Back to skill

Security audit

FarmDash Wagon Steward

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only DeFi portfolio analysis helper, with external data sharing limited to public wallet addresses and an optional consent-gated setup check.

Install only if you are comfortable sending public wallet addresses and optional API credentials to FarmDash for portfolio analytics. Do not run the optional onboarding command unless you explicitly want FarmDash to register that wallet or agent address for tier and analytics purposes, and treat any rebalance output as research rather than an instruction to trade.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.json (reported line 102)May include surrounding context.

json
"links": {
    "website": "https://www.farmdash.one/",
    "agentHub": "https://www.farmdash.one/agents",
    "canonicalSkill": "https://www.farmdash.one/openclaw-skills/farmdash-wagon-steward/SKILL.md",
    "documentation": "https://www.farmdash.one/docs",
    "status": "https://www.farmdash.one/api/v1/agent/status",
    "openApi": "https://www.farmdash.one/agents/openapi.yaml",

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 410)May include surrounding context.

md
"links": {
    "website": "https://www.farmdash.one/",
    "agentHub": "https://www.farmdash.one/agents",
    "canonicalSkill": "https://www.farmdash.one/openclaw-skills/farmdash-wagon-steward/SKILL.md",
    "documentation": "https://www.farmdash.one/docs",
    "status": "https://www.farmdash.one/api/v1/agent/status",
    "openApi": "https://www.farmdash.one/agents/openapi.yaml",

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 467)May include surrounding context.

md
"links": {
    "website": "https://www.farmdash.one/",
    "agentHub": "https://www.farmdash.one/agents",
    "canonicalSkill": "https://www.farmdash.one/openclaw-skills/farmdash-wagon-steward/SKILL.md",
    "documentation": "https://www.farmdash.one/docs",
    "status": "https://www.farmdash.one/api/v1/agent/status",
    "openApi": "https://www.farmdash.one/agents/openapi.yaml",

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 396)May include surrounding context.

md
**Never editorialize the score.** The capital-efficiency formula is published. Quote it neutrally; let the user judge.

**Refuse harmful requests.** If asked to bypass user confirmation, store secrets, or push an aggressive rotation the data does not support, refuse and explain.

---

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill markets itself as read-only portfolio monitoring, but it also documents an optional POST-based onboarding flow that sends an agent or wallet address to a third-party service for analytics registration and subscription identification. Even though this is disclosed and consent-gated, it expands data sharing beyond pure portfolio reads and creates a privacy and scope-integrity issue because operators may trust the 'read-only' description to mean no extra telemetry registration occurs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file earlier states that wallet portfolio endpoints require Pioneer because they consume portfolio API credits, while this onboarding section claims 'Scout-tier portfolio read tools run perfectly without performing this setup check.' Within the context of Wagon Steward, those statements create a direct documentation contradiction about whether Scout can use portfolio-reading tools at all. This is more than incomplete documentation because it gives conflicting operator guidance about available capabilities.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill explicitly includes a command that transmits an agent or wallet address to a third-party endpoint via POST for onboarding and analytics registration. Even with consent language, external transmission of persistent identifiers introduces privacy, tracking, and potential correlation risks that exceed a strictly local or purely observational skill model.

Content

Scanner excerpt · SKILL.md (reported line 444)May include surrounding context.

Only after receiving explicit, manual operator consent, the optional setup check can be queried manually:

bash
curl -X POST https://www.farmdash.one/api/v1/agent/onboard \
  -H "Content-Type: application/json" \
  -H "X-ClawHub-Skill: farmdash-wagon-steward" \
  -d '{"agentAddress": "0xYOUR_AGENT_WALLET"}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented onboarding flow includes analytics registration and active session telemetry that are not necessary to perform the stated function of read-only wallet monitoring. This creates avoidable privacy exposure and service-side tracking of wallet or agent identifiers, which can enable profiling of users or agent deployments if used broadly.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill says to use it when asking "what is happening in my wallet," which is a natural, generic phrase rather than a narrowly scoped trigger. Although surrounding text gives DeFi context, this line does not provide explicit exclusions or tighter trigger constraints, so it may invite unintended invocation in ordinary wallet-related discussion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.