Back to skill

Security audit

Solana Portfolio

Security checks for vulnerabilities and agentic risk

Overview

This Solana portfolio skill is mostly coherent, but it exposes sensitive wallet and portfolio records through caller-supplied Telegram IDs and includes under-disclosed financial analysis behavior.

Review before installing. Use this only behind a trusted dispatcher that supplies the authenticated user's own Telegram ID and prevents users from choosing arbitrary IDs. Treat wallet addresses, holdings, values, and PnL as sensitive financial metadata, and be aware that the package includes rebalancing output not clearly documented in the main skill file.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/add-wallet.js:13
Finding

Caller-Controlled User Identifier Allows Cross-User Data Access and Modification

Content
View full analysis
= 5) { process.exit(1); } const added = addWallet(user.id, address); ``` #### `scripts/get-pnl.js:17-77` ```js const telegramId = process.argv[2]; async function main() { const user = findOrCreateUser(telegramId, ''); const wallets = getUserWallets(user.id); if (!wallets || wallets.length === 0) { process.exit(0); } const portfolio = await getPortfolio(user.id); if (!portfolio.holdings || portfolio.holdings.length === 0) { process.exit(0); } const pnlRows = await getPortfolioPnl(user.id, portfolio.holdings); ``` #### `scripts/get-portfolio.js:14-40` ```js const telegramId = process.argv[2]; async function main() { const user = findOrCreateUser(telegramId, ''); const wallets = getUserWallets(user.id); if (!wallets || wallets.length === 0) { process.exit(0); } const portfolio = await getPortfolio(user.id); ``` #### `scripts/get-rebalance-suggestion.js:14-63` ```js const telegramId = process.argv[2]; const benchmarkArg = process.argv[3]; async function main() { try { const user = findOrCreateUser(telegramId, ''); const wallets = getUserWallets(user.id); if (!wallets || wallets.length === 0) { process.exit(0); } const portfolio = await getPortfolio(user.id); if (!portfolio || portfolio.isEmpty || po ...[truncated 4660 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

声明描述的是投资组合追踪与管理功能:查看持仓、添加钱包、了解余额与估值。实际代码并不执行添加钱包,也不只是展示余额、分布或估值;其核心功能是调用 generateRebalanceSuggestion,对投资组合进行基准对比并生成具体的再平衡建议。这属于更偏向投资分析/配置建议的能力,超出了单纯“追踪多钱包余额、代币分布和资产估值”的声明范围。虽然代码确实读取钱包和组合数据,和投资组合领域相关,但其主要目的与描述相比发生了实质偏移,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
| `add-wallet.js` | 添加钱包 | `<user_id> <address>` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
| `list-wallets.js` | 列出钱包 | `<user_id>` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
| `remove-wallet.js` | 移除钱包 | `<user_id> <address>` |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language policy violations include forcing a specific language without user opt-in. This file presents the skill description, usage instructions, prompts, and guardrails entirely in Chinese, while only one script parameter hints at optional English output and the skill text itself does not offer the user a language choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough that ordinary conversation about 'portfolio', 'balance', 'holdings', or 'wallet' could activate the skill outside a clearly scoped Solana context. In an agent setting, overbroad activation can cause the system to collect a Telegram user ID, ask for wallet addresses, or run wallet-management scripts when the user did not intend to interact with this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sets the default lang to zh when the user does not provide --lang. This forces a specific locale by default rather than offering a neutral default or requiring explicit user choice, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sets the default language to 'zh' and treats any non-'en' value as Chinese output, which imposes a specific locale without user opt-in. This is a natural-language policy issue because users are not offered a neutral default or prompted to choose their preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This script performs an irreversible account-affecting action by removing a wallet association, but it proceeds immediately once arguments are provided. Although there is a success message after completion and a brief file header, there is no confirmation prompt or explicit pre-action warning to the user about the destructive effect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script defaults lang to zh when --lang is omitted, which imposes a specific locale without user opt-in. This is a natural-language policy concern because the skill does not prompt for or otherwise offer a neutral default before choosing Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sets lang to 'zh' when --lang is not provided, which imposes a specific language choice by default. The file does not indicate that the user selected this locale or that the tool is region-specific, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.