Back to skill

Security audit

The Flip Publish

Security checks for vulnerabilities and agentic risk

Overview

This is a real Solana devnet game skill, but users should review it carefully because it handles wallet signing and token movement while the game fairness and operator controls are under-disclosed.

Install only if you are comfortable testing an unaudited devnet blockchain game. Use a dedicated devnet-only wallet with no mainnet funds, avoid passing sensitive keypair paths, review transactions before signing, and do not rely on the stated odds or anti-rug framing until the randomness, admin controls, and dependency issues are fixed or independently audited.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:100
Finding

Unverified Remote Installer Is Downloaded and Executed by a Shell

Content
View full analysis
Remediation
View remediation
solana-installer.tar.gz" | sha256sum --check - ``` 4. Prefer signature verification using a trusted, separately distributed release key. 5. Extract and inspect the artifact only after verification. 6. Avoid silently selecting a mutable `stable` channel. 7. Document a package-manager or official manual installation alternative. 8. Apply the correction to both `SKILL.md` and `README.md`. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
program/src/lib.rs:91
Finding

Predictable and Manipulable Clock-Derived Randomness Controls Jackpot Outcomes

Content
View full analysis
) -> Result<()> { let game = &mut ctx.accounts.game; let idx = game.global_flip as usize % BUFFER_SIZE; // Randomness from slot + timestamp + game key + global flip number let clock = Clock::get()?; let mut seed: u8 = (game.global_flip & 0xFF) as u8; for b in clock.slot.to_le_bytes() { seed ^= b; } for b in clock.unix_timestamp.to_le_bytes() { seed ^= b; } for b in game.key().to_bytes() { seed ^= b; } // Even = H (1), Odd = T (2) let result: u8 = if seed % 2 == 0 { 1 } else { 2 }; game.flip_results[idx] = result; game.global_flip += 1; ``` ### Technical Analysis The outcome is derived exclusively from public or predictable values: - The current global flip number - The Solana slot - The on-chain clock timestamp - The public game PDA The code XORs these values into a single `u8` and then uses only its parity. This construction supplies no cryptographic unpredictability. Once the execution slot and timestamp are known or controlled, the result is deterministic. The `flip` instruction is permissionless, increasing exposure to transaction timing and ordering attacks. A caller can target favorable execution windows, while a block producer or leader with transaction-ordering control has a stronger ability to include, delay, or withhold a flip based on its deterministic result. The implementation therefore does not support the documentation’s claims of “verifiable randomness,” equal independent odds, or a fair 1-in-16,384 game. Verifiability alone does not provide unpredictability or resistance to manipulation. ### Attack Path 1. An attacker purchases a ticket with known predictions. 2. The attacker reads the public game state, including the next global flip index and game PDA ...[truncated 1366 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
app/demo.mjs:42
Finding

Read-Only Commands Unnecessarily Load the User’s Wallet Private Key

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill presents the game as trust-minimized and centered on a simple winner-takes-all mechanic, but the documented behavior omits material authority-controlled capabilities such as fee withdrawal, explicit initialization, and state management. That mismatch can mislead users and agents about custody, admin power, and fund flows, causing them to take financial actions under false assumptions about decentralization and rug-resistance.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: bigint-buffer==1.1.5 — 1 advisory(ies): CVE-2025-3194 (bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function)

High
Category
Supply Chain
Confidence
91% confidence
Finding

bigint-buffer 1.1.5 is a real vulnerable dependency and appears in the resolved lockfile, so this is not a false positive. In this package it is a transitive dependency of Solana tooling rather than custom malicious code, but a buffer overflow in numeric parsing can still crash a process or potentially enable memory-safety issues when attacker-controlled binary data is handled.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
87% confidence
Finding

brace-expansion 2.0.2 is a real vulnerable version with multiple DoS-style expansion issues, and it is concretely present in the lockfile. Because it is only a dev/transitive test-tool dependency here, the practical exposure is lower in production, but CI, local tooling, or any runtime path using glob pattern expansion could still be crashed or exhausted by crafted input.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
86% confidence
Finding

js-yaml 4.1.1 is actually present and has several known CPU-consumption issues, so this is a true vulnerable dependency. Here it is used transitively through development tooling, reducing production exposure, but any automation or CI that parses untrusted YAML could still be vulnerable to denial of service.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: minimatch==9.0.5 — 3 advisory(ies): CVE-2026-27904 (minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regu); CVE-2026-26996 (minimatch has a ReDoS via repeated wildcards with non-matching literal in patter); CVE-2026-27903 (minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adja)

