Back to skill

Security audit

Zyfai Yield Automation

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent DeFi yield SDK skill, but it should be reviewed carefully because it can guide agents to move real crypto funds without strong transaction-risk and confirmation guardrails.

Review before installing in any wallet-enabled agent. Pin and lock dependencies, avoid raw private keys, prefer wallet/KMS signers with policy controls, and require explicit user approval for every deposit, withdrawal, strategy update, cross-chain setting, and on-chain registration. Users should understand deposits are real blockchain transactions and expose funds to smart contract, market, protocol, and strategy risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
skill.md:45
Finding

Unpinned Third-Party SDK Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 45-49
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

bash
npm install @zyfai/sdk viem

Latest version: @zyfai/sdk@0.2.54

Technical Analysis

The installation command does not pin either @zyfai/sdk or viem to an exact version. Although the documentation states that the latest Zyfai SDK version is 0.2.54, the command does not enforce that version. npm can therefore resolve a newer release at installation time.

Because the project contains only skill.md, no lockfile or integrity metadata is supplied to make dependency resolution reproducible. A future compromised, malicious, or incompatible package release could consequently be installed without any change to the reviewed skill.

This is particularly sensitive because the documented SDK is given access to wallet providers, SIWE signatures, API keys, wallet addresses, and potentially private-key-backed WalletClient objects. Code executed by a compromised dependency would run with the privileges of the Node.js process and could access data available to that process.

Attack Path

  1. An attacker compromises the npm account, publication pipeline, or package repository for one of the named dependencies.
  2. The attacker publishes a newer package version containing malicious runtime code or an npm lifecycle script.
  3. A user follows the documented unpinned npm install command.
  4. npm resolves and installs the attacker-controlled release.
  5. Malicious lifecycle code may execute during installation, or malicious SDK code may execute when imported or used.
  6. Depending on the host configuration, that code could inspect environment variables, API credentials, wallet configuration, accessible files, and signing interactions, then transmit collected data or manipulate transactions.

This is a conditional supply-chain exploitation path; the audit found no evidence ...[truncated 719 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin all direct dependencies to reviewed exact versions, for example:

    bash
    npm install --save-exact @zyfai/sdk@0.2.54 viem@REVIEWED_EXACT_VERSION
    
  2. Provide and commit a reviewed package-lock.json, then direct automated environments to use:

    bash
    npm ci
    
  3. Verify lockfile integrity and review dependency changes before upgrades. Use automated vulnerability and provenance checks, but do not permit unattended upgrades in wallet-signing environments.

  4. Disable lifecycle scripts during installation where package functionality permits:

    bash
    npm ci --ignore-scripts
    
  5. Run the SDK in a restricted process or container with minimal filesystem, network, and environment-variable access.

  6. Keep raw private keys out of the SDK process. Prefer a KMS, hardware wallet, or policy-controlled remote signer that requires explicit authorization and constrains destination addresses, assets, chains, and transaction values.

  7. Document the reviewed viem version alongside the SDK version and establish an explicit dependency-upgrade review procedure.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The deposit flow instructs agents to move assets on-chain into a yield strategy without an explicit warning that deposits are real blockchain transactions, may be irreversible once confirmed, and expose funds to DeFi/protocol/strategy risk. In an agent context, this increases the chance of users authorizing deposits without informed consent, especially since the skill emphasizes seamless onboarding and automation.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · skill.md (reported line 771)May include surrounding context.

md
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Static analysis

No suspicious patterns detected.