Back to skill

Security audit

Fund Wallet

Security checks for vulnerabilities and agentic risk

Overview

The skill is a mostly coherent wallet-funding guide, but it grants an unused account-information command and uses broad triggers that could invoke it in the wrong financial context.

Review before installing. The core workflow only displays wallet addresses and funding options, but the skill should ideally remove getMyInfo and require clearer confirmation that the user wants to fund a Finance District wallet before showing wallet details.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:6
Finding

Unnecessary Permission to Access User Information

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:6
Vulnerability Type: Excessive tool permission violating least privilege
Risk Level: Low

Vulnerable Code

yaml
allowed-tools: ["Bash(fdx status*)", "Bash(fdx call getWalletOverview*)", "Bash(fdx call getMyInfo*)"]

Technical Analysis

The skill permits invocation of fdx call getMyInfo*, although none of its documented funding workflows requires that command. Authentication checks use fdx status, while wallet-address and balance retrieval use fdx call getWalletOverview.

Granting getMyInfo* access therefore exceeds the minimum permissions needed to fund a wallet. The wildcard also permits any command-line suffix accepted by the tool policy and command. An erroneous instruction or malicious content influencing the agent could cause it to retrieve user-profile information unrelated to the requested funding task.

There is no evidence that this skill currently invokes the command or transmits its output externally. The finding is limited to unnecessary access capability, not confirmed data theft.

Attack Path

  1. A user invokes the wallet-funding skill.
  2. The agent receives permission to execute fdx call getMyInfo*.
  3. Malicious contextual content, prompt injection, or an agent error directs the agent to invoke that permitted command.
  4. The Finance District CLI returns user information that is unnecessary for wallet funding.
  5. The resulting information becomes exposed in the agent's execution context or command output.

Impact Assessment

Exploitation could disclose user-account or profile information returned by getMyInfo to the active agent session. The precise data scope depends on the Finance District API response and the authenticated user's privileges. The reviewed file provides no evidence that this permission enables privilege elevation, transaction execution, persistence, or external exfiltration.

Remediation
View remediation

Remediation Suggestions

Remove the unused getMyInfo capability and retain only commands required by the documented workflow:

yaml
allowed-tools: ["Bash(fdx status*)", "Bash(fdx call getWalletOverview*)"]

Additionally:

  1. Replace wildcard command permissions with exact argument patterns where the skill framework supports them.
  2. Review each future tool addition against a documented workflow requirement before granting access.
  3. Ensure outputs containing wallet or account information are displayed only when necessary and are not persisted or transmitted.
  4. Add a least-privilege review to skill maintenance and release checks.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description contains very broad trigger phrases such as 'how do I get funds?' and 'how do I add money?', which can overlap with many ordinary wallet or payment questions and cause the agent to invoke this skill in unintended contexts. Misrouting to a funding workflow can expose wallet addresses unnecessarily, confuse the user, or steer them toward financial actions they did not explicitly request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.