Back to skill

Security audit

Warren - On-Chain Website Deploy

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it claims, but it gives an agent wallet-signing authority for permanent on-chain deployments without enough safety gates around private keys, confirmations, and setup supply chain risk.

Only install this if you intend to let an agent deploy content to MegaETH testnet. Use a brand-new disposable testnet wallet with no real assets or reused keys, avoid the --private-key option, review the npm dependency before running setup.sh, and require an explicit confirmation for every deployment because content is public, immutable, and spends gas.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
setup.sh:6
Finding

Unpinned npm Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
deploy.js:301
Finding

Wallet Private Key Accepted Through Command-Line Arguments

Content
View full analysis
Wallet private key (or PRIVATE_KEY env) ``` ### Technical Analysis The CLI permits a wallet private key to be supplied using `--private-key`. Command-line arguments are not an appropriate secret-transport mechanism because they may be exposed through: - Shell command history. - Process inspection utilities and process metadata. - Debugging, monitoring, audit, or crash-collection systems. - Terminal logs and copied command transcripts. - Automation logs that record the invoked command. The environment-variable fallback avoids shell-history exposure but can still be exposed to same-user processes, child processes, diagnostics, or improperly configured CI logs. The command-line option is the more direct vulnerability because it places the complete key in process arguments. The audited code does not explicitly transmit or log the private key. It uses the key locally to construct an ethers wallet and sign blockchain transactions. The finding concerns local credential disclosure through the input channel. ### Attack Path 1. A user follows the documented interface and invokes the deployment command with `--private-key` followed by the wallet key. 2. The command, including the key, is retained in shell history or exposed through process-argument inspection while `deploy.js` is running. 3. Another local account with sufficient process visibility, malware running in the user's session, a monitoring agent, or an operator with access to collected logs retrieves the argument. 4. The attacker imports the disclosed private key into another wallet. 5. The attacker signs arbitrary transactions as the vi ...[truncated 812 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

Check leaderboard

bash
curl -s https://megawarren.xyz/api/stress-test/leaderboard | node -e "process.stdin.on('data',d=>console.log(JSON.parse(d)))"

Gas Costs

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · deploy.js (reported line 85)May include surrounding context.

js
// Inline ABIs & Bytecode (no external files needed)
// ============================================================================

const PAGE_BYTECODE = '0x60a0604052346100e45761025c80380380610019816100fc565b9283398101906020818303126100e4578051906001600160401b0382116100e4570181601f820112156100e4578051906001600160401b0382116100e85761006a601f8301601f19166020016100fc565b92828452602083830101116100e457815f9260208093018386015e8301015280518060401b6bfe61000180600a3d393df3000161fffe8211830152600b8101601583015ff09182156100d7575260805260405161013a908161012282396080518181816044015260d50152f35b63301164255f526004601cfd5b5f80fd5b634e487b7160e01b5f52604160045260245ffd5b6040519190601f01601f191682016001600160401b038111838210176100e85760405256fe6080806040526004361015610012575f80fd5b5f3560e01c9081634822da1c146100c357506357de26a414610032575f80fd5b346100bf575f3660031901126100bf577f00000000000000000000000000000000000000000000000000000000000000006020608060405180935f19813b0164ffffffffff16905f6021830191601f8501903c808252016040810193846040528385528051938491826060850152018383015e5f828483010152603f1992601f8019910116810103010190f35b5f80fd5b346100bf575f3660031901126100bf577f00000000000000000000000000000000000000000000000000000000000000006001600160a01b03168152602090f3fea2646970667358221220fe4f8a378a0b003d3e1438e45234630293b1a4f7cf94a9f28a4c2d2531789b9d64736f6c634300081a0033';

const PAGE_ABI = [{"type":"constructor","inputs":[{"name":"_content","type":"bytes","internalType":"bytes"}],"stateMutability":"nonpayable"}];

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill is user-invocable and clearly expects access to sensitive environment data via PRIVATE_KEY, but it declares no explicit tool scope or permission boundaries. That creates a real risk that an agent runtime may expose broader environment access than necessary, enabling secret use or leakage during deployment workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is marked user-invocable and described broadly as a deployment capability, with no clear trigger constraints limiting when it should activate or what confirmations are required before spending funds. In an agent setting, this can cause the skill to engage on vague website, file, or deployment requests and potentially initiate blockchain transactions using the user's wallet.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.