Back to skill

Security audit

Security Defense Line 安全防线

Security checks for vulnerabilities and agentic risk

Overview

This paid crypto-security skill needs Review because it advertises strong safety decisions while much of the analysis is simulated or hard-coded, and its billing code uses automatic charging with a hard-coded API key.

Install only if you treat it as a demo or toy, not as a source of wallet, contract, transaction, phishing, or incident-response truth. Before real use, require removal of mock/random security decisions, rotation and removal of the embedded billing key, explicit consent for every charge, and clear warnings for any asset-affecting workflow.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (8)

T09 · Insecure Skill Coding Practices

Error
Location
payment.py:11
Finding

Hard-Coded Billing API Credential

Content
View full analysis
Remediation
View remediation

other

Warning
Location
payment.py:48
Finding

User Identifier Disclosed During Automatic Billing

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/contract_auditor.py:68
Finding

Requested Contracts Are Replaced with Fixed Mock Source Code

Content
View full analysis
str: mock_code = ''' pragma solidity ^0.8.0; contract VulnerableContract { mapping(address => uint256) public balances; function withdraw() public { uint256 amount = balances[msg.sender]; require(amount > 0, "No balance"); (bool success, ) = msg.sender.call{value: amount}(""); require(success, "Transfer failed"); balances[msg.sender] = 0; } function isAuthorized() internal view returns (bool) { return tx.origin == owner; } } ''' return mock_code ``` The mock code is selected for address-based audits at `scripts/contract_auditor.py:203-208`: ```python if not code and address: code = self.fetch_contract_code(address, network) ``` ### Technical Analysis The submitted address and network are not used to retrieve deployed bytecode or verified source. Every address-based audit analyzes the same embedded vulnerable contract, after which the resulting findings are associated with the user-supplied address. This breaks the integrity of the primary advertised security function. ### Attack Path 1. A user submits a real contract address for review. 2. `fetch_contract_code()` ignores that address and returns fixed mock Solidity source. 3. Static analysis runs against the unrelated mock source. 4. The report labels the findings with the submitted address. 5. The user may act on findings that have no relationship to the deployed contract. ### Impact Assessment The flaw can create both false positives and false negatives. Vulnerable contracts may receive irrelevant results, while legitimate contracts may be falsely accused of containing vulnerabilities. Financial and deployment decisions based on the report may ther ...[truncated 20 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wallet_guardian.py:65
Finding

Wallet Security Findings Are Randomly Generated

Content
View full analysis
SecurityCheck: is_verified = random.random() < 0.7 ``` ```python def check_scam_reports(self, address: str) -> SecurityCheck: has_reports = random.random() < 0.1 ``` ```python def check_taint_analysis(self, address: str) -> SecurityCheck: is_tainted = random.random() < 0.05 ``` ```python def check_approvals(self, address: str) -> SecurityCheck: unlimited_approvals = random.randint(0, 3) ``` ```python def check_balance_diversity(self, address: str) -> SecurityCheck: token_count = random.randint(1, 20) ``` ### Technical Analysis Contract verification, scam reports, taint associations, unlimited approvals, and token holdings are produced by random-number generation rather than blockchain or threat-intelligence data. These values feed the reported security score and overall risk level. The same address can consequently receive contradictory reports on repeated executions. ### Attack Path 1. A user invokes a full wallet scan. 2. The scanner generates random values for material security properties. 3. The random findings are scored as if they were wallet-specific evidence. 4. The tool presents an authoritative security rating and recommendations. 5. The user may continue using a compromised wallet or distrust a safe wallet based on fabricated results. ### Impact Assessment A false safe result can expose all assets controlled by the evaluated wallet. False high-risk results can also cause unnecessary revocations, transfers, or operational disruption. The affected scope is the complete wallet-security decision made from the report. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tx_validator.py:180
Finding

