Back to skill

Security audit

Solana Alerts

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Solana price-alert wrapper, but its important alert logic depends on unaudited external code and includes under-disclosed global alert processing.

Review before installing. This skill may be acceptable only in a controlled OpenClaw deployment where the ../../../shared modules are trusted, versioned, and permissioned, and where global alert checks are restricted to an authorized scheduler. Users should understand that it handles user identifiers and persistent alert records, and that the included stop-loss/take-profit scripts go beyond the documented simple price-threshold workflow.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/check-prices.js:12
Finding

Caller-Controlled Flag Bypasses Authorization for Global Alert Processing

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/check-prices.js:6
Finding

Security-Sensitive Operations Depend on Mutable Executable Modules Outside the Audited Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation creates profit-percentage take-profit alerts instead of absolute price alerts, users may set what they believe are simple threshold notifications but actually trigger different financial monitoring behavior. In an asset-tracking context, this can lead to incorrect actions, unintended notifications, mishandling of user identifiers, and misuse of the skill under false pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation creates profit-percentage take-profit alerts instead of absolute price alerts, users may set what they believe are simple threshold notifications but actually trigger different financial monitoring behavior. In an asset-tracking context, this can lead to incorrect actions, unintended notifications, mishandling of user identifiers, and misuse of the skill under false pretenses.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
| `create-alert.js` | 创建警报 | `<user_id> <token> <above\|below> <price>` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
| `delete-alert.js` | 删除警报 | `<user_id> <alert_id>` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language content of the skill, including description, workflow, prompts, and guardrails, is presented only in Chinese. This effectively imposes a language choice on users without any opt-in mechanism or documented reason for limiting the skill to that locale.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation guidance includes generic phrases like “提醒”, “通知”, and “到了xxxx通知我”, which are common conversational expressions and are not narrowly scoped to token price alerts. Without explicit exclusions or tighter context, the skill could be invoked unintentionally for unrelated reminder or notification requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script defaults lang to zh when --lang is not provided, which imposes a specific locale choice on the user. The policy allows locale constraints only when the user is given a choice or the constraint is clearly justified and documented; neither is evident here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sets the language to 'zh' by default when the user does not pass --lang. This imposes a specific locale choice rather than offering a neutral default or requiring explicit user selection, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes alerts that notify users when a token price is above or below a target value, which implies absolute price-threshold alerts. This script instead creates a stop-loss alert based on cost-basis drawdown percentage, a distinct alert model tied to user position performance rather than simply crossing a target price.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes this skill as creating and managing alerts when a token price goes above or below a target value. This script instead creates a take-profit alert based on profit percentage relative to cost basis, which is a different alert model requiring portfolio/cost-basis semantics beyond a simple price threshold.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script defaults lang to zh when --lang is not provided, which imposes a specific language preference without user opt-in. The applicable policy only permits locale constraints when the user is given a choice or the constraint is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.