Back to skill

Security audit

Switchboard Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Switchboard oracle work, but it asks users to route sensitive credentials, including a reusable Kalshi private key, through remote oracle workflows without enough scoping or disclosure.

Review before installing or using this skill for production. Keep it in read-only or plan-only mode unless you have explicit spend limits and allowlists. Do not put API keys in URLs, avoid sending reusable private keys into remote oracle jobs, prefer local signing or short-lived scoped credentials, and use pinned package versions in an isolated environment without wallet or production secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:762
Finding

Reusable Authentication Private Key Transmitted to Remote Oracle Infrastructure

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:120
Finding

Unpinned Third-Party and Global CLI Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The metadata description grants a very broad autonomous operational role across multiple chains and sensitive actions, but it does not define strict invocation boundaries or default-safe behavior at activation time. In an agent environment, this can cause overreach, where the skill is selected for requests that were not intended to authorize deployment, signing, or fund-moving workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The opening instructions describe the skill as an autonomous operator able to design, simulate, deploy, update, read, and integrate feeds and randomness, which is an unusually broad execution surface for an agent skill. Even though later sections add guardrails, the top-level framing can still bias orchestration toward high-privilege use without tight scoping, increasing the chance of unintended sensitive operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 469)May include surrounding context.

typescript
   {
     tasks: [
       { httpTask: { url: "https://api.example.com/price", method: "GET" } },
       { jsonParseTask: { path: "$.data.price" } },
       { multiplyTask: { big: "1e18" } }, // normalize to 18 decimals
     ]

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The example places an API key directly in the request URL query string, which commonly leaks through logs, browser history, proxies, analytics, and monitoring systems. Because this skill is intended for autonomous operation and feed simulation/deployment, normalizing URL-based secret placement can lead users to expose production credentials during automated runs.

Content

Scanner excerpt · SKILL.md (reported line 517)May include surrounding context.

md
const job = OracleJob.fromObject({
     tasks: [
       { httpTask: { url: "https://api.polygon.io/v2/last/trade/AAPL?apiKey=${POLYGON_API_KEY}" } },
       { jsonParseTask: { path: "$.results.p" } },
     ]
   });

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example again embeds a secret in the URL (?key=${API_KEY}), creating a credential leakage path via logs and intermediary infrastructure. In the context of job testing and repeated simulation, this is more dangerous because automated tooling often records full request URLs, increasing exposure of the secret over time.

Content

Scanner excerpt · SKILL.md (reported line 575)May include surrounding context.

md
function getCustomJob(): OracleJob {
  return OracleJob.fromObject({
    tasks: [
      { httpTask: { url: "https://api.example.com/data?key=${API_KEY}", method: "GET" } },
      { jsonParseTask: { path: "$.price" } },
    ]
  });

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 764)May include surrounding context.

md
{
     tasks: [{
       kalshiApiTask: {
         url: "https://api.elections.kalshi.com/v1/...",
         api_key_id: "${KALSHI_API_KEY_ID}",
         private_key: "${KALSHI_PRIVATE_KEY}",
       }

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1299)May include surrounding context.

md
#### DEX / DeFi Pricing

| Task                          | Description                            | Key Parameters                                                                                |
| ----------------------------- | -------------------------------------- | --------------------------------------------------------------------------------------------- |
| `jupiterSwapTask`             | Jupiter swap simulation                | `in_token_address`, `out_token_address`, `base_amount`, `slippage`                            |
| `uniswapExchangeRateTask`     | Uniswap swap price                     | `in_token_address`, `out_token_address`, `in_token_amount`, `slippage`, `provider`, `version` |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1309)May include surrounding context.

md
#### DEX / DeFi Pricing

| Task                          | Description                            | Key Parameters                                                                                |
| ----------------------------- | -------------------------------------- | --------------------------------------------------------------------------------------------- |
| `jupiterSwapTask`             | Jupiter swap simulation                | `in_token_address`, `out_token_address`, `base_amount`, `slippage`                            |
| `uniswapExchangeRateTask`     | Uniswap swap price                     | `in_token_address`, `out_token_address`, `in_token_amount`, `slippage`, `provider`, `version` |

Static analysis

No suspicious patterns detected.