Back to skill

Security audit

ZetaChain Skill

Security checks for vulnerabilities and agentic risk

Overview

This ZetaChain helper is a narrow command-line lookup tool that contacts public blockchain endpoints, with privacy and documentation gaps but no evidence of hidden persistence, credential theft, destructive behavior, or transaction execution.

Install only if you are comfortable with wallet addresses and CCTX hashes being queried through the listed public RPC/API providers. Verify any suggested deposit or TSS address against official ZetaChain sources before moving funds, and do not treat the tool's action suggestions as financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

A description-behavior mismatch is security-relevant because users and agent platforms rely on the manifest to understand what a skill will do. If the implementation includes undeclared capabilities such as operational advice, asset navigation, gas-price queries, or network health analysis, the skill can perform actions or influence decisions outside the reviewed scope, undermining informed consent and policy enforcement.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill advertises capabilities that inherently require network access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization ambiguity where an agent runtime may permit broader-than-intended network use, reducing transparency and making review and sandboxing harder.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The script transmits user-supplied wallet addresses to third-party RPC providers, which leaks potentially sensitive financial metadata and links user activity to external infrastructure outside the user's control. In this skill context, external lookups are expected for blockchain queries, but the privacy risk remains because addresses may be correlated, logged, or profiled by those providers.

Content

Scanner excerpt · scripts/zeta_tool.py (reported line 29)May include surrounding context.

python
payload = {"jsonrpc": "2.0", "method": "eth_getBalance", "params": [address, "latest"], "id": 1}
    for node in node_list:
        try:
            r = requests.post(node, json=payload, timeout=5)
            result = r.json().get("result")
            if result: return int(result, 16) / 1e18
        except: continue

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

Gas-price queries contact external RPC endpoints and expose the user's usage of the skill, network interest, and timing metadata to third parties. While less sensitive than balance lookups, it still creates an external dependency and telemetry channel that can be logged, manipulated, or used for profiling in a finance-related context.

Content

Scanner excerpt · scripts/zeta_tool.py (reported line 49)May include surrounding context.

python
payload = {"jsonrpc": "2.0", "method": "eth_gasPrice", "params": [], "id": 1}
    for node in node_list:
        try:
            r = requests.post(node, json=payload, timeout=5)
            result = r.json().get("result")
            if result: return int(result, 16) / 1e9
        except: continue

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes support for zEVM contract deployment guidance and technical document indexing, yet this file exposes only nav, track, balance, and help behaviors. Its documented commands and implemented functions are limited to asset/balance lookups, gas checks, and CCTX status retrieval, so the described feature set is materially broader than the actual code behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill’s natural-language description and feature documentation are presented entirely in Chinese, which can impose a locale/language constraint on users without any stated opt-in or alternative. The policy specifically flags language or locale restrictions when the skill does not offer a user choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The manifest frames the skill around asset querying, CCTX tracking, deployment guidance, and documentation indexing. In contrast, the help text and generate_navigation logic produce prescriptive operational recommendations such as 'Unlock BTC Liquidity' and 'Low-Cost ETH Deposit', which goes beyond simple query/tracking behavior into advisory workflow generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing help content and command descriptions are presented entirely in Chinese, which imposes a specific language on users. Under the policy, language constraints should either offer a user choice or be clearly documented as a justified locale-specific tool, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.