Transaction Simulation Is Hard-Coded to Succeed

Content
View full analysis
TxCheckResult: simulated_success = True estimated_output = "1000 USDC" price_impact = 0.5 return TxCheckResult( check_name="Transaction simulation", passed=simulated_success, risk_level=RiskLevel.SAFE if simulated_success else RiskLevel.CRITICAL, details=f"Simulation succeeded, estimated output: {estimated_output}, price impact: {price_impact}%", recommendation="Verify transaction parameters" if not simulated_success else "None" ) ``` The result contributes to the final authorization decision at `scripts/tx_validator.py:272-278`: ```python 'can_proceed': overall_risk not in [RiskLevel.CRITICAL, RiskLevel.HIGH] ``` ### Technical Analysis No EVM, RPC, state-fork, or trace simulation occurs. Every transaction with calldata receives the same successful result, estimated output, and price impact. The fabricated pass is included in a final decision that can state the transaction is safe to proceed. ### Attack Path 1. An attacker prepares a transaction containing malicious calldata, such as an asset-draining call or dangerous approval. 2. The user passes the transaction to the validator. 3. `simulate_execution()` unconditionally returns success. 4. Other simplistic checks may not identify the malicious semantics. 5. The aggregate report sets `can_proceed` to true. 6. The user signs or broadcasts the harmful transaction. ### Impact Assessment Successful exploitation can result in token approval abuse, direct asset transfer, execution against the wrong chain or contract, transaction reversion, or severe financial loss. The validator itself does not sign transactions, but its false authorization can influence the user or an integ ...[truncated 26 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/multisig_manager.py:106
Finding

Multisig Confirmation Threshold Can Be Bypassed by Reusing One Signer

Content
View full analysis
Dict: if tx_id >= len(self.transactions): return {'success': False, 'error': 'Transaction does not exist'} tx = self.transactions[tx_id] if tx.status != TransactionStatus.PENDING: return {'success': False, 'error': 'Transaction is no longer pending'} if signer not in self.owners: return {'success': False, 'error': 'Signer is not a wallet owner'} tx.num_confirmations += 1 return { 'success': True, 'tx_id': tx_id, 'confirmations': tx.num_confirmations, 'threshold': self.threshold, 'ready_to_execute': tx.num_confirmations >= self.threshold } ``` Related access-control omissions also occur in `execute_transaction()`, `revoke_confirmation()`, `add_owner()`, and `remove_owner()` at `scripts/multisig_manager.py:136-224`. ### Technical Analysis The implementation stores only a numeric confirmation count. It does not record which owners confirmed a transaction, so the same listed owner can call `confirm_transaction()` repeatedly until the threshold is reached. No cryptographic signature is verified. The execution caller is not authenticated, revocation does not verify that the caller previously confirmed, and owner-management methods do not authenticate their `proposer` parameter. ### Attack Path 1. An attacker obtains the string value of any configured owner address. 2. The attacker repeatedly calls `confirm_transaction()` using that same address. 3. Each call increments `num_confirmations`. 4. The counter reaches the configured threshold without independent owners. 5. The attacker calls `execute_transaction()` using any executor value. 6. In an implementation connected to real assets, the transaction would bypass th ...[truncated 355 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/incident_responder.py:134
Finding

Emergency Freeze Reports Successful Containment Without Performing Actions

Content
View full analysis
Dict: actions = [ "Revoke all token approvals", "Cancel pending transactions", "Notify exchanges to monitor the wallet", "Enable multisig emergency mode" ] for action in actions: logger.info(f"Completed: {action}") return { 'success': True, 'wallet': wallet_address, 'actions_taken': actions, 'timestamp': datetime.now().isoformat() } ``` ### Technical Analysis The function performs no blockchain transaction, wallet operation, exchange notification, or multisig configuration change. It only logs action descriptions and then returns `success: True`. This creates a dangerous discrepancy between the function’s reported state and actual containment. ### Attack Path 1. A wallet compromise or suspicious transfer is detected. 2. The user invokes the documented emergency-freeze operation. 3. The function logs each intended response action as completed. 4. The function returns a successful result. 5. No approval is revoked and no transaction is cancelled. 6. The attacker retains access and can continue draining assets while the user believes the incident is contained. ### Impact Assessment False containment can delay real response during a time-critical asset compromise. The potential scope includes all assets and approvals associated with the affected wallet. The current function does not itself obtain privileges or modify assets. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/phishing_detector.py:122
Finding

