Back to skill

Security audit

Node of COC testnet

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly describes a COC blockchain node management tool, including its local data writes, node process control, and data-deleting remove behavior.

Before installing, be aware this skill manages real local node processes and persistent node data. Use `--keep-data` when removing a node if you want to preserve on-disk state, and only use `--yes` when you intentionally want to skip an interactive confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This is a markdown file, so SQP-2 applies to whether the skill description warns about behaviors that could affect user data or system integrity. The node remove command notes that --keep-data preserves the data directory and that the default is delete, but it does not explicitly warn users that invoking removal without this flag can permanently delete on-disk node data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/cli.md (reported line 38)May include surrounding context.

md
Deregister a node.

- `--yes` — skip confirmation prompt
- `--keep-data` — preserve the data directory on disk (default: delete)

## `node config show [name]`

Static analysis

No suspicious patterns detected.