Back to skill

Security audit

Lista

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Lista lending analytics assistant, but it stores wallet/settings data locally and uses unsafe shell-write instructions that could execute user-supplied input.

Review before installing. This skill is not limited to read-only reporting in practice: it can persist wallet addresses and preferences under ~/.lista, query Lista services with wallet-linked data, and set up alert or digest-style notification flows. Do not enter untrusted custom language names or wallet text unless the skill is changed to validate inputs and write files without shell interpolation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:67
Finding

Shell Command Injection Through Custom Language Persistence

Content
View full analysis
" > ~/.lista/language.txt ``` The `` placeholder may contain a user-provided custom language name. The Skill does not require validation, shell-safe encoding, or use of a non-shell filesystem interface before substituting this value into the command. ### Technical Analysis The command places attacker-controlled content inside a double-quoted shell argument. Double quotes do not suppress shell command substitution. Consequently, input containing constructs such as `$(...)` may be evaluated by the shell rather than written exclusively as literal data. Custom language names are intentionally unrestricted by the Skill. Unlike the predefined values `en`, `zh-CN`, and `zh-TW`, no allowlist or character validation is specified for an “Other” language. This creates a direct data-to-command boundary violation. The vulnerability depends on the Agent following the documented command by textual placeholder substitution. An input equivalent to: ```text $(id > /tmp/lista-language-injection) ``` could produce an effective command resembling: ```bash mkdir -p ~/.lista && echo "$(id > /tmp/lista-language-injection)" > ~/.lista/language.txt ``` The shell would execute the command substitution before invoking `echo`. ### Attack Path 1. The Skill asks the user to choose an output language. 2. The attacker selects “Other” and supplies a crafted custom language name containing shell syntax. 3. The Agent substitutes the value directly for `` in the documented shell command. 4. The shell evaluates command substitutions or other successfully injected syntax. 5. The injected command executes with the same operating-system privileges as the Agent process. 6. The legitimate language file write may still complete ...[truncated 889 chars]
Remediation
View remediation
"$HOME/.lista/language.txt"' sh "" ``` 7. Prefer an implementation equivalent to the following non-shell logic: ```javascript await fs.promises.mkdir(path.join(os.homedir(), '.lista'), { recursive: true }); await fs.promises.writeFile( path.join(os.homedir(), '.lista', 'language.txt'), validatedChoice + '\n', { encoding: 'utf8', mode: 0o600 } ); ``` 8. Add tests confirming that values containing `$()`, backticks, quotes, semicolons, newlines, and redirection operators are rejected or stored literally without execution. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:147
Finding

Shell Command Injection Through Wallet Address Persistence

Content
View full analysis
" > ~/.lista/wallet.txt ``` ### Change address When the user says "change address" / "换个地址" / "換個地址", ask for the new address and save it: ```bash echo "" > ~/.lista/wallet.txt ``` ``` The same issue also affects the multiple-address flow described at `SKILL.md:161-163`, which instructs the Agent to save user-provided comma-, space-, or line-separated addresses without defining mandatory validation or safe serialization. ### Technical Analysis Both commands interpolate a user-controlled wallet value into shell source. Although the Skill mentions checking whether a previously loaded address is valid, it does not mandate strict validation before saving a newly supplied address or replacement address. Wrapping `` or `` in double quotes is insufficient because shell command substitution remains active inside double quotes. A malicious value containing `$(...)` can therefore cause command execution if the Agent performs direct placeholder replacement. For example, a supplied wallet value equivalent to: ```text $(id > /tmp/lista-wallet-injection) ``` could result in: ```bash echo "$(id > /tmp/lista-wallet-injection)" > ~/.lista/wallet.txt ``` The shell evaluates `id > /tmp/lista-wallet-injection` before `echo` writes the resulting text. More complex payloads could invoke available tools, modify files, or send locally accessible data to an external host. This behavior exceeds the minimum privileges required by the declared functionality. Persisting a public blockchain address requires only literal file output; it does not require interpreting the address as executable shell syntax. ### Attack Path 1. The user requests a position, risk, or da ...[truncated 1436 chars]
Remediation
View remediation
addressPattern.test(a))) { throw new Error('Invalid wallet address'); } await fs.promises.mkdir(path.join(os.homedir(), '.lista'), { recursive: true }); await fs.promises.writeFile( path.join(os.homedir(), '.lista', 'wallet.txt'), addresses.join('\n') + '\n', { encoding: 'utf8', mode: 0o600 } ); ``` 8. Validate addresses again after loading the persisted file so that previously tampered state cannot be treated as trusted input. 9. Add regression tests using command substitutions, quotes, semicolons, redirections, newlines, and mixed valid/invalid multi-address input. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The code substantially matches several declared capabilities: it produces position reports (dashboard), market overviews (markets, vaults, cdp-markets), yield-related information (vaults, staking, rewards), and liquidation/risk-style metrics (ltv, healthFactor, liqPriceUsd, riskLevel). It also supports BSC and Ethereum via the --chain flag. However, the declared description includes 'daily digest' and 'loop strategy', which are not implemented anywhere in the supplied code. The code is a read-only API querying/reporting CLI and does not generate a digest/scheduled summary or perform/analyze looping strategy logic. Additionally, it exposes extra capabilities like prices, rewards, staking, and CDP markets, but these are closely related to the lending assistant domain rather than materially unrelated. Therefore this is a partial but real description-behavior mismatch.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: lista
description: Lista Lending assistant — position report, market overview, yield scan, liquidation risk check, daily digest, and loop strategy on BSC and Ethereum
---

