Back to skill

Security audit

Sui Opportunities Hunter

Security checks for vulnerabilities and agentic risk

Overview

This skill is an openly described Sui DeFi opportunity tool, but it also tells agents to autonomously execute real mainnet trades and report activity to a third-party service without enough user control.

Review this carefully before installing. Use it only in a read-only mode unless you explicitly want an agent to interact with Sui mainnet funds. Do not give it access to a primary wallet or private key; if testing execution at all, use a dedicated low-balance wallet, require manual approval for every transaction, and avoid sending wallet-linked details or strategy logs to the remote service unless you are comfortable with that disclosure.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:210
Finding

Autonomous Mainnet Trading Uses Wallet Authority Without Explicit Per-Transaction Authorization

Content
View full analysis
\ --module swap \ --function swap_exact_input \ --args \ --gas-budget 50000000 ``` ``` Related workflow instructions at `SKILL.md:288-306` state: ```markdown Repeat every 30 seconds: 1. **Scan** — `curl .../api/scan` to find fresh arbitrage + yield opportunities 2. **Get opportunities** — `curl .../api/opportunities` to see all available 3. **Research** — Use Brave Search to find additional opportunities 4. **Share** — POST any new discoveries to `/api/opportunities` 5. **Verdict** — Submit verdicts for opportunities that need analysis 6. **Execute or present** — If you have a wallet, execute approved trades. If not, present them to your human with actionable details. 7. **Log** — Log your activity to `/api/agent-logs` --- ## Rules - **NEVER** share your private key with anyone — it stays local - **ALWAYS** verify in at least 2 sources before submitting an opportunity - **ALWAYS** log actions to `/api/agent-logs` - **Mainnet only** — real prices, real data - **Max 10 SUI** per trade when executing autonomously ``` ### Technical Analysis The Skill treats access to a Sui CLI or private key as sufficient authorization to execute real mainnet transactions. Possession or technical availability of signing authority is not equivalent to user consent for a particular transaction. The instructions lack enforceable controls for: - Explicit user approval for each transaction. - Transaction simulat ...[truncated 2425 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:263
Finding

Mandatory Third-Party Telemetry Can Disclose Financial and Operational Information

Content
View full analysis
","status":"executed","tx_hash":""}' curl -X POST https://sui-opportunities-hunter.vercel.app/api/agent-logs \ -H "Content-Type: application/json" \ -d '{"action":"Trade executed","details":"Tx: , Profit: ~$X.XX","status":"success"}' ``` ``` The rule at `SKILL.md:304` further mandates: ```markdown - **ALWAYS** log actions to `/api/agent-logs` ``` ### Technical Analysis The Skill requires activity, discoveries, verdicts, execution status, transaction digests, estimated profits, and other broadly defined details to be sent to `sui-opportu ...[truncated 2880 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is presented as an opportunity scanner/research agent, but it also directs the agent to execute real Sui mainnet trades using a local wallet. That materially expands authority from information gathering to irreversible financial action, creating a dangerous capability mismatch that could cause loss of funds or unauthorized trading if the agent follows the instructions autonomously.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill encourages autonomous mainnet trade execution but does not provide a clear up-front warning that trades are financially risky and irreversible. Users may reasonably treat this as routine automation and expose funds to slippage, malicious pools, bad quotes, or simple strategy errors without informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions tell the agent to use local wallet access and Sui CLI calls backed by private keys, even though the skill's stated purpose is opportunity discovery and sharing. Giving a discovery agent the ability to spend from a local wallet unnecessarily increases blast radius and could let prompt-driven behavior trigger unauthorized on-chain transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill says discoveries are shared with a network and logs are sent to remote endpoints, but it does not clearly warn users that research artifacts, opportunity details, and action logs will be transmitted off-box and stored. This creates privacy and operational-security risk, especially if logs include sensitive strategy details, wallet-related context, or proprietary trading observations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This endpoint call sends data to an external service, which is expected for the skill's design, but still creates a real exfiltration channel to a third-party API. In context, the danger is not the GET request alone but the broader pattern of normalizing unsandboxed outbound communication without strong consent, validation, or data-minimization controls.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Get all opportunities

bash
curl https://sui-opportunities-hunter.vercel.app/api/opportunities

Get only approved opportunities

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This log submission sends operational details to a remote endpoint, including whether a wallet is available and specifics about discovered opportunities. Such telemetry can leak strategy, timing, and environment information to an external service, which is especially risky in a financial-trading context where data freshness and secrecy matter.

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

Also log it so the network knows:

bash
curl -X POST https://sui-opportunities-hunter.vercel.app/api/agent-logs \
  -H "Content-Type: application/json" \
  -d '{"action":"Opportunity presented to human","details":"SUI/USDC arb 2.1% — no wallet available for autonomous execution","status":"info"}'

Static analysis

No suspicious patterns detected.