T09 · Insecure Skill Coding Practices
- Location
SKILL.md:762- Finding
Reusable Authentication Private Key Transmitted to Remote Oracle Infrastructure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent for Switchboard oracle work, but it asks users to route sensitive credentials, including a reusable Kalshi private key, through remote oracle workflows without enough scoping or disclosure.
Review before installing or using this skill for production. Keep it in read-only or plan-only mode unless you have explicit spend limits and allowlists. Do not put API keys in URLs, avoid sending reusable private keys into remote oracle jobs, prefer local signing or short-lived scoped credentials, and use pinned package versions in an isolated environment without wallet or production secrets.
SKILL.md:762Reusable Authentication Private Key Transmitted to Remote Oracle Infrastructure
SKILL.md:120Unpinned Third-Party and Global CLI Dependency Installation
The metadata description grants a very broad autonomous operational role across multiple chains and sensitive actions, but it does not define strict invocation boundaries or default-safe behavior at activation time. In an agent environment, this can cause overreach, where the skill is selected for requests that were not intended to authorize deployment, signing, or fund-moving workflows.
The opening instructions describe the skill as an autonomous operator able to design, simulate, deploy, update, read, and integrate feeds and randomness, which is an unusually broad execution surface for an agent skill. Even though later sections add guardrails, the top-level framing can still bias orchestration toward high-privilege use without tight scoping, increasing the chance of unintended sensitive operations.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
{
tasks: [
{ httpTask: { url: "https://api.example.com/price", method: "GET" } },
{ jsonParseTask: { path: "$.data.price" } },
{ multiplyTask: { big: "1e18" } }, // normalize to 18 decimals
]
The example places an API key directly in the request URL query string, which commonly leaks through logs, browser history, proxies, analytics, and monitoring systems. Because this skill is intended for autonomous operation and feed simulation/deployment, normalizing URL-based secret placement can lead users to expose production credentials during automated runs.
const job = OracleJob.fromObject({
tasks: [
{ httpTask: { url: "https://api.polygon.io/v2/last/trade/AAPL?apiKey=${POLYGON_API_KEY}" } },
{ jsonParseTask: { path: "$.results.p" } },
]
});
This example again embeds a secret in the URL (?key=${API_KEY}), creating a credential leakage path via logs and intermediary infrastructure. In the context of job testing and repeated simulation, this is more dangerous because automated tooling often records full request URLs, increasing exposure of the secret over time.
function getCustomJob(): OracleJob {
return OracleJob.fromObject({
tasks: [
{ httpTask: { url: "https://api.example.com/data?key=${API_KEY}", method: "GET" } },
{ jsonParseTask: { path: "$.price" } },
]
});
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
{
tasks: [{
kalshiApiTask: {
url: "https://api.elections.kalshi.com/v1/...",
api_key_id: "${KALSHI_API_KEY_ID}",
private_key: "${KALSHI_PRIVATE_KEY}",
}
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
#### DEX / DeFi Pricing
| Task | Description | Key Parameters |
| ----------------------------- | -------------------------------------- | --------------------------------------------------------------------------------------------- |
| `jupiterSwapTask` | Jupiter swap simulation | `in_token_address`, `out_token_address`, `base_amount`, `slippage` |
| `uniswapExchangeRateTask` | Uniswap swap price | `in_token_address`, `out_token_address`, `in_token_amount`, `slippage`, `provider`, `version` |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
#### DEX / DeFi Pricing
| Task | Description | Key Parameters |
| ----------------------------- | -------------------------------------- | --------------------------------------------------------------------------------------------- |
| `jupiterSwapTask` | Jupiter swap simulation | `in_token_address`, `out_token_address`, `base_amount`, `slippage` |
| `uniswapExchangeRateTask` | Uniswap swap price | `in_token_address`, `out_token_address`, `in_token_amount`, `slippage`, `provider`, `version` |
No suspicious patterns detected.