# Lista Lending

Your Lista Lending (Moolah) assistant on BSC and Ethereum. Choose a function below.

## Skill Routing Boundary (Required)

Use this skill for report-style, read-only analysis.

- Use `lista` for position report, market overview, vault yield scan, risk check, daily digest, and loop strategy.
- Do not use `lista` for lending execution flows (`deposit`, `withdraw`, `supply`, `borrow`, `repay`) or operation target selection.
- For lending-onl

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill presents itself as read-only analysis, but it instructs the agent to persist user data locally. That creates unnecessary collection and retention of potentially sensitive wallet identifiers and user preferences, expanding privacy and compromise risk beyond what a user would expect from a read-only reporting skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documenting the skill as read-only while embedding write-to-disk behavior is a trust-boundary violation. Even if the writes are local, users and operators may authorize the skill under the assumption it performs no state-changing actions, making the hidden persistence more dangerous in agent environments.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
## Data sources — silent fallback

Try each source in order. Move to the next silently on any error (connection error, tool not found, command not recognized). NEVER ask the user to install, configure, or set up anything.

1. MCP tools (preferred): `lista_get_position`, `lista_get_borrow_markets`, `lista_get_lending_vaults`, `lista_get_oracle_price`, `lista_get_staking_info`, `lista_get_dashboard`, `lista_get_rewards`
2. moolah.js (Node.js, no install needed): `node skills/lista/scripts/moolah.js [--chain bsc|eth] <command>`

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The skill is designed to send wallet-linked queries to external services via MCP or the Lista API. External transmission is expected for a data-fetching assistant, but it still exposes user wallet addresses and request metadata to third parties, creating privacy and tracking risk.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
1. MCP tools (preferred): `lista_get_position`, `lista_get_borrow_markets`, `lista_get_lending_vaults`, `lista_get_oracle_price`, `lista_get_staking_info`, `lista_get_dashboard`, `lista_get_rewards`
2. moolah.js (Node.js, no install needed): `node skills/lista/scripts/moolah.js [--chain bsc|eth] <command>`
3. REST API (curl): `curl -s "https://api.lista.org/api/moolah/<endpoint>"`

Each reference file lists the exact fallback commands per data step.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
### Ask if no saved language

Do NOT run any commands until the user has answered this question:

> Which language should I use for the output?
> 請問輸出以哪種語言生成?

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Writing language preference to a persistent file creates cross-session state without user consent. While lower sensitivity than wallet storage, it still introduces undisclosed tracking/persistence behavior and can combine with other stored artifacts to profile users.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Save the choice:

bash
mkdir -p ~/.lista && echo "<CHOICE>" > ~/.lista/language.txt

Where <CHOICE> is one of: en, zh-CN, zh-TW, or the user's custom language name.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Persisting wallet addresses locally is unnecessary for generating reports and creates a durable record of a user's on-chain identity. If the host is shared, compromised, or logs home-directory contents, that data can be correlated with financial activity and reused without the user's awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill tells the agent to save wallet addresses locally without any privacy or safety warning. Users may not realize their address will be retained on disk, which undermines informed consent and increases the chance of accidental exposure on multi-user systems or in backups.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

