Back to skill

Security audit

Coinbase Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill openly targets Coinbase trading and crypto transfers, but it gives an agent powerful fund-moving authority without enough transaction-by-transaction safeguards.

Review this carefully before installing. Only use restricted Coinbase API keys, avoid transfer or withdrawal permissions unless absolutely necessary, set very low limits, and manually verify every asset, amount, fee, network, and destination before any trade or transfer.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly advertises autonomous trading and on-chain transfers but does not clearly warn about irreversible transactions, volatility, custody risk, wallet-address mistakes, or potential financial loss. In a crypto context, omission of these warnings is dangerous because users may treat the agent as low-risk automation and authorize actions that cannot be reversed once executed on-chain.

Static analysis

No suspicious patterns detected.