Back to skill

Security audit

Harvest Rewards

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only PancakeSwap reward checker, but it includes mandatory hidden telemetry and unpinned runtime package installation that users should review before installing.

Review this skill before installing. It does not appear to steal keys or execute wallet transactions, but it will contact third-party services with your wallet address, requires a background telemetry ping to pancakeswap.ai with host metadata, and may modify your Python environment by installing an unpinned dependency. Safer use would remove telemetry and preinstall pinned dependencies in an isolated environment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:66
Finding

Mandatory Host and Agent Telemetry Exceeds Least-Privilege Requirements

Content
View full analysis
/dev/null & ``` ### Technical Analysis The mandatory initialization request collects and transmits the AI agent identifier, invocation timestamp, operating-system name, and CPU architecture to `pancakeswap.ai`. These attributes are not necessary to query public blockchain state, calculate pending rewards, retrieve token prices, or generate PancakeSwap harvest links. The behavior therefore exceeds the minimum data access required for the Skill's declared functionality. The request is sent in the background while both its response and error output are discarded. This makes the telemetry less visible to the user and prevents normal review of server responses or transmission failures. The request does not transmit private keys, wallet seed phrases, authentication credentials, or arbitrary environment variables. Its confirmed scope is limited to the explicitly constructed query parameters and network metadata inherently available to the remote server, such as the source IP address. ### Attack Path 1. A user invokes the reward-harvesting Skill. 2. The Skill instructs the agent to execute the initialization command before performing reward discovery. 3. Local commands collect the current UTC time, operating-system name, and CPU architecture. 4. The collected values and configured agent identifier are inserted into an HTTPS query string. 5. The information is transmitted to `pancakeswap.ai`. 6. The remote service can associate the reported host characteristics and agent type with the source IP address and invocation time. 7. Repeated invocations could be correl ...[truncated 592 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/fetch-v3-pending.py:1
Finding

Unpinned Runtime Installation of the Requests Package in V3 Reward Scanner

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/fetch-infinity-pending.py:1
Finding

Unpinned Runtime Installation of the Requests Package in Infinity Reward Scanner

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/fetch-syrup-pending.py:1
Finding

Unpinned Runtime Installation of the Requests Package in Syrup Pool Scanner

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (39)

Tainted flow: 'rpc_url' from os.environ.get (line 66, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · references/fetch-infinity-pending.py (reported line 42)May include surrounding context.

python
'jsonrpc': '2.0', 'id': 1, 'method': 'eth_call',
        'params': [{'to': contract, 'data': data}, 'latest']
    }
    r = requests.post(rpc_url, json=payload, timeout=15)
    r.raise_for_status()
    result = r.json().get('result', '0x0')
    return int(result, 16)

Tainted flow: 'url' from os.environ.get (line 51, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The script sends the user's wallet address to an external PancakeSwap endpoint, disclosing wallet metadata and usage timing to a third party. In a crypto agent skill, this is security-relevant because wallet addresses are sensitive financial identifiers and the network call occurs automatically when the skill runs.

Content

Scanner excerpt · references/fetch-infinity-pending.py (reported line 53)May include surrounding context.

python
url = f'https://infinity.pancakeswap.com/farms/users/{CHAIN_ID}/{YOUR_ADDRESS}/{CURRENT_TS}'
try:
    r = requests.get(url, timeout=15)
    r.raise_for_status()
    data = r.json()
except Exception as e:

Tainted flow: 'data' from os.environ.get (line 55, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · references/fetch-syrup-pending.py (reported line 21)May include surrounding context.

python
return addr.lower().replace('0x', '').zfill(64)

def eth_call(to, data):
    r = requests.post(RPC, json={
        'jsonrpc': '2.0', 'id': 1, 'method': 'eth_call',
        'params': [{'to': to, 'data': data}, 'latest']
    }, timeout=15)

Tainted flow: 'RPC' from os.environ.get (line 29, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · references/fetch-v3-pending.py (reported line 34)May include surrounding context.

python
print(f'Chain: {CHAIN}')

def eth_call(to, data):
    r = requests.post(RPC, json={
        'jsonrpc': '2.0', 'id': 1, 'method': 'eth_call',
        'params': [{'to': to, 'data': data}, 'latest']
    }, timeout=15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description says the skill is for harvesting pending CAKE and partner-token rewards from PancakeSwap farming positions and Syrup Pools, including commands like '/harvest-rewards' and 'claim my Syrup Pool rewards'. The code does not submit any transaction or claim rewards at all; it only reads data and prints pending Infinity rewards. Its primary purpose is informational reporting for PancakeSwap Infinity farms, using an Infinity-specific API endpoint and a distributor contract's claimedAmounts mapping. This is materially different from harvesting/claiming general PancakeSwap farm or Syrup Pool rewards. Therefore the declared description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description says the skill can harvest/claim pending CAKE and partner-token rewards and respond to claim-oriented requests. The code is strictly read-only: it performs eth_call RPC queries to inspect staked V3 positions and pending CAKE, then prints results. There is no transaction construction, signing, or submission, so no harvesting occurs. Its scope is also narrower than declared: it targets MasterChef V3 positions on configured chains and queries only pendingCake, not partner-token rewards or Syrup Pool rewards. Additionally, it calls CoinGecko for USD pricing, which is an undeclared external resource. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

md
::: danger MANDATORY — Do NOT write your own Python script
Using `python3 -c "..."` causes SyntaxError (bash mangles `!` and `$`).
Using `curl | python3 << 'EOF'` causes JSONDecodeError (heredoc steals stdin).
You MUST follow the exact two-step process below. Do NOT improvise.
:::

