Back to skill

Security audit

Torch Liquidation Bot

Security checks for vulnerabilities and agentic risk

Overview

The liquidation bot is mostly transparent about running live financial transactions, but its install path and bundled SDK expose broader financial powers than the stated keeper role.

Review this before installing. Prefer the bundled reviewed source or an exact pinned package version, run it under a dedicated low-privilege account, use a fresh disposable controller key only, never provide a vault authority key, and revoke the linked controller wallet when the bot is not in use. Treat the bundled SDK as a broad Torch Market SDK, not just a liquidation-only component.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
lib/torchsdk/tokens.js:268
Finding

Creator-Controlled Metadata URI Enables Server-Side Request Forgery

Content
View full analysis

Vulnerability Details

File Location: lib/torchsdk/tokens.js:268-285
Vulnerability Type: Server-Side Request Forgery through an unvalidated metadata URI
Risk Level: Medium

Vulnerable Code

javascript
// Fetch metadata from URI
let metadata;
const uri = (0, program_1.decodeString)(bondingCurve.uri);
if (uri) {
    try {
        const controller = new AbortController();
        const timer = setTimeout(() => controller.abort(), 10000);
        const res = await fetch(uri, { signal: controller.signal }).finally(() => clearTimeout(timer));
        const data = (await res.json());
        metadata = {
            description: data.description,
            image: data.image,
            twitter: data.twitter,
            telegram: data.telegram,
            website: data.website,
        };
    }
    catch (e) {
        warnings.push(`Metadata fetch failed: ${e instanceof Error ? e.message : String(e)}`);
    }
}

Technical Analysis

The metadata URI is read from the on-chain BondingCurve.uri field, which is controlled by the token creator. The SDK passes this value directly to fetch() without validating:

  • The permitted URI scheme
  • The destination hostname or resolved IP address
  • Loopback and private network ranges
  • Link-local and cloud metadata addresses
  • Nonstandard destination ports
  • Redirect destinations
  • Response content type or maximum response size

The ten-second AbortController timeout reduces the risk of indefinitely hanging requests but does not prevent server-side request forgery. A creator can supply a URI targeting services reachable from the Agent's runtime, including localhost, private network services, or cloud instance metadata endpoints.

Because redirects are followed by default, an apparently public URL could also redirect to a prohibited internal destination unless every redirect hop is independently validated.

The autonom ...[truncated 1865 chars]

Remediation
View remediation

Remediation Suggestions

  1. Parse metadata locations with new URL(uri) and permit only an explicitly supported scheme, preferably https:.
  2. Reject URLs containing embedded usernames or passwords.
  3. Restrict destination ports to an allowlist such as port 443.
  4. Resolve the destination hostname before connecting and reject:
    • IPv4 and IPv6 loopback ranges
    • RFC1918 private ranges
    • Link-local addresses
    • Multicast and unspecified addresses
    • Cloud metadata destinations
  5. Disable automatic redirects or validate the scheme, hostname, resolved address, and port of every redirect hop.
  6. Apply a strict response-size limit while streaming the body rather than calling unrestricted res.json().
  7. Require a successful HTTP status and an expected JSON content type before parsing.
  8. Prefer an allowlist of trusted metadata gateways, such as an approved Arweave gateway, instead of permitting arbitrary creator-selected hosts.
  9. Retain the existing timeout, but combine it with connection, body-size, and redirect limits.
  10. Add tests covering localhost, private IPv4, private IPv6, DNS rebinding, alternate numeric IP representations, and redirect-based SSRF attempts.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:65
Finding

Mutable npm and npx Installation Instructions Can Execute Code Outside the Audited Artifact

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:65-70, SKILL.md:186-190, and SKILL.md:222
Vulnerability Type: Unpinned third-party package execution and supply-chain exposure
Risk Level: Medium

Vulnerable Code

yaml
install:
  - id: npm-torch-liquidation-bot
    kind: npm
    package: torch-liquidation-bot@^10.7.1
    flags: []
    label: "Install Torch Liquidation Bot (npm, optional -- SDK is bundled in lib/torchsdk/ and bot source is bundled under lib/kit on clawhub)"
bash
npm install torch-liquidation-bot
bash
VAULT_CREATOR=<your-vault-creator-pubkey> SOLANA_RPC_URL=<rpc-url> npx torch-liquidation-bot

Technical Analysis

The installation manifest uses the semver range ^10.7.1, which permits later compatible package releases that were not included in this audit. The documentation also recommends an entirely unversioned npm install and npx invocation.

Consequently, the code that users execute may differ from the bundled JavaScript reviewed in this project. An upstream account compromise, malicious future release, registry compromise, or dependency-chain compromise could cause npm lifecycle or runtime code to execute with the user's privileges.

This is especially sensitive because the bot is expected to run with environment access to:

  • SOLANA_RPC_URL
  • VAULT_CREATOR
  • The optional sensitive SOLANA_PRIVATE_KEY
  • The controller wallet's signing authority
  • The local filesystem and network permissions of the invoking user

No evidence indicates that the currently bundled implementation is malicious. The vulnerability is the mutable remote execution path, which bypasses the security guarantees of reviewing the bundled artifact.

Attack Path

  1. An attacker compromises the npm publisher, a transitive dependency, or the relevant registry distribution path.
  2. The attacker publishes a package version accepted by ^10.7.1, o ...[truncated 1518 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package to an exact reviewed version:
    yaml
    package: torch-liquidation-bot@10.7.1
    
  2. Replace unversioned documentation examples with exact-version commands:
    bash
    npm install --save-exact torch-liquidation-bot@10.7.1
    npx --no-install torch-liquidation-bot
    
  3. Prefer invoking the bundled, reviewed entry point rather than downloading another artifact at runtime.
  4. Publish and verify package integrity hashes and use a committed lockfile with integrity metadata.
  5. Prevent implicit npx downloads by requiring prior installation and using --no-install.
  6. Consider npm install --ignore-scripts where the package's functionality does not require lifecycle scripts.
  7. Generate reproducible builds and verify that the npm tarball exactly corresponds to the reviewed source.
  8. Audit and pin all transitive dependencies, not only the top-level bot package.
  9. Run the bot under a dedicated low-privilege operating-system account with a minimal environment.
  10. Avoid supplying a vault authority key and retain the documented disposable-controller model to reduce consequences if the package chain is compromised.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (77)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A broader SDK surface than the narrow liquidation purpose described can be a real capability-disclosure problem in agent ecosystems. Even absent direct evidence of exploitation in SKILL.md, the mismatch matters because operators may trust the package based on the manifest while the underlying artifact can do more.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.