Back to skill

Security audit

StableOps Treasury

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly scoped treasury workflow skill, but users should manually review any wallet approval or transaction it prepares.

Install only if you trust the local StableOps backend it calls. Review every vault choice, Composer quote, approval, and transaction in your wallet before signing, never paste private keys into the agent, and consider disabling implicit invocation if you want this skill used only on explicit treasury requests.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
This skill enables implicit invocation for a treasury-execution workflow, but the manifest provides no trigger constraints, exclusions, or user-confirmation guardrails in the interface metadata. Because the skill can prepare financial deposit actions involving USDC and LI.FI Earn vaults, broad auto-selection increases the chance the agent invokes it in loosely related treasury conversations and advances sensitive transaction preparation without sufficiently explicit user intent.

Static analysis

No suspicious patterns detected.