Back to skill

Security audit

31Third Safe Rebalancer

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its rebalancing purpose, but it needs review because it can submit financial transactions and its documentation, dependency lockfile, and execution behavior do not consistently describe what will run.

Review this before installing on a real Safe. Use read-only smoke and drift checks first, regenerate and verify the lockfile, confirm which ExecutorModule contract generation is supported, and only provide an executor wallet key with limited authority after understanding that planning data is sent to 31Third and execution can submit live transactions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
package-lock.json:2
Finding

Manifest and Lockfile Pin Different SDK Versions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/executor.ts:66
Finding

Execution Implementation Contradicts Documented Authorization and Allowance Safeguards

Content
View full analysis
{ void params.approvals; const request: Record = { address: params.executorModule, abi: executorModuleAbi, functionName: 'execute', args: [params.trades, params.config] }; if (params.account) { request.account = params.account; } await (params.publicClient as any).simulateContract(request); } ``` Transaction submission follows the same behavior: ```ts export async function executeTradeNow(params: { walletClient: WalletClient; executorModule: Address; ...[truncated 4773 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (36)

Known Vulnerable Dependency: vitest==2.1.9 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vitest==2.1.9 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk does not implement or expose a portfolio rebalancing assistant. It is strictly a test validating contract reference construction and the use of hardcoded addresses/ABIs for shared contracts. That is a materially different primary purpose from the declared description, and the declared description omits the hardcoded contract-wiring behavior shown here.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The supplied code chunk does not implement a portfolio rebalancing assistant. It defines unit/smoke tests for a separate smoke-check script, mocking configuration loading, viem client creation, policy snapshot reading, drift checking, and trade simulation. Its primary purpose is test validation of success/failure paths and output formatting. That is materially different from the declared purpose of a policy-aware Safe portfolio rebalancing assistant for an ExecutorModule.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description suggests an assistant or module that performs policy-aware safe portfolio rebalancing for the 31Third ExecutorModule. The supplied code chunk does not implement such an assistant; it is specifically a Vitest test file. Its behavior is limited to validating helper logic: passing baseEntries into a mocked calculateRebalancing SDK call and constructing base entries from token balances while filtering zero balances. There is no evidence of policy handling, assistant behavior, executor-module integration, or live rebalancing execution in this chunk. Therefore the code's actual purpose is materially different from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description suggests the skill itself is an operational assistant that performs policy-aware safe portfolio rebalancing via a 31Third ExecutorModule. The supplied code chunk does not implement such functionality directly. Instead, it is a unit test file for a CLI, mocking the underlying rebalancing functions and checking that commands are routed correctly and JSON string fields are parsed into bigint values. While the tested commands are related to rebalancing, the actual behavior of this code chunk is test infrastructure and CLI validation, which is materially different from the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description suggests an assistant that performs or supports policy-aware Safe portfolio rebalancing using the 31Third ExecutorModule. The supplied code chunk does not implement rebalancing, policy checks, executor actions, or assistant functionality. Instead, it is a narrow test file that validates contract reference construction and use of hardcoded addresses/ABIs. That is a materially different primary purpose from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description suggests a functional assistant that performs or supports policy-aware portfolio rebalancing for a Safe via the 31Third ExecutorModule. However, the supplied code chunk is only a test file. It constructs mock IO and config objects, invokes runSmoke with mocked dependencies, and asserts expected return codes and log output. It does not itself perform portfolio analysis, policy enforcement, trade planning, Safe execution, or module interaction. While the mocked names imply the surrounding project may relate to rebalancing, this specific chunk’s actual purpose is smoke-test validation, which is materially different from the declared primary purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Changing the authorized executor (setExecutor) and mutating the active policy set (addPolicy/removePolicy) are governance capabilities that materially alter who may trade and what constraints apply. Those powers are not an obvious requirement for a skill whose stated purpose is assisting Safe portfolio rebalancing.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.11 — 3 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.6 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: rollup==4.57.1 — 1 advisory(ies): CVE-2026-27606 (Rollup 4 has Arbitrary File Write via Path Traversal)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.18.3 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vite==5.4.21 — 3 advisory(ies): CVE-2026-39365 (Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling); CVE-2026-53571 (vite: `server.fs.deny` bypass on Windows alternate paths); CVE-2026-53632 (launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requests or relies on sensitive environment-provided capabilities, including an executor private key and API credentials, but does not declare any explicit tool scope or permissions boundary in the skill manifest. In an agent ecosystem, undeclared capability use weakens reviewability and increases the chance that secrets are exposed to components or execution paths users did not expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a 'Policy-aware Safe portfolio rebalancing assistant', which implies checking and executing rebalancing trades. However, the ABI also exposes administrative mutation functions such as addPolicy, removePolicy, setCooldown, and setExecutor, allowing the skill to reconfigure governance and execution controls rather than just assist with rebalancing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The ABI includes setCooldown(uint256), which changes the minimum time between successful executions. Adjusting protocol-level execution throttling is an administrative control-plane action, not a direct or necessary part of helping rebalance a portfolio.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The ABI exposes non-read administrative functions, specifically setFeed(address,address) and clearFeed(address), which allow mutation of token-to-price-feed mappings. For a skill described as a policy-aware portfolio rebalancing assistant, bundling feed-governance capabilities expands authority beyond stated scope and can enable incorrect or malicious pricing inputs if the skill or downstream agent is permitted to invoke them.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Including capability to alter token price-feed mappings is dangerous because portfolio rebalancing logic typically depends on trustworthy price data; changing feeds can distort valuations, trigger unsafe trades, or bypass policy controls that assume honest oracle configuration. In the context of a rebalancing assistant, this mismatch between declared purpose and available authority makes the capability more dangerous, since it can silently subvert core decision inputs rather than merely execute intended trades.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code provides rebalance-now and execute-rebalance commands that appear to trigger live portfolio rebalancing and trade execution, including a --force option, but the file contains no confirmation prompt, cautionary log, or explanatory warning before invoking those operations. For a code file, safety-critical execution paths that may change assets or system state should include some form of user disclosure unless the warning is clearly present elsewhere in the code being reviewed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function sends sensitive operational metadata including wallet/safe address, signer address, chain ID, target allocations, and portfolio base entries to a third-party API. In a security-sensitive Safe rebalancing skill, undisclosed off-platform transmission expands the trust boundary and can leak portfolio composition and operator identity to an external service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code depends on a remote API and API key despite the skill being described as a policy-aware rebalancing assistant, which could reasonably be expected to operate locally against onchain and policy data. This creates unnecessary credential handling and a remote dependency that can expose secrets or enable data exfiltration if the service or key management is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The external API call includes wallet and signer identifiers in the request payload without any evidence in this file of user-facing notice or consent. For an agent skill handling treasury/Safe operations, silent transmission of identity and holdings-related data is a meaningful privacy and operational security issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded external endpoint shows that the skill transmits data to a third-party service outside the local/onchain execution boundary. In the context of a Safe rebalancer, this is more sensitive because portfolio state and signer-associated metadata can reveal treasury strategy and enable profiling or targeted attacks if mishandled.

Content

Scanner excerpt · dist/src/balancer.js (reported line 184)May include surrounding context.

js
}
export async function planRebalancingWithSdk(input) {
    return calculateRebalancing({
        apiBaseUrl: 'https://api.31third.com/1.3',
        apiKey: input.apiKey,
        chainId: input.chainId,
        payload: {

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/index.js:297

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
index.ts:447