Phishing Detector Equates an HTTPS Prefix with Certificate Safety

Content
View full analysis
ThreatCheck: has_ssl = url.startswith('https://') return ThreatCheck( check_name="SSL certificate check", threat_type=ThreatType.SAFE if has_ssl else ThreatType.SUSPICIOUS, confidence=0.5 if not has_ssl else 0.0, details="HTTPS encryption is present" if has_ssl else "HTTPS encryption is absent", indicators=[] if has_ssl else ["No SSL encryption"] ) ``` The affirmative recommendation is generated at `scripts/phishing_detector.py:275-285`: ```python recommendations = { ThreatType.SAFE: "Website is safe and may be visited", ThreatType.SUSPICIOUS: "Suspicious indicators found; proceed cautiously", ThreatType.PHISHING: "Possible phishing site; do not visit or enter information", ThreatType.MALWARE: "Malware detected; leave immediately", ThreatType.SCAM: "Possible scam site; do not conduct transactions" } ``` ### Technical Analysis The certificate check validates only that the raw string begins with `https://`. It does not establish a connection, validate a certificate chain, inspect certificate names, process redirects, or check revocation. The remaining checks are limited local heuristics. Page content is not fetched by the CLI, and domain age is guessed from substrings. A site without recognized patterns can therefore receive an affirmative “safe” recommendation. ### Attack Path 1. An attacker hosts a phishing page on an HTTPS-enabled domain. 2. The domain avoids the small set of brand and suspicious-TLD patterns. 3. The page avoids the static phrases inspected by the tool. 4. The HTTPS-prefix check returns safe without certificate validation. 5. The aggregate result contains no recognized threat. 6. The user is told that the site is safe a ...[truncated 337 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (36)

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · payment.py (reported line 29)May include surrounding context.

python
def check_balance(user_id: str) -> float:
    """查询用户余额"""
    try:
        resp = requests.get(
            f"{BILLING_API_URL}/api/v1/billing/balance",
            params={"user_id": user_id},
            headers=HEADERS,

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The code automatically charges a user by sending an environment-sourced user_id to an external billing API without explicit user confirmation or strong binding between the current user/session and that identifier. If an attacker can influence SKILLPAY_USER_ID or trigger this code path, they may cause unauthorized charges, account mix-ups, or billing abuse.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

Tainted flow: 'user_id' from os.environ.get (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description frames the skill as a comprehensive security system, while the underlying behavior reportedly uses simulated or randomized checks instead of real security data and does not implement several advertised controls. That creates a false sense of assurance in a high-risk domain involving wallets, contracts, and transactions, where inaccurate results can directly influence unsafe user decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description frames the skill as a comprehensive security system, while the underlying behavior reportedly uses simulated or randomized checks instead of real security data and does not implement several advertised controls. That creates a false sense of assurance in a high-risk domain involving wallets, contracts, and transactions, where inaccurate results can directly influence unsafe user decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description frames the skill as a comprehensive security system, while the underlying behavior reportedly uses simulated or randomized checks instead of real security data and does not implement several advertised controls. That creates a false sense of assurance in a high-risk domain involving wallets, contracts, and transactions, where inaccurate results can directly influence unsafe user decisions.

Content

No source excerpt is available for this finding.

YARA rule 'offensive_tool_references': References to well-known offensive security tools [hacktools]

High
Category
YARA Match
Confidence
70% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

wallet 0x... --status

发起交易

python scripts/multisig_manager.py --wallet 0x... --propose --to 0x... --value 1.0

签名交易

python scripts/multisig_manager.py --wallet 0x... --sign --tx-id 1

执行交易

python scripts/multisig_manager.py --wallet 0x... --execute --tx-id 1

管理成员

python scripts/multisig_manager.py --wallet 0x... --add-owner 0x...

