Back to skill

Security audit

KaspaCom DeFi MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent KaspaCom DeFi integration, but it asks users to install an unpinned global package and can run wallet-enabled financial transactions with limited built-in scoping or confirmation guidance.

Review the package source and version before installing, avoid global installation where possible, test only on testnet first, and use a dedicated low-value wallet rather than exposing a primary private key to the MCP server. Do not run write actions unless the tool shows exactly what transaction will be signed and you explicitly approve it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:18
Finding

Unpinned Global Installation of a Wallet-Enabled Third-Party Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18–20
Vulnerability Type: Unpinned and globally installed executable dependency
Risk Level: High

Vulnerable Code

bash
npm i -g @kaspacom/defi-mcp

Related wallet-enabled execution instructions at lines 27–29:

bash
MCP_WALLET_KEY="0x..." MCP_NETWORK=igra node dist/mcp/index.js

Technical Analysis

The Skill directs users to install the latest available version of @kaspacom/defi-mcp globally. It does not specify an exact version, integrity hash, lockfile, verified source repository, or package publisher validation procedure.

npm packages may execute lifecycle scripts during installation. A global installation also exposes the installing user's environment to package-controlled code and makes the resulting executable available system-wide for that user. The project contains only SKILL.md; therefore, the package implementation, installation scripts, transaction handling, and treatment of MCP_WALLET_KEY cannot be independently verified from the audited artifact.

The wallet-enabled invocation substantially increases the potential consequences. If the dependency or its publisher account is compromised, malicious package code could read the wallet key from the process environment, manipulate transaction parameters, or execute unrelated commands with the privileges of the user running npm or the MCP server.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or another relevant supply-chain component for @kaspacom/defi-mcp.
  2. The attacker publishes a malicious version under the package's expected name.
  3. A user follows the Skill and runs the unpinned global installation command, which resolves to that malicious version.
  4. Malicious code executes through an npm lifecycle script or when the installed MCP server or CLI is launched.
  5. The user starts the service with `MCP_WALLET_KEY ...[truncated 1036 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact, reviewed version rather than resolving the latest release:
    bash
    npm install --save-exact @kaspacom/defi-mcp@<audited-version>
    
  2. Avoid global installation. Use a project-local dependency with a committed lockfile and execute it through a controlled project script.
  3. Publish or reference the verifiable source code corresponding to the pinned package release.
  4. Verify package provenance, publisher identity, signatures, and registry integrity metadata before installation.
  5. Review all npm lifecycle scripts. Where operationally feasible, install with lifecycle scripts disabled and explicitly run only audited build steps.
  6. Run the MCP server in a sandbox or container with minimal filesystem, network, and operating-system permissions.
  7. Do not expose a primary wallet private key directly through a general-purpose process environment. Prefer a hardware wallet, delegated signer, narrowly scoped signing service, or secret manager.
  8. Use a dedicated low-value wallet with only the funds and permissions required for the intended operation.
  9. Require an explicit transaction preview and user confirmation that displays the destination, asset, amount, slippage, network, and contract before signing.
  10. Test wallet-enabled operations on igra-testnet or kasplex-testnet before mainnet use.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description is broad enough to activate on many generic requests involving KaspaCom, MCP, CLI, prices, swaps, lending, or launchpad actions, without strong constraints on when the skill should or should not take over. In a skill that can perform financial transactions when a wallet key is configured, overbroad activation increases the chance of unintended routing into transaction-capable tooling and can lead to accidental high-risk actions or confusing the user about what will be executed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.