Back to skill

Security audit

Solana Investor

Security checks for vulnerabilities and agentic risk

Overview

The skill presents itself as a prompt-only Solana investment orchestrator, but it also ships undocumented operational scripts that read shared configuration, database counts, environment-credential indicators, and metrics.

Review before installing. The prompt instructions are conservative about confirming investment actions, but the package also contains hidden operational scripts that can expose deployment posture and aggregate application state if invoked with access to the surrounding repository and environment. Only use it where those scripts are understood, authorized, and run with least-privilege read access.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/evaluate-execution-mode.js:7
Finding

Undocumented Access to Shared Operational Configuration, Database Statistics, and Metrics

Content
View full analysis

Vulnerability Details

File Location: scripts/evaluate-execution-mode.js:7-12, 27-28, 76-95, 137-144; scripts/get-metrics.js:6-12
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

The skill documentation states that the package is a prompt-only orchestrator with no direct scripts. Nevertheless, the package contains executable scripts that cross the skill directory boundary and access shared application modules, configuration, environment-variable indicators, database statistics, and operational metrics.

Complete Code Snippets

From scripts/evaluate-execution-mode.js:

js
const fs = require('fs');
const path = require('path');
const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared');

const config = require(path.join(sharedDir, 'config'));
const { initDatabase, getDb } = require(path.join(sharedDir, 'database'));
const { formatError } = require(path.join(sharedDir, 'errors'));
js
function count(sql) {
    return getDb().prepare(sql).get().count;
}
js
{
    key: 'notification',
    status: process.env.TELEGRAM_BOT_TOKEN ? 'pass' : 'warn',
    zh: process.env.TELEGRAM_BOT_TOKEN ? '已配置 Telegram 通知通道。' : '未配置 Telegram 通知通道。',
    en: process.env.TELEGRAM_BOT_TOKEN ? 'Telegram notification channel is configured.' : 'Telegram notification channel is not configured.',
    actionZh: '确保策略执行失败、价格触发、风控事件均可即时通知。',
    actionEn: 'Ensure execution failures, alert triggers, and risk events notify users immediately.',
},
{
    key: 'signer_control',
    status: process.env.EXECUTION_SIGNER_REF ? 'warn' : 'fail',
    zh: process.env.EXECUTION_SIGNER_REF
        ? '检测到执行签名器引用(需进一步审计权限边界)。'
        : '未检测到执行签名器控制面(HSM/MPC/KMS)。',
    en: process.env.EXECUTION_SIGNER_REF
        ? 'Execution signer reference detected (permission boundaries still need audit).'
        : 'No signer control-plane detected (HSM/MPC/KM
...[truncated 4213 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the operational assessment and metrics scripts from this prompt-only orchestration skill if they are not required for its documented purpose.
  2. If the functionality is legitimate, move it into a separately reviewed operations or readiness skill and explicitly document its data-access requirements.
  3. Replace direct database and environment access with a narrow, read-only service interface that returns only approved aggregate fields.
  4. Apply an explicit output allowlist to getMetricsSummary() results and redact identifiers, secrets, internal endpoints, detailed error data, and tenant-specific information.
  5. Avoid resolving and loading mutable modules outside the package boundary. Pin trusted modules through a defined package dependency or a controlled internal API.
  6. Run operational scripts under a dedicated least-privilege identity with read-only database permissions and restricted environment-variable visibility.
  7. Add authorization checks before exposing readiness or metrics output, and ensure standard output is not automatically included in user-facing agent responses.
  8. Update SKILL.md so the declared capabilities, executable scripts, required permissions, and expected outputs accurately match the shipped package.
  9. Add automated tests that fail when unapproved fields are emitted or when scripts access files and modules outside their authorized directory boundary.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is an investment assistant orchestrator that coordinates other skills for complex user investment requests. The supplied code does not orchestrate portfolio, DCA, alerts, or market functions, nor does it process user requests. Instead, it is an operational audit/readiness script that inspects config, env vars, docs, and database counts to score preparedness for live execution. This is a materially different primary purpose and involves undeclared capabilities and resources, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill is an investment workflow orchestrator for coordinating multiple investment-related skills. The supplied code does not implement any orchestration, request handling, or investment operations. Instead, it is a simple utility script for fetching and outputting operational metrics from a shared metrics module. This is a materially different primary purpose and includes access to a metrics resource unrelated to the stated investment-assistant role.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains user-facing natural-language guidance entirely in Chinese, including the description, usage instructions, workflow, and guardrails. Under the policy rule, forcing a specific language without giving the user a language/locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The language selection logic sets Chinese as the default for all cases except when --lang en is provided, effectively forcing a specific locale without explicit user opt-in. This is a natural-language policy issue because the skill does not present a neutral default or require the user to choose their preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script reads sensitive configuration from environment variables, including TELEGRAM_BOT_TOKEN and EXECUTION_SIGNER_REF, to assess operational readiness. While the file contains internal readiness text, it does not include a user-facing warning, confirmation, or explicit disclosure that sensitive credentials are being inspected at runtime.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.