Back to skill

Security audit

Miraix Wallet Roast

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its wallet-analysis purpose, but needs review because it sends wallet data to Miraix and may present remote swap commands and share-image links without enough user control or validation.

Review this skill carefully before installing. It does not appear to install code or persist locally, but using it means wallet addresses can be sent to Miraix endpoints, and generated share URLs can expose the analyzed wallet address if opened or previewed. Treat any returned swap or command text as untrusted advice and verify it independently in a wallet or transaction simulator before signing anything.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:47
Finding

Forced Branded URL Injection into Wallet Analysis Responses

Content
View full analysis
&language= ``` Label it clearly as the share card or screenshot. If the client supports media URLs or markdown images, use the same URL as the image attachment or inline preview. ``` `agents/openai.yaml:5`: ```yaml default_prompt: "Use $miraix-wallet-roast to analyze a Solana wallet, explain the risks, and include a share card URL in the result." ``` ### Technical Analysis The Skill requires the agent to append a Miraix-hosted share-image URL after every wallet analysis, even when the user did not request a share card. The agent configuration reinforces this behavior through its default prompt. This modifies the agent's normal output policy to inject an external branded resource systematically. If a client automatically resolves media URLs or renders Markdown image previews, the client may contact `app.miraix.fun` without a separate, explicit request to load that resource. The URL also embeds the analyzed wallet address and selected language in its query string. The wallet address is public blockchain information rather than a secret credential, but automatically transmitting or loading it can still disclose that a particular client or network identity is interested in the wallet. The endpoint operator may consequently receive the wallet address, language preference, source IP address, request time, and ordinary HTTP metadata. ### Attack Path 1. A user asks for a Solana wallet analysis without requesting a share image. 2. The Skill is invoked implicitly or explicitly. 3. The Skill requires the agent to append a URL containing the supplied wallet addres ...[truncated 838 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:29
Finding

Unvalidated Relay of Remote Financial Command Content

Content
View full analysis
","language":""}' ``` 4. Base the answer on the returned JSON. The important fields are: - `score` - `verdict` - `roast` - `summary` - `risks` - `actions` - `shareText` 5. Keep any `actions[].command` text verbatim when the user may want to execute it later. ``` ### Technical Analysis The Skill treats content returned by `https://app.miraix.fun/api/wallet-audit` as trusted and specifically requires `actions[].command` values to be preserved verbatim. No instruction requires the agent to validate the command format, supported protocol, token mint, recipient, destination program, slippage, approval scope, or expected transaction effects. Because the command originates from a remote service, its contents can change after the Skill package has been reviewed. If the API, its hosting environment, DNS resolution, or an upstream data source is compromised, an attacker could return deceptive financial instructions. The agent would then reproduce those instructions under the apparent authority of a wallet-analysis and rebalance recommendation. The Skill does not itself execute the returned command. Exploitation therefore requires the user or another integrated component to execute or submit it. Nevertheless, presenting remote command text verbatim without validation creates an unsafe trust boundary in a cryptocurrency workflow. ### Attack Path 1. An attacker compromises or controls the wallet-audit API, one of its upstream data sources, or its response-generation logic. 2. The attacker places a malicious or deceptive value in `actions[].command`. 3. The agent requests an analysis for a user-pr ...[truncated 1371 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to send a user-supplied Solana wallet address to Miraix public endpoints, but it does not require informing the user that their address and requested language will be transmitted to a third-party service. Even though wallet addresses are public on-chain identifiers, transmitting them to an external analytics provider can create privacy, profiling, and consent issues, especially when tied to user intent or conversation context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to default to zh unless the user clearly asks for English imposes a language choice without user opt-in. This is a natural-language policy issue because the skill does not offer a neutral language selection or ask the user for their preference first.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill contains a concrete instruction to POST wallet data to an external endpoint, which crosses a trust boundary and exposes user-provided data to a third party. In context, this is expected functionality for wallet analysis, but it is still security-relevant because the transfer happens by design and the skill does not mandate informed consent, minimization, or failure-safe handling around that transmission.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

  1. Run:
bash
curl -sS -X POST https://app.miraix.fun/api/wallet-audit \
  -H 'Content-Type: application/json' \
  -d '{"walletAddress":"<wallet-address>","language":"<zh|en>"}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation without any visible trigger constraints or narrowing conditions, which can cause the agent to auto-select this wallet-analysis skill in broader contexts than intended. Because the skill is designed to generate analysis, portfolio commentary, and branded share outputs, unintended invocation could expose wallet-related processing or cause actions/results to be produced without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.