High
Category
Supply Chain
Confidence
88% confidence
Finding

minimatch 9.0.5 is installed and the listed ReDoS issues are typical high-complexity pattern-matching flaws, making this a legitimate finding. Because this appears under dev/test tooling, the main risk is denial of service when crafted glob patterns are accepted from untrusted sources rather than compromise of blockchain assets directly.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
89% confidence
Finding

ws 8.19.0 is present and the advisory set includes memory disclosure and memory exhaustion issues, so this is a true vulnerability. Since Solana/websocket-based clients commonly maintain network connections, a flaw in websocket frame handling could be relevant if the skill communicates with untrusted or compromised endpoints, though the impact is still mostly confidentiality/availability at the client side.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: serialize-javascript==6.0.2 — 2 advisory(ies): GHSA-5c6j-r48x-rmvq (Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.to); CVE-2026-34043 (Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like)

High
Category
Supply Chain
Confidence
84% confidence
Finding

serialize-javascript 6.0.2 is installed and has a real RCE/DoS advisory profile, so the finding is credible. However, in this lockfile it is pulled in via dev/test tooling, so the RCE angle usually requires unsafe serialization of attacker-influenced objects during development, build, or test workflows rather than normal end-user gameplay.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: toml==3.0.0 — 2 advisory(ies): CVE-2026-77465 (toml-node: Uncontrolled Recursion); CVE-2026-63376 (toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__pro)

High
Category
Supply Chain
Confidence
90% confidence
Finding

toml 3.0.0 is directly present and the advisories include uncontrolled recursion and prototype pollution, so this is a substantive finding. Anchor-based tooling often consumes TOML configuration, and if untrusted TOML is parsed the prototype pollution issue could corrupt application behavior or trigger downstream security bugs.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==7.5.10 — 1 advisory(ies): CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
89% confidence
Finding

ws 7.5.10 is also present separately in the tree and has a real memory exhaustion DoS advisory, so this is not a duplicate false positive but a second vulnerable version. This older websocket stack comes through jayson and increases attack surface if RPC/websocket traffic can be influenced by an attacker or malicious upstream service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The test script invokes ts-mocha through npx without pinning an explicit version, which can cause execution of whatever version resolves at runtime from the local environment or registry. In a build or review workflow, this weakens supply-chain integrity and could expose users to malicious or unexpected package code if dependency resolution is compromised or non-reproducible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to run a command that uses a local Solana keypair and submits an on-chain transaction, but it does not clearly warn that this will spend funds, require trusting a local private-key file path, and interact with a live deployed program. In an agent/automation context, this can trigger unintended wallet use or spending, especially if the command is copied verbatim or executed by tooling without strong confirmation safeguards.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 289)May include surrounding context.

