Back to skill

Security audit

Solana Dca

Security checks for vulnerabilities and agentic risk

Overview

This Solana DCA skill should be reviewed because it delegates strategy actions to unaudited shared code outside the package, so the claimed simulation-only behavior cannot be verified.

Install only if you trust the surrounding shared runtime that supplies the strategy services. Before use, verify what the external shared modules do, where strategies are stored, how Telegram user IDs are authorized, and whether any scheduler or Solana transaction path can execute real trades despite the simulation-only documentation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/create-dca.js:7
Finding

Execution of Unbundled Dependencies Outside the Audited Skill

Content
View full analysis

Vulnerability Details

File Location: scripts/create-dca.js:7-12, scripts/list-strategies.js:6-11, scripts/pause-strategy.js:6-9, and scripts/resume-strategy.js:6-9
Vulnerability Type: Untrusted external code dependency
Risk Level: Medium

Vulnerable Code

scripts/create-dca.js:7-12:

js
const path = require('path');
const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared');

const { createStrategy } = require(path.join(sharedDir, 'services'));
const { formatError } = require(path.join(sharedDir, 'errors'));
const { resolveToken } = require(path.join(sharedDir, 'price-service'));

scripts/list-strategies.js:6-11:

js
const path = require('path');
const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared');

const { listStrategies } = require(path.join(sharedDir, 'services'));
const { formatError } = require(path.join(sharedDir, 'errors'));
const { formatStrategy } = require(path.join(sharedDir, 'formatter'));

scripts/pause-strategy.js:6-9:

js
const path = require('path');
const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared');
const { pauseStrategy } = require(path.join(sharedDir, 'services'));
const { formatError } = require(path.join(sharedDir, 'errors'));

scripts/resume-strategy.js:6-9:

js
const path = require('path');
const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared');
const { resumeStrategy } = require(path.join(sharedDir, 'services'));
const { formatError } = require(path.join(sharedDir, 'errors'));

Technical Analysis

Every executable script imports JavaScript modules from a shared directory located three levels above the Skill directory. These modules are outside the supplied and audited project artifact. Their source, version, integrity, installation process, and authorization behavior therefore cannot be verified.

Node.js executes top-level module code ...[truncated 2292 chars]

Remediation
View remediation

Remediation Suggestions

  1. Move all required implementation modules into the audited Skill package so that the complete runtime behavior is reviewable.
  2. If shared code must remain external, distribute it as a trusted package with an exact version, a committed lockfile, and package-integrity verification.
  3. Verify the canonical path and integrity hash of every dependency before loading it, and terminate execution if verification fails.
  4. Ensure the dependency directory and its parent directories are owned by a trusted account and are not writable by unprivileged users or unrelated Skills.
  5. Document the complete dependency installation and update process, including the provenance of the shared modules.
  6. Include and audit the authorization logic used to associate telegramId values with strategy records.
  7. Add tests proving that the implementation performs simulation-only operations and cannot initiate on-chain transactions.
  8. Run the scripts under a least-privilege account with restricted filesystem, environment-variable, credential, and network access to reduce the impact of a compromised module.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

声明描述的是“创建和管理 DCA 定投策略”,其中明确包含设置定投、查看策略和调整自动购买计划等管理能力;而这段代码的实际功能仅限于创建 DCA 策略,不包含查询已有策略、修改计划、暂停/恢复或其他管理操作。代码与“支持自动周期性购买 Solana 代币”的创建部分是吻合的,但对描述中的管理与查看能力没有体现。因此存在描述与实际行为不完全一致的情况,属于能力范围被高估的 mismatch。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
| `create-dca.js` | 创建策略 | `<user_id> <token> <amount_usdc> <daily\|weekly\|monthly\|6hours>` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
| `pause-strategy.js` | 暂停策略 | `<user_id> <strategy_id>` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
| `resume-strategy.js` | 恢复策略 | `<user_id> <strategy_id>` |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

文件中的名称、描述和交互示例均固定为中文,没有说明可根据用户语言偏好切换,也未声明该技能仅面向特定中文区域用户。根据规则,未经用户选择而强制特定语言属于自然语言政策问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad and overlap with common conversational language such as '自动买' and '每天买', which can cause accidental activation of a financial-action skill. In the context of a DCA trading skill, misrouting ordinary discussion into a strategy-creation workflow is more dangerous than usual because it may lead users toward unintended financial operations or strategy setup steps.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script defaults lang to 'zh' when the user does not provide --lang, which imposes a specific language choice rather than offering a neutral default or explicit opt-in. This is a natural-language locale policy concern because the file does support multiple languages but selects one automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script defaults lang to zh when --lang is not supplied, which imposes a specific language choice on users without explicit opt-in. The policy allows locale constraints only when documented and justified or when users are offered a choice by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.