T09 · Insecure Skill Coding Practices
- Location
SKILL.md:139- Finding
Server-Supplied Solana Transaction Is Signed Without Local Validation
- Content
View full analysis
", "walletPublicKey": ""}' ``` Returns `{ transaction (base64), expectedSignature, tournamentInfo }`. **2. Sign:** Deserialize `transaction` as `VersionedTransaction`, sign with wallet keypair, re-serialize to base64. **3. Send signed transaction:** ```bash curl -X POST "https://tokendraft-production.up.railway.app/api/v2/buyIn/sendSignedTransaction" \ -H "Content-Type: application/json" \ -d '{ "signedTransactionBase64": "", "tournamentId": "", "expectedSignature": "", "walletPublicKey": "" }' ``` ``` ### Technical Analysis The remote TokenDraft API controls the serialized Solana transaction that the Skill instructs the Agent to sign. The instructions do not require the Agent to decode and validate the transaction before applying the wallet signature. In particular, the workflow does not verify: - The invoked Solana program IDs - The instruction types and instruction data - Recipient and destination accounts - The exact SOL or token amount transferred - The fee payer and required signer set - The selected Solana network - The relationship between the transaction and the requested tournament - The absence of additional or unrelated instructions - The expected post-transaction balance changes The API also supplies `expectedSignature`, so that field is not an independent integrity check. Verifying that the wallet has enough SOL for the advertised buy-in does not prove that the serialized transaction contains only that buy-in. This creat ...[truncated 1581 chars]- Remediation
View remediation
