Back to skill

Security audit

Dune Analytics API

Security checks for vulnerabilities and agentic risk

Overview

This Dune skill is mostly purpose-aligned, but it includes account-changing Dune operations with weak safeguards and an automatic public-query fallback that users should review before installing.

Install only if you are comfortable giving the skill a Dune API key and letting it run credit-consuming Dune operations. Review any query update, upload, table deletion, or public query creation before it runs, and prefer a pinned dune-client version in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Unpinned Third-Party Dependency Creates Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
" ``` 2. Maintain a lock file containing exact versions of all transitive dependencies. 3. Generate and enforce package hashes with `pip --require-hashes`. 4. Explicitly use the official Python package index or an organization-controlled mirror. 5. Install the dependency inside a dedicated virtual environment with minimal filesystem and environment access. 6. Review new dependency versions before updating the pin. 7. Avoid exposing `DUNE_API_KEY` to installation steps; inject it only when an audited runtime command needs it. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
references/table-discovery.md:184
Finding

SQL Injection Through Direct Interpolation of User Input and Remote Metadata

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description substantially overstates the implemented behavior. While the code does interact with Dune Analytics and supports some query operations, it only manages existing queries by ID: execution, cached result retrieval, SQL retrieval, and SQL update. It does not implement many prominently declared capabilities such as data upload, schema/table discovery, creating queries, or domain-specific blockchain analytics features. The code’s primary purpose is a Dune query CLI wrapper, not a comprehensive blockchain analytics skill. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code’s primary purpose is much narrower than the description. It supports Dune table creation and data upload/append operations only. While upload functionality is accurately represented, most of the declared scope—querying, analyzing blockchain data, exploring Dune tables/schemas, optimizing SQL, and various crypto analytics triggers—is not implemented in this code chunk. This is a material description-behavior mismatch because the declared skill presents a broad analytics/querying capability, whereas the actual code is an upload utility.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to environment variables and reference/script files but does not define any explicit tool scope such as allowed-tools or permissions. In an agent setting, this weakens least-privilege boundaries and can let the skill read sensitive data like DUNE_API_KEY or local files more broadly than users may expect. The risk is moderate because the skill is API-oriented and legitimately needs the key, but the absence of scoping still increases the blast radius if the skill is misused or prompt-injected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger conditions are extremely broad and instruct the agent to invoke this skill for many generic blockchain and crypto-analysis requests, even when Dune is not explicitly requested. Over-broad activation increases the chance that the skill accesses API-backed resources, reads sensitive context, or steers execution into file/env-dependent behavior when a narrower or safer skill would have been more appropriate. In this context, the danger is elevated because the skill uses an API key and encourages reading local references before acting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented fallback silently creates a public query when private query creation fails, which can expose SQL text, embedded business logic, wallet lists, investigation targets, or other sensitive analysis artifacts to unintended parties. In a blockchain analytics context, query contents can reveal proprietary research methods or sensitive addresses of interest, so automatically downgrading privacy is materially risky.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script documentation frames the tool as query execution and management, but it also includes a write-capable update_sql operation that can modify remote Dune queries. In an agent skill context, under-disclosed state-changing behavior increases the risk that a caller or orchestration layer invokes the tool expecting read-only analytics while actually altering production or shared query definitions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

cmd_update_sql performs a remote SQL update immediately with no interactive confirmation, dry-run, diff preview, or secondary acknowledgement. In a skill intended for analytics workflows, this makes accidental or prompt-influenced modification of remote query state much easier, especially when an agent may process ambiguous user requests or untrusted SQL content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON file contains user-facing natural-language content entirely in Chinese across the prompts, expected outputs, and expectations. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation, and there is no indication that this skill is intentionally limited to Chinese users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file includes code that reads DUNE_API_KEY from environment variables, which is a credential-related operation. The surrounding documentation does not warn users to protect the key, avoid exposing it in logs, or ensure it is set securely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes code that reads an API credential from os.environ['DUNE_API_KEY']. While the page documents table discovery usage, it does not explicitly warn users that the examples require access to a sensitive credential or advise safe handling of that secret.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The markdown includes requests.get(...) examples that contact external Dune documentation endpoints. Although benign and aligned with the feature, the surrounding text does not explicitly disclose that these examples perform network requests, which is the kind of behavior the warning rule asks markdown files to call out when relevant to privacy or system behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.