Back to skill

Security audit

Miraix LI.FI Earn Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for crypto vault deposits, but it can guide real wallet approvals and deposits without a mandatory final transaction-specific confirmation step.

Review carefully before installing. Use it only if you trust Miraix and LI.FI Earn for vault discovery and quotes, and configure your agent or wallet flow to require explicit confirmation for every approval and deposit with the exact amount, chain, vault, token, spender address, and expected receipt token shown before signing.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to execute approval and deposit transactions once the user 'wants to execute now', but it does not require an explicit, transaction-specific confirmation immediately before on-chain actions. Because token approvals and deposits can move funds or grant spending rights, an agent following this skill could perform irreversible wallet actions based on ambiguous intent or stale context.

Static analysis

No suspicious patterns detected.