of a skill handling royalty splits and wallet allocations, the transmitted data may reveal sensitive financial relationships and recipient details, making the external transmission more security-relevant than in a purely public-data workflow.

Content

Scanner excerpt · scripts/splitxch.sh (reported line 31)May include surrounding context.

sh
fi

# Call API
RESPONSE=$(curl -s -w "\n%{http_code}" -X POST "$API_URL" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script transmits the entire user-supplied JSON payload, including recipient names, wallet addresses, IDs, and payment split information, to a third-party service without an explicit consent prompt or clear disclosure at execution time. In a payment/royalty workflow, that metadata can be sensitive business or financial information, so silent external transmission creates a real confidentiality and privacy risk even if the API use is functionally intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.