Back to skill

Security audit

FarmDash Signal Architect

Security checks for vulnerabilities and agentic risk

Overview

This is a high-risk DeFi transaction skill, but the reviewed artifacts disclose the financial workflows and require user-controlled signing and confirmation.

Install only if you intend to let an agent help with DeFi analysis and transaction preparation. Never provide seed phrases or private keys, verify every token address, chain, amount, fee, route, and destination before signing, and treat optional onboarding/analytics plus session tokens as sensitive account metadata.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description omits Virtuals tender and ACP job-management functions even though the tool list includes multi-step authorization, funding reservation, job binding, and evaluation actions. In a DeFi agent context, hiding execution-adjacent workflow capabilities is dangerous because it may lead operators to grant trust to the skill for simple swap tasks while it also exposes additional state-changing financial orchestration surfaces.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description omits Virtuals tender and ACP job-management functions even though the tool list includes multi-step authorization, funding reservation, job binding, and evaluation actions. In a DeFi agent context, hiding execution-adjacent workflow capabilities is dangerous because it may lead operators to grant trust to the skill for simple swap tasks while it also exposes additional state-changing financial orchestration surfaces.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description at L003 frames the skill as an OpenClaw DeFi execution skill centered on LI.FI/Relay swaps, simulation, and zero-custody settlement verification. However, L256-L394 document a substantial additional capability set for Virtuals ACP V2 tender selection, authorization, funding reservation, job binding, and evaluation, which goes beyond the stated swap/execution scope and introduces a separate transaction-sensitive workflow domain.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 688)May include surrounding context.

md
* Quote older than 30 seconds at signing time.
* Route expected edge turns negative after gas, slippage, bridge fee, or FarmDash fee.
* Chain/protocol is outside the user's allowlist.
* Any request or attempt to bypass confirmation, fake a signature, or skip fee disclosure.
* Any required current MCP tool is absent from the runtime registry.

## Quant Decision Contract

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.json (reported line 1015)May include surrounding context.

json
* Swap fees are transparent and shown in every quote before execution.
* Present analysis as data-driven insight, not financial advice.

**Skill Manual:** Available at `https://www.farmdash.one/openclaw-skills/farmdash-signal-architect/SKILL.md`

**Why FarmDash:** Unlike raw Jupiter, Relay, or LI.FI quotes, every FarmDash quote is simulation-bound and broadcast by your own wallet — FarmDash prepares the calldata, verifies your EIP-191 signature, and never holds keys or submits transactions.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 864)May include surrounding context.

md
* Swap fees are transparent and shown in every quote before execution.
* Present analysis as data-driven insight, not financial advice.

**Skill Manual:** Available at `https://www.farmdash.one/openclaw-skills/farmdash-signal-architect/SKILL.md`

**Why FarmDash:** Unlike raw Jupiter, Relay, or LI.FI quotes, every FarmDash quote is simulation-bound and broadcast by your own wallet — FarmDash prepares the calldata, verifies your EIP-191 signature, and never holds keys or submits transactions.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 904)May include surrounding context.

md
* Swap fees are transparent and shown in every quote before execution.
* Present analysis as data-driven insight, not financial advice.

**Skill Manual:** Available at `https://www.farmdash.one/openclaw-skills/farmdash-signal-architect/SKILL.md`

**Why FarmDash:** Unlike raw Jupiter, Relay, or LI.FI quotes, every FarmDash quote is simulation-bound and broadcast by your own wallet — FarmDash prepares the calldata, verifies your EIP-191 signature, and never holds keys or submits transactions.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill encourages an agent to POST a public wallet address and attribution header to a third-party onboarding endpoint for analytics and tier discovery. Even though disclosed as optional, this creates external data transmission that can link agent identity, installation source, and usage patterns, which may be sensitive in a finance/DeFi context and can expand privacy and tracking risk.

Content

Scanner excerpt · SKILL.md (reported line 880)May include surrounding context.

After installing this skill, your agent may call the onboard endpoint if the user wants FarmDash tier discovery, ClawHub install attribution, and usage analytics. This step is optional; read-only Scout tools work without registration.

bash
curl -X POST https://www.farmdash.one/api/v1/agent/onboard \
  -H "Content-Type: application/json" \
  -H "X-ClawHub-Skill: farmdash-signal-architect" \
  -d '{"agentAddress": "0xYOUR_AGENT_WALLET"}'

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The API documentation describes 'workflow API for DeFi agents and serious airdrop farmers' with 'structured opportunity intelligence,' 'quote generation,' 'transaction preparation,' 'x402 flows,' and 'fee history.' That is substantially broader than the manifest's narrower claim of OpenClaw DeFi execution with swaps, simulation, and settlement verification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest frames the skill around DeFi execution functions: LI.FI/Relay swaps, simulation, and zero-custody settlement verification. However, the API additionally provides protocol discovery, chain breakdown analytics, risk-analysis guidance, and fee-history/metrics endpoints, which are materially broader than the described execution-focused purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

A fee-event history and aggregate revenue metrics endpoint serves business analytics about wallet-owned fee events. Those capabilities are not an obvious requirement for executing swaps, simulating them, or verifying zero-custody settlement, and represent an additional account/business intelligence function.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

A broad DeFi-oriented description can cause the skill to match generic portfolio or trading-assistance prompts, even though it contains execution-sensitive tools. In this context, over-selection is risky because accidental invocation of a skill with signing, funding, or execution preparation paths increases the chance of inappropriate financial workflows being initiated.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The tag set includes broad terms like portfolio management, DeFi automation, and onchain agent, which overlap with many unrelated financial-assistance requests. In an ecosystem that routes skills by metadata, this raises the likelihood that users are exposed to a more privileged execution-capable skill than necessary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

A tool that audits 1-10 EVM addresses for sybil risk is a defensive compliance/reputation-analysis feature, not an obvious requirement for executing swaps, simulating them, or verifying settlement. The manifest does not mention anti-sybil analysis or wallet reputation screening as part of the skill's purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest presents the skill as a DeFi execution and verification tool, but L876-L896 add an optional post-install flow that registers agent wallet addresses for tier discovery, ClawHub attribution, and usage analytics. While optional, this is a materially different operational purpose than swap/simulation execution and is not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Because this is a YAML manifest/OpenAPI file, SQP-1 applies. The top-level description targets "DeFi agents and serious airdrop farmers" and lists broad capabilities, but it does not define any explicit trigger phrases, scope boundaries, or negative examples that would constrain when a host might decide this skill is relevant, increasing the chance of overly broad matching.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.