Back to skill

Security audit

Solana Intelligence Solana智能分析

Security checks for vulnerabilities and agentic risk

Overview

The Solana analytics skill is mostly coherent, but it embeds a payment API key and sends wallet addresses to an external payment service without clear in-skill disclosure.

Review this skill before installing. The Solana analysis pieces are ordinary market-data tooling, but the package exposes a payment-service API key and can link a wallet address to use of the skill through SkillPay. Install only if you are comfortable with that payment flow and the publisher has rotated the exposed key and clearly documented what wallet data is sent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
payment.py:15
Finding

Hard-Coded Payment API Credential

Content
View full analysis
Remediation
View remediation

other

Warning
Location
payment.py:30
Finding

Undisclosed Transmission of User Wallet Identifiers

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/ecosystem_monitor.py:136
Finding

Predictable Temporary File Enables Symlink-Based File Overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A Solana intelligence skill that also performs payment verification, uses an embedded API key, and introduces billing logic through an external SkillPay API is a serious description-behavior mismatch. Hidden monetization and embedded credentials are dangerous because they can exfiltrate secrets, mislead users about the skill's real purpose, and create unauthorized external dependencies unrelated to the declared function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A Solana intelligence skill that also performs payment verification, uses an embedded API key, and introduces billing logic through an external SkillPay API is a serious description-behavior mismatch. Hidden monetization and embedded credentials are dangerous because they can exfiltrate secrets, mislead users about the skill's real purpose, and create unauthorized external dependencies unrelated to the declared function.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill declares no explicit tool scope or permission boundaries, yet the referenced capabilities imply access to environment data, file writing, and network operations. In an investment-analysis skill, undeclared powerful capabilities increase the risk of overreach, unexpected data access, or unauthorized outbound calls because neither users nor the platform can clearly constrain runtime behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest says the skill triggers whenever the user needs to analyze the Solana ecosystem, discover new projects, track opportunities, obtain market intelligence, or perform on-chain analysis. This covers a very wide range of ordinary crypto questions and does not define clear boundaries or exclusion conditions, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This manifest describes broad capabilities such as ecosystem analysis, new coin discovery, meme coin tracking, and investment opportunity identification, but it does not define when the skill should or should not activate. For manifest files, missing specificity on trigger scope or constraints is a vague-trigger issue because it can lead to unintended invocation in loosely related crypto conversations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is entirely in Chinese, which indicates a language-specific presentation without any visible opt-in or explanation that the skill is intended only for Chinese-speaking users. The policy requires that language or locale constraints be optional or clearly justified rather than implicitly enforced.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The file hardcodes a live API key for an external payment service, which is a direct secret exposure vulnerability. Anyone with access to the code can reuse the credential to query or abuse the SkillPay API, potentially impersonating the skill, accessing billing data, or incurring fraudulent activity against the account.

Content

Scanner excerpt · payment.py (reported line 15)May include surrounding context.

python
from datetime import datetime

# SkillPay API 配置
SKILLPAY_API_URL = "https://api.skillpay.io/v1"
SKILLPAY_API_KEY = "sk_f03aa8f8bbcf79f7aa11c112d904780f22e62add1464e3c41a79600a451eb1d2"
SKILL_SLUG = "shenmeng-solana-intelligence"
PRICE = "0.01"  # USDT

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code hardcodes configuration for SkillPay and a BNB Chain payment flow, which is not an obvious requirement for analyzing the Solana ecosystem or monitoring on-chain opportunities. Monetization infrastructure may be valid operationally, but it is not justified by the skill’s declared analytical purpose unless explicitly documented.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for Solana on-chain analysis, opportunity detection, meme trend tracking, and investment intelligence. This file instead implements paid access control by verifying payments with an external SkillPay service and presenting a payment flow on BNB Chain, which is a distinct product monetization function not described in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code transmits a user's wallet address and a timestamp to an external API, creating a privacy leak and linking user identity/activity to a third party. In a blockchain intelligence context, wallet addresses are especially sensitive because they can be correlated with on-chain behavior and profiling, and this file provides no user-facing notice or consent flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains all instructional content in Chinese and does not provide an opt-in, alternative language, or justification for restricting the skill reference to that locale. That can violate language/locale policy when users are not given a choice.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 8)May include surrounding context.

市场数据 (CoinGecko)

bash
# 获取 Solana 生态代币列表
curl "https://api.coingecko.com/api/v3/coins/markets?vs_currency=usd&category=solana-ecosystem&order=market_cap_desc&per_page=100&page=1"

# 获取特定代币数据
curl "https://api.coingecko.com/api/v3/coins/bonk"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 17)May include surrounding context.

DefiLlama API

bash
# Solana TVL
curl "https://api.llama.fi/chain/Solana"

# 协议 TVL
curl "https://api.llama.fi/protocols"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 20)May include surrounding context.

DefiLlama API

bash
# Solana TVL
curl "https://api.llama.fi/chain/Solana"

# 协议 TVL
curl "https://api.llama.fi/protocols"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and nowhere indicates that the skill is region- or language-specific or that users may choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 8)May include surrounding context.

md
def __init__(self):
        self.base_urls = {
            'defillama': 'https://api.llama.fi',
            'coingecko': 'https://api.coingecko.com/api/v3',
        }
    
    def get_tvl(self) -> Optional[Dict]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 11)May include surrounding context.

md
def __init__(self):
        self.base_urls = {
            'defillama': 'https://api.llama.fi',
            'coingecko': 'https://api.coingecko.com/api/v3',
        }
    
    def get_tvl(self) -> Optional[Dict]:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ecosystem_monitor.py (reported line 25)May include surrounding context.

python
def __init__(self):
        self.base_urls = {
            'defillama': 'https://api.llama.fi',
            'coingecko': 'https://api.coingecko.com/api/v3',
        }
    
    def get_tvl(self) -> Optional[Dict]:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing natural language exclusively in Chinese, including the module description and all report text, with no indication that language is configurable or that the skill is intended only for a Chinese-speaking or region-specific audience. That creates a locale-policy issue because the skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The phrase 'detect new opportunities on Solana' is open-ended and does not specify whether it refers to launchpad tokens, DeFi protocols, NFT activity, or other contexts. Without narrower scope, it can collide with general market-advice or research queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings and module descriptions in this file are presented in Chinese, including user-facing payment guidance, but there is no indication that users can opt into this language or select an alternative. That can violate language/locale policy when a specific language is imposed implicitly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest frames this skill as a Solana analysis, monitoring, and opportunity-detection tool. In addition to generating a report, the script persists collected market data to /tmp as JSON, which is a side effect not implied by the description's analytics-focused wording.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.