Back to skill

Security audit

Torch Market

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Solana DeFi SDK skill, but it deserves user review because it can submit financial transactions and has under-scoped network and supply-chain risks.

Install only if you are comfortable with a DeFi skill that can build and submit real Solana transactions. Prefer read-only/build-only use unless needed, use a fresh disposable controller key rather than any vault authority or high-value wallet, restrict outbound network access where possible, and pin or avoid the optional npm install so reviewed code is what actually runs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
lib/torchsdk/tokens.js:354
Finding

Creator-Controlled Metadata URI Enables Server-Side Request Forgery

Content
View full analysis
controller.abort(), 10000); const res = await fetch(uri, { signal: controller.signal }).finally(() => clearTimeout(timer)); const data = (await res.json()); metadata = { description: data.description, image: data.image, twitter: data.twitter, telegram: data.telegram, website: data.website, }; } catch (e) { warnings.push(`Metadata fetch failed: ${e instanceof Error ? e.message : String(e)}`); } } ``` ### Technical Analysis The value of `bondingCurve.uri` is controlled by the token creator and stored on-chain. When `getToken()` is called, the SDK passes this value directly to `fetch()`. The implementation does not validate: - The URL scheme - The destination hostname - The resolved IP address - Whether the destination is loopback, link-local, or part of a private network - Redirect destinations - The response content type - The maximum response size The ten-second `AbortController` timeout reduces the duration of a slow request but does not prevent server-side request forgery. Redirects are followed by default, meaning an initially acceptable endpoint could redirect the request to an internal address. In Node.js or another server-side runtime, this behavior allows an attacker to cause requests from the Agent's network environment. Browser same-origin restrictions may limit some deployments, but they do not protect server-side execution. ### Attack Path 1. An attacker creates a Torch token. ...[truncated 1395 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:34
Finding

Mutable npm Version Range Expands the Audited Supply-Chain Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (59)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The simultaneous claims of 'No keepers' and documentation of permissionless maintenance/crank actions can create a dangerous mismatch in operational expectations. Even if these actions are permissionless rather than privileged, users and integrators may incorrectly assume there are no required maintenance dependencies or liveness assumptions affecting rewards, fee conversion, or protocol state progression.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file asserts a minimal admin surface, but it also introduces a new admin-only instruction, resolve_legacy_vote. Contradictory trust-signaling in security documentation is dangerous because operators and integrators may underestimate privileged capabilities and fail to review or monitor admin paths that can mutate protocol state.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · audit_sdk.md (reported line 375)May include surrounding context.

md
**Severity:** Low
**File:** `transactions.ts`
**Description:** Slippage values outside the 0.1%-10% range were silently clamped. A caller passing `slippage_bps: 5000` (50%) got 10% without any warning.
**Impact:** Unexpected slippage behavior. Not a fund safety issue — trades fail rather than execute at bad prices.
**Resolution:** Out-of-range `slippage_bps` values now throw an explicit error with the accepted range (10–1000 bps).

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest explicitly says 'No stored baselines,' but this module's own treasury-state comment says it returns 'baseline pool reserves captured at migration' and the function returns baseline_sol_reserves, baseline_token_reserves, and baseline_initialized. This is a direct contradiction between the stated product intent and what the code/documentation indicates the protocol stores and surfaces.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The protocol description explicitly claims 'no stored baselines,' yet the interface defines persistent baseline fields such as baseline_sol_reserves, baseline_token_reserves, and baseline_initialized in Treasury. This is a strong semantic contradiction that can cause downstream agents, users, or auditors to make unsafe assumptions about pricing, buyback logic, liquidation conditions, or manipulation resistance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest claims 'No oracles,' but the borrow flow explicitly depends on a Raydium pool for price calculation, which is still an external market-derived price source. If risk and liquidation logic rely on a manipulable on-chain pool price without robust TWAP/liquidity protections, attackers can temporarily move the pool price to over-borrow, evade liquidation, or force liquidations.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · lib/torchsdk/transactions.js (reported line 1401)May include surrounding context.

js
})))
            .instruction();
    };
    // Helper: build the swap instruction
    const buildSwapIx = async () => {
        return program.methods
            .swapFeesToSol(new anchor_1.BN(minimum_amount_out.toString()))

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares required environment variables and clearly depends on Solana RPC/network access, but it does not define an explicit tool scope such as permissions or allowed-tools. That creates an authorization/expectation gap where a host agent may grant broader capabilities than users anticipate, especially for a skill that can build and submit blockchain transactions when a private key is present.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document makes a categorical safety/architecture claim of 'No stored baselines' while also describing an SDK function that returns 'baseline pool reserves at migration' as treasury state. Contradictory risk-model documentation in a financial skill can mislead users about statefulness, manipulation resistance, and liquidation assumptions, which is dangerous even without direct code execution.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The risk-model narrative says there are no stored baseline values, but the treasury-state API explicitly advertises stored migration baseline reserves. This inconsistency can cause integrators to build faulty assumptions about the protocol's risk engine and trust model, which is especially sensitive in a lending/margin context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a token-margin market with depth-adaptive risk, treasury-backed lending, and short selling. This file’s documented behavior extends materially beyond that scope into frontend/API routes, an agent plugin, outbound SAID feedback/reputation integration, vault UX guidance, and message-board semantics, which are not obvious implementation details of an on-chain margin market.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The later guidance says 'There are no direct buys' and 'No direct buys,' yet the document also discusses frontend/API buy routes and a prior buildDirectBuyTransaction capability. While some of this is historical/plugin-specific context, the unconditional wording creates an intent mismatch by implying a universal platform property rather than a scoped agent-kit constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.