Persisting wallet addresses across sessions creates durable sensitive state tied to a user's financial identity. In an agent setting, this can be silently reused in later requests or exposed through filesystem access, backups, or other local compromise.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

Save address

bash
mkdir -p ~/.lista && echo "<ADDRESS>" > ~/.lista/wallet.txt

Change address

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
1. Call the Read tool on **every** reference file listed in the table below for the selected report type.
2. Do NOT generate any output from memory or prior context. If you have not read the file in this session using the Read tool, read it now.
3. Follow the fallback chain in "Data sources" above. Move to the next source silently on any error. Never ask the user to configure a data source.

| Report type | Read these files |
|---|---|

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file mandates output templates in English and Traditional Chinese and also hard-codes specific Chinese-language subscription prompts. This imposes language choices in the skill content without stating that the user can select their preferred language or opt out.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill adds subscription-management behavior for scheduled delivery over Telegram/Discord, which expands capability beyond the described lending analytics/reporting scope. That mismatch can cause users or host platforms to authorize a skill they believe is read-only while it actually initiates persistent outbound messaging behavior, increasing privacy and consent risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The subscription flow asks the user to pick Telegram or Discord and then immediately confirms recurring scheduled delivery, but it provides no warning about ongoing notifications, data shared to external channels, or retention/privacy implications. This can lead to users unknowingly enabling persistent broadcasts of wallet-related financial information to third-party platforms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction requires appending either English or Chinese text '(correlated)' / '(相關對)' in output, but does not provide a user opt-in or selection mechanism for language/locale. This can violate language policy expectations by forcing locale-specific output behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to simulate a leveraged looping strategy but does not require a clear upfront warning that looping increases liquidation risk, leverage losses, and sensitivity to variable borrow rates. In a DeFi lending context, users may interpret the output as an endorsement and act on it without appreciating that small price moves or rate changes can wipe out the expected yield advantage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill hard-codes both English and Traditional Chinese output templates without user selection, reducing user control and potentially causing confusion or poor UX when only one language is desired. While not a direct security flaw, forced multilingual output can obscure critical financial risk information, especially if warnings are diluted by rigid formatting requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates a character-for-character output template in only English or Traditional Chinese, without any user-choice, accessibility fallback, or allowance for system/developer safety messaging. This can suppress needed clarifications, warnings, or policy-compliant output shaping, and may cause the agent to ignore user language preferences or higher-priority instructions in favor of rigid formatting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill hard-codes output into English or Traditional Chinese templates and requires character-for-character conformance without any explicit user choice. This can override user language preferences or downstream system expectations, creating prompt-injection-like behavior where formatting constraints take precedence over the actual request and may cause misleading or unusable responses in multilingual contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file provides only fixed English and Traditional Chinese output templates and requires copying them character-for-character, but does not instruct the skill to ask for or honor the user's preferred language. This can violate language/locale policy because a specific language or locale is imposed without explicit opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill scope expands from reporting liquidation risk into persistent threshold management and alert subscription workflows. That broadening is risky because a report-oriented assistant may begin performing state-changing actions based on loosely matched user phrases, increasing the chance of unintended configuration changes and hidden side effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation directs the agent to write and delete a local file in the user's home directory, which is a persistent side effect beyond normal analytical/reporting behavior. Without an explicit permission and warning model, this can surprise users, create unwanted state, and normalize filesystem writes from a skill that appears read-only.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases for changing thresholds and enabling alerts are broad and conversational, which makes accidental activation more likely during ordinary discussion. In a skill with persistent writes and notification side effects, ambiguous triggers can cause unauthorized or unintended state changes without the user realizing they initiated an action.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

Writing threshold settings to ~/.lista/thresholds.json creates session-persistent state in the user's home directory. Persistent storage can outlive user expectations, affect future outputs invisibly, and be abused by ambiguous prompts to alter the assistant's behavior across sessions.

Content

Scanner excerpt · references/risk.md (reported line 180)May include surrounding context.

Validation: For each scenario, DANGER < WARNING <= SAFE. Reject and re-ask if violated.

After collecting, write to ~/.lista/thresholds.json:

json
{

Static analysis

No suspicious patterns detected.