T09 · Insecure Skill Coding Practices
- Location
SKILL.md:295- Finding
Blind Signing and Broadcasting of Remotely Constructed Solana Transactions
- Content
View full analysis
r.json()); const tx = Transaction.from(Buffer.from(r.txBase64, "base64")); tx.partialSign(agent); // wallet's slot const sig = await conn.sendRawTransaction( tx.serialize({ requireAllSignatures: true }) ); await conn.confirmTransaction(sig, "confirmed"); ``` The end-to-end swap workflow repeats the same pattern: ```ts const swap = await fetch("https://clawpump-v2.vercel.app/api/swap", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ pool: launch.poolPubkey, userWallet: agent.publicKey.toBase58(), amountIn: "1000000", swapBaseForQuote: false, slippageBps: 200, }), }).then((r) => r.json()); const buyTx = Transaction.from(Buffer.from(swap.txBase64, "base64")); buyTx.partialSign(agent); const buySig = await conn.sendRawTransaction( buyTx.serialize({ requireAllSignatures: true }) ); await conn.confirmTransaction(buySig, "confirmed"); ``` ### Technical Analysis The Skill instructs an agent to accept a serialized transaction from `clawpump-v2.vercel.app`, deserialize it, sign it with a wallet that may hold SOL and SPL tokens, and broadcast it directly to Solana mainnet. No validation is performed before signing. In particular, the examples do not verify: - The transaction's program IDs. - The identities and permissions of account metas. - The fee payer. - SOL or token transfer destinations and amounts. - The expected mint, pool, config, and quote-token addresses. - The number, order ...[truncated 2656 chars]- Remediation
View remediation