bash
# Game state (base64 -> decode with IDL layout)
curl -s https://api.devnet.solana.com -X POST -H "Content-Type: application/json" -d '{
  "jsonrpc": "2.0", "id": 1,
  "method": "getAccountInfo",
  "params": ["AAEwxhqM1EGjTbCyPqSCX7YpyuRqzBBfyf2kJG1nsGqd", {"encoding": "base64"}]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The build instructions include a remote shell installation command (sh -c "$(curl ...)") without any safety guidance. Piping downloaded content directly to a shell is risky because users execute unreviewed code from the network, and a compromised endpoint or MITM in a weak environment could lead to arbitrary code execution on the developer machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup instructions tell users to install blockchain tooling, generate a wallet, request funds, and interact with a live on-chain game, but they do not clearly warn that these steps create sensitive credentials and may submit irreversible blockchain transactions. In an agent-executed context, this increases the risk of accidental wallet creation, unsafe key handling, and unintended spending by users who may not realize the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script automatically loads a signing key from a local file path or the ANCHOR_WALLET environment variable and immediately uses it for privileged blockchain actions, without any explicit warning, confirmation, or scope restriction. In an agent/skill context, this is risky because invoking seemingly harmless commands like status or operational actions may implicitly access sensitive credentials, increasing the chance of unintended key use or leakage through misconfiguration, logs, or unsafe runtime environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest markets the game with jackpot language while the interface also supports full jackpot payout and operator fee withdrawals, but without conspicuous caution that these operations move user-affecting assets. In an agent-integrated environment, insufficient disclosure around asset movement can mislead users about who can move funds and under what conditions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description frames the skill as an always-live game users can enter at any time, but the IDL includes authority-only instructions to initialize and close game state for migration. Those lifecycle and migration controls are not obvious from the manifest's narrow gameplay description and represent additional administrative behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest describes the 'enter' action as 'Player enters the game' and 'Always open — no rounds, no gates' without defining any narrower trigger conditions or exclusions. In a manifest file, such broad natural-language activation wording can make it unclear when this skill should activate versus other game- or payment-related actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The enter instruction explicitly transfers 1 USDC from the player's token account into the vault, yet the skill text does not provide a strong user-facing warning that invoking this action spends assets. In wallet/agent contexts, weak payment disclosure can lead to deceptive or accidental authorization of token transfers, especially when the skill is framed as a simple game action.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a player-facing game experience: $1 entry, 14 coin flips, and winner-take-all jackpot play. However, this IDL exposes additional authority-only operations such as withdrawing operator fees, which materially expands behavior beyond the simple jackpot-game description into operator fund management.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The program exposes administrative capabilities beyond the user-facing game description: the authority can withdraw operator fees and can also close the game PDA entirely. In a gambling-style jackpot skill, undisclosed admin controls materially affect user trust and fund safety because users may assume the game is only a neutral 14-flip jackpot mechanism, while the operator retains unilateral powers that can interrupt operation or alter recoverability of state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

close_game_v1 lets the authority zero the game account data and reclaim its lamports at any time, with no checks that active tickets remain outstanding or that users have been warned. In this skill context, that is dangerous because claims depend on the game state (global_flip, flip_results, vault reference, and authority-derived PDA data); destroying that state can strand players and make legitimate winnings or verification impossible.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: bn.js==5.2.2 — 1 advisory(ies): CVE-2026-2739 (bn.js affected by an infinite loop)

Low
Category
Supply Chain
Confidence
80% confidence
Finding

bn.js 5.2.2 is present in the lockfile and the cited issue is an infinite-loop condition, so this is a genuine availability risk rather than a false positive. In this skill it is a common crypto/math dependency, and exploitation would more likely cause denial of service than code execution or asset theft.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: diff==7.0.0 — 1 advisory(ies): CVE-2026-24001 (jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch)

Low
Category
Supply Chain
Confidence
76% confidence
Finding

diff 7.0.0 is present and the reported parsePatch/applyPatch DoS issue is plausible, so this is a real but limited vulnerability. In this project it is a dev dependency used by test infrastructure, which makes exploitation unlikely outside development or CI contexts.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: stream-json==1.9.1 — 1 advisory(ies): CVE-2026-71429 (stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — )

Low
Category
Supply Chain
Confidence
78% confidence
Finding

stream-json 1.9.1 is present and the reported depth-related performance issue is a genuine algorithmic DoS concern. In this project it is transitive through jayson rather than obviously directly exposed, so practical exploitability is limited unless the application parses attacker-supplied deeply nested JSON streams.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.potential_exfiltration

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
app/demo.mjs:43

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
app/demo.mjs:43