T08 · Insecure Dependencies
- Location
package-lock.json:2- Finding
Manifest and Lockfile Pin Different SDK Versions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its rebalancing purpose, but it needs review because it can submit financial transactions and its documentation, dependency lockfile, and execution behavior do not consistently describe what will run.
Review this before installing on a real Safe. Use read-only smoke and drift checks first, regenerate and verify the lockfile, confirm which ExecutorModule contract generation is supported, and only provide an executor wallet key with limited authority after understanding that planning data is sent to 31Third and execution can submit live transactions.
package-lock.json:2Manifest and Lockfile Pin Different SDK Versions
src/executor.ts:66Execution Implementation Contradicts Documented Authorization and Allowance Safeguards
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
The supplied code chunk does not implement or expose a portfolio rebalancing assistant. It is strictly a test validating contract reference construction and the use of hardcoded addresses/ABIs for shared contracts. That is a materially different primary purpose from the declared description, and the declared description omits the hardcoded contract-wiring behavior shown here.
The supplied code chunk does not implement a portfolio rebalancing assistant. It defines unit/smoke tests for a separate smoke-check script, mocking configuration loading, viem client creation, policy snapshot reading, drift checking, and trade simulation. Its primary purpose is test validation of success/failure paths and output formatting. That is materially different from the declared purpose of a policy-aware Safe portfolio rebalancing assistant for an ExecutorModule.
The declared description suggests an assistant or module that performs policy-aware safe portfolio rebalancing for the 31Third ExecutorModule. The supplied code chunk does not implement such an assistant; it is specifically a Vitest test file. Its behavior is limited to validating helper logic: passing baseEntries into a mocked calculateRebalancing SDK call and constructing base entries from token balances while filtering zero balances. There is no evidence of policy handling, assistant behavior, executor-module integration, or live rebalancing execution in this chunk. Therefore the code's actual purpose is materially different from the declared description.
The declared description suggests the skill itself is an operational assistant that performs policy-aware safe portfolio rebalancing via a 31Third ExecutorModule. The supplied code chunk does not implement such functionality directly. Instead, it is a unit test file for a CLI, mocking the underlying rebalancing functions and checking that commands are routed correctly and JSON string fields are parsed into bigint values. While the tested commands are related to rebalancing, the actual behavior of this code chunk is test infrastructure and CLI validation, which is materially different from the declared primary purpose.
The declared description suggests an assistant that performs or supports policy-aware Safe portfolio rebalancing using the 31Third ExecutorModule. The supplied code chunk does not implement rebalancing, policy checks, executor actions, or assistant functionality. Instead, it is a narrow test file that validates contract reference construction and use of hardcoded addresses/ABIs. That is a materially different primary purpose from the declared description.
The declared description suggests a functional assistant that performs or supports policy-aware portfolio rebalancing for a Safe via the 31Third ExecutorModule. However, the supplied code chunk is only a test file. It constructs mock IO and config objects, invokes runSmoke with mocked dependencies, and asserts expected return codes and log output. It does not itself perform portfolio analysis, policy enforcement, trade planning, Safe execution, or module interaction. While the mocked names imply the surrounding project may relate to rebalancing, this specific chunk’s actual purpose is smoke-test validation, which is materially different from the declared primary purpose.
Changing the authorized executor (setExecutor) and mutating the active policy set (addPolicy/removePolicy) are governance capabilities that materially alter who may trade and what constraints apply. Those powers are not an obvious requirement for a skill whose stated purpose is assisting Safe portfolio rebalancing.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
The skill requests or relies on sensitive environment-provided capabilities, including an executor private key and API credentials, but does not declare any explicit tool scope or permissions boundary in the skill manifest. In an agent ecosystem, undeclared capability use weakens reviewability and increases the chance that secrets are exposed to components or execution paths users did not expect.
The manifest describes a 'Policy-aware Safe portfolio rebalancing assistant', which implies checking and executing rebalancing trades. However, the ABI also exposes administrative mutation functions such as addPolicy, removePolicy, setCooldown, and setExecutor, allowing the skill to reconfigure governance and execution controls rather than just assist with rebalancing.
The ABI includes setCooldown(uint256), which changes the minimum time between successful executions. Adjusting protocol-level execution throttling is an administrative control-plane action, not a direct or necessary part of helping rebalance a portfolio.
The ABI exposes non-read administrative functions, specifically setFeed(address,address) and clearFeed(address), which allow mutation of token-to-price-feed mappings. For a skill described as a policy-aware portfolio rebalancing assistant, bundling feed-governance capabilities expands authority beyond stated scope and can enable incorrect or malicious pricing inputs if the skill or downstream agent is permitted to invoke them.
Including capability to alter token price-feed mappings is dangerous because portfolio rebalancing logic typically depends on trustworthy price data; changing feeds can distort valuations, trigger unsafe trades, or bypass policy controls that assume honest oracle configuration. In the context of a rebalancing assistant, this mismatch between declared purpose and available authority makes the capability more dangerous, since it can silently subvert core decision inputs rather than merely execute intended trades.
This code provides rebalance-now and execute-rebalance commands that appear to trigger live portfolio rebalancing and trade execution, including a --force option, but the file contains no confirmation prompt, cautionary log, or explanatory warning before invoking those operations. For a code file, safety-critical execution paths that may change assets or system state should include some form of user disclosure unless the warning is clearly present elsewhere in the code being reviewed.
The function sends sensitive operational metadata including wallet/safe address, signer address, chain ID, target allocations, and portfolio base entries to a third-party API. In a security-sensitive Safe rebalancing skill, undisclosed off-platform transmission expands the trust boundary and can leak portfolio composition and operator identity to an external service.
The code depends on a remote API and API key despite the skill being described as a policy-aware rebalancing assistant, which could reasonably be expected to operate locally against onchain and policy data. This creates unnecessary credential handling and a remote dependency that can expose secrets or enable data exfiltration if the service or key management is compromised.
The external API call includes wallet and signer identifiers in the request payload without any evidence in this file of user-facing notice or consent. For an agent skill handling treasury/Safe operations, silent transmission of identity and holdings-related data is a meaningful privacy and operational security issue.
The hardcoded external endpoint shows that the skill transmits data to a third-party service outside the local/onchain execution boundary. In the context of a Safe rebalancer, this is more sensitive because portfolio state and signer-associated metadata can reveal treasury strategy and enable profiling or targeted attacks if mishandled.
}
export async function planRebalancingWithSdk(input) {
return calculateRebalancing({
apiBaseUrl: 'https://api.31third.com/1.3',
apiKey: input.apiKey,
chainId: input.chainId,
payload: {
Detected: suspicious.exposed_secret_literal