Back to skill

Security audit

Upgrade Cairo Contracts

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill about safely upgrading Cairo smart contracts, with no hidden execution behavior or agent-memory manipulation.

Installers should treat this as technical guidance for a high-impact smart-contract workflow: verify class hashes, restrict upgrade authority, use multisig or timelocks for valuable contracts, and test upgrades on a devnet before production.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Memory Manipulation

High
Category
Memory Poisoning
Content
### Storage compatibility

When replacing a class hash, existing storage is reinterpreted by the new class. Incompatible changes corrupt state:

- **Do not rename or remove** existing storage variables — the slot is derived from the variable name, so renaming makes old data inaccessible
- **Do not change the type** of existing storage variables
Confidence
90% confidence
Finding
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Static analysis

No suspicious patterns detected.