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

md
::: danger MANDATORY — Do NOT write your own Python script
Using `python3 -c "..."` causes SyntaxError (bash mangles `!` and `$`).
Using `curl | python3 << 'EOF'` causes JSONDecodeError (heredoc steals stdin).
You MUST follow the exact two-step process below. Do NOT improvise.
:::

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
::: danger MANDATORY — Do NOT write your own Python script
Using `python3 -c "..."` causes SyntaxError (bash mangles `!` and `$`).
Using `curl | python3 << 'EOF'` causes JSONDecodeError (heredoc steals stdin).
You MUST follow the exact two-step process below. Do NOT improvise.
:::

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
After running the scans, compile all results into a single summary table.

::: danger MANDATORY OUTPUT RULE
**Every row in the rewards summary MUST include a deep link to the relevant harvest/claim page.** A row without a URL is INVALID.
:::

Lp1

High
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The script has shell capability through subprocess-based pip installation, but that capability is not declared in permissions. In an agent skill, undeclared shell execution materially increases risk because it enables local command execution and package installation beyond the user-visible purpose of checking pending rewards.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The script has shell capability through subprocess-based pip installation, but that capability is not declared in permissions. In an agent skill, undeclared shell execution materially increases risk because it enables local command execution and package installation beyond the user-visible purpose of checking pending rewards.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says the skill harvests pending CAKE and partner-token rewards, implying an on-chain state-changing claim action. In this file, the code performs read-only JSON-RPC eth_call queries and prints pending amounts and estimated USD values, with no transaction construction, signing, or submission to claim rewards.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation description goes beyond explicit commands and includes generic phrases like asking 'what they can harvest' and 'pending farming rewards'. In a manifest file, this is broad enough to overlap with normal conversation about rewards, making the invocation boundary unclear.

Content

No source excerpt is available for this finding.

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
allowed-tools: Read, Write, Edit, Glob, Grep, Bash(curl:*), Bash(jq:*),
  Bash(python3:*), Bash(node:*), WebFetch, WebSearch,
  Task(subagent_type:Explore), AskUserQuestion
model: sonnet
license: MIT
metadata:
  author: pancakeswap

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation says the skill only checks rewards and produces deep links, but the instructions later require a telemetry request. This inconsistency can mislead operators into approving or running the skill under a false assumption about network behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims to only inspect rewards and generate deep links, but Step 0 silently sends a telemetry ping to pancakeswap.ai containing agent identifier, timestamp, OS, and architecture. This is an unnecessary external transmission of environment metadata that users may not expect from a read-only reward-checking skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The initialization step performs analytics collection unrelated to the core task of reading pending rewards. Even if the data is limited to host metadata, it expands the data exposure surface and creates hidden network behavior in a skill that presents itself as a local/read-only assistant workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The initialization performs a background telemetry call without a clear user-facing warning, and it includes system metadata in query parameters. Hidden outbound requests are especially risky in agent skills because users and host environments may assume the skill only performs the explicitly requested blockchain/API lookups.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 291)May include surrounding context.

Fetch current CAKE price for USD conversion:

bash
curl -s 'https://api.coingecko.com/api/v3/simple/price?ids=pancakeswap-token&vs_currencies=usd' | \
  python3 -c "import json,sys; d=json.load(sys.stdin); print(d['pancakeswap-token']['usd'])"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatically installing a package at runtime without advance user warning introduces a software supply-chain risk and changes the host environment unexpectedly. In a skill ecosystem, users may reasonably expect read-only reward checking, not network package installation with local system modification.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The script invokes pip via subprocess at runtime to install requests if it is missing. This creates an unexpected code-execution and supply-chain surface, because package resolution and installation occur dynamically from the network without user approval or pinning, which is risky in an agent skill context.

Content

Scanner excerpt · references/fetch-infinity-pending.py (reported line 6)May include surrounding context.

python
import requests
except ImportError:
    import subprocess
    subprocess.check_call([sys.executable, '-m', 'pip', 'install', '-q', 'requests'])
    import requests

YOUR_ADDRESS = os.environ.get('YOUR_ADDRESS', '')

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill for harvesting pending CAKE and partner-token rewards from PancakeSwap farming positions, including Syrup Pool rewards. This file instead queries the Infinity rewards API endpoint and an Infinity distributor contract to compute pending rewards, with explicit chain support only for BSC and Base and messaging that says 'Infinity rewards', which is a materially different product/scope than the manifest description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest emphasizes harvesting and claiming rewards, but this code only fetches reward data from an HTTP endpoint, reads claimed amounts via eth_call, computes a pending balance, and prints a table. There is no transaction construction, wallet interaction, or state-changing contract call to collect rewards.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/fetch-infinity-pending.py (reported line 42)May include surrounding context.

python
'jsonrpc': '2.0', 'id': 1, 'method': 'eth_call',
        'params': [{'to': contract, 'data': data}, 'latest']
    }
    r = requests.post(rpc_url, json=payload, timeout=15)
    r.raise_for_status()
    result = r.json().get('result', '0x0')
    return int(result, 16)

Static analysis

No suspicious patterns detected.