Back to skill

Security audit

synaptic-token-factory

Security checks for vulnerabilities and agentic risk

Overview

This skill is explicit about creating blockchain tokens, but it asks agents to perform live financial blockchain actions without enough risk warnings or confirmation guidance.

Review carefully before installing. Use only with explicit user confirmation, prefer a testnet or dry run first, and do not let an agent deploy, mint, or trade tokens unless wallet, fee, legal, and financial-risk handling are clearly understood.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill encourages users to deploy and initialize tokens on a live blockchain but does not warn about irreversible on-chain actions, financial loss, fees, key-management risk, or legal/compliance implications. In an agent context, this omission is more dangerous because automation can trigger real token creation and trading without adequate human confirmation or risk awareness.

Static analysis

No suspicious patterns detected.