text

### scripts/incident_responder.py
安全事件响应器

```bash
# 紧急冻结
python scripts/incident_responder.py --emergency-freeze --wallet 0x...

# 事件分析
python scripts/incident_responder.py --analyze --tx-hash 0x...

# 损失评估
python scripts/incident_responder.py --assess-loss --address 0x...

# 生成报告
python scripts/incident_responder.py --generate-report --incident-id 1

scripts/security_monitor.py

安全监控中心

bash
# 启动监控
python scripts/security_monitor.py --daemon

# 监控特定地址
python scripts/security_monitor.py --watch 0x... --events all

# 监控合�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file is entirely focused on billing enforcement despite the skill being presented as a security-defense tool. This mismatch is dangerous because it conceals unrelated monetization logic inside a trust-sensitive security skill, increasing the likelihood of deceptive deployment and reducing informed consent for operators and users.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

verify_payment immediately invokes charge_user, meaning a charge attempt occurs automatically at skill start before any explicit warning or consent. In a security-focused skill, this is especially risky because users may trust the tool during urgent incidents and be billed without informed authorization.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The audit workflow accepts a real contract address and emits an audit report for that address, but if no code is provided it analyzes the hard-coded mock contract instead. In this security context, the mismatch can directly produce false audit conclusions for arbitrary contracts, which is especially dangerous because the tool presents itself as a defense/auditing system.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

revoke_confirmation decrements the aggregate confirmation count without tracking which owners actually confirmed and without verifying that the supplied signer previously approved the transaction. In a multisig context this breaks authorization integrity: any caller who can reach this method can arbitrarily reduce approvals, potentially blocking legitimate execution or manipulating transaction state.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

add_owner and remove_owner directly mutate the owner set immediately, despite presenting themselves as multisig administration functions and accepting a proposer parameter that is never enforced. In a security tool for multisig wallet management, this effectively bypasses multisignature governance and would allow unauthorized takeover, lockout, or weakening of wallet control if exposed in real operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These functions present themselves as security checks but generate outcomes using random values rather than real on-chain, reputation, or approval data. In a wallet-security skill, fabricated results can directly mislead users into trusting malicious addresses or distrusting safe ones, creating dangerous false negatives and false positives.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The scan workflow aggregates and reports a 'security score' and 'overall risk' as if they were meaningful security conclusions, but for full scans those conclusions are largely derived from random mock checks. Because this skill is explicitly positioned as a defensive wallet-security tool, users may act on unreliable results and expose funds to theft, scams, or incorrect incident response.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and documents capabilities that imply network access, environment-variable use, and file/output side effects, yet it declares no explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can cause overbroad runtime access, making it harder to constrain billing, monitoring, or transaction-related actions and increasing the blast radius if the skill is misused or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents high-impact operations such as revoking approvals, executing multisig actions, emergency freezing, and daemonized monitoring without clear upfront warning, confirmation, rollback, or dry-run guidance. In a crypto/security context, these actions can affect asset control or service availability, so weak safety UX materially increases the chance of accidental or socially engineered misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The top-level natural-language description is written as 自动集成付费验证功能 with no indication that users may choose their preferred language or locale. This can violate language/locale policy when the skill imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The code transmits billing-related user data to an external service during a charge operation. External transmission itself is expected for payment processing, but here it is more dangerous because it is hidden inside a security skill and coupled with automatic charging, creating privacy and trust risks.

Content

Scanner excerpt · payment.py (reported line 48)May include surrounding context.

python
返回: {"ok": bool, "balance": float, "payment_url": str|None}
    """
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/charge",
            headers=HEADERS,
            json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The payment-link generation sends user billing data to an external provider. While common in payment integrations, in this skill context it is an undocumented external disclosure unrelated to the declared security-defense purpose, which makes it a meaningful trust and privacy concern.

Content

Scanner excerpt · payment.py (reported line 79)May include surrounding context.

python
def get_payment_link(user_id: str, amount: float = 5.0) -> str:
    """生成充值链接"""
    try:
        resp = requests.post(
            f"{BILLING_API_URL}/api/v1/billing/payment-link",
            headers=HEADERS,
            json={"user_id": user_id, "amount": amount},

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill reads billing identity from an environment variable even though its declared purpose is security defense, not payments. In this context, that hidden dependency enables silent identity coupling, potential account confusion, and unexpected data disclosure to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains user-facing natural language such as the module description and later console output exclusively in Chinese. Because the skill does not provide any opt-in or language selection mechanism, it effectively forces a specific language/locale on users, which matches the policy-violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function is documented and parameterized as if it retrieves contract source for a supplied address/network, but it always returns embedded mock code. In a smart-contract security skill, this creates a deceptive analysis path where users may believe a real target was audited when in fact results are unrelated, leading to unsafe decisions based on false assurance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The logger messages, printed report headings, field labels, and completion notices are all hard-coded in Chinese. This is a natural-language locale restriction in operational output, and the file does not offer an alternative language or any explicit user choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The demo states it is auditing the example address, but it actually exercises the embedded sample contract path. While likely intended as a demonstration convenience, it conditions users to trust address-based output that is not tied to the target contract, reinforcing the misleading behavior of the main audit flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code contains natural-language strings, comments, and docstrings such as the module description and all printed/logged messages in Chinese only. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.