Back to skill

Security audit

erc-8004-development

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent documentation for ERC-8004 development, but it directs users toward wallet-signing, on-chain writes, public metadata publication, and an unpinned SDK install with incomplete safety framing.

Review this skill carefully before installing. Use pinned and reviewed SDK versions, prefer testnet or hardware/scoped signers, never put private keys or JWTs in frontend code, verify every chain/recipient/URI before signing, and avoid publishing session IDs, confidential task details, or sensitive payment context in feedback files or semantic search queries.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:58
Finding

Unpinned Security-Sensitive Third-Party SDK Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:58-60; duplicated in references/sdk-typescript.md:12-18
Vulnerability Type: Unpinned third-party dependency and supply-chain exposure
Risk Level: Medium

Vulnerable Code

SKILL.md:58-60:

bash
npm install agent0-sdk

references/sdk-typescript.md:12-18:

bash
npm install agent0-sdk
text
Runtime dependencies: `viem ^2.37.5`, `graphql-request ^6.1.0`, `ipfs-http-client ^60.0.1`

Technical Analysis

The installation instructions do not pin agent0-sdk to an exact reviewed version or provide a lockfile or integrity hash. Running the documented command resolves the package version from npm at installation time, so the code installed by users can differ from the version reviewed when this Skill was authored.

This dependency is especially security-sensitive because subsequent examples give the SDK access to a wallet private key, a Pinata JWT, RPC configuration, and transaction-signing operations. A compromised publisher account, malicious upstream release, dependency-confusion event, or compromised transitive dependency could therefore run with access to valuable credentials and signing authority. npm lifecycle scripts may also execute during installation.

No evidence establishes that the current package is malicious. The vulnerability is the non-reproducible and insufficiently constrained supply-chain trust boundary.

Attack Path

  1. An attacker compromises the agent0-sdk npm publisher, package distribution channel, or a transitive dependency.
  2. The attacker publishes a malicious version under the legitimate package name.
  3. A user follows the documented unpinned npm install agent0-sdk command.
  4. npm retrieves the attacker-controlled release and may execute its installation lifecycle scripts.
  5. The user initializes the package with PRIVATE_KEY, PINATA_JWT, or a browser wallet provider.
  6. Malicious pack ...[truncated 916 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact reviewed version, for example:

    bash
    npm install --save-exact agent0-sdk@1.5.3
    
  2. Distribute a reviewed lockfile and instruct users to install with npm ci rather than dynamically resolving dependency versions.

  3. Verify package integrity and provenance, including npm provenance attestations and expected registry ownership.

  4. Audit the package and its transitive dependencies before supplying wallet or storage credentials.

  5. Where compatible, initially install with lifecycle scripts disabled:

    bash
    npm ci --ignore-scripts
    
  6. Prefer browser or hardware-wallet signing so the SDK never receives a raw mainnet private key.

  7. Use dedicated, low-value testnet keys during development and narrowly scoped credentials for IPFS providers.

  8. Add dependency update review and automated supply-chain scanning before changing the pinned version.

T09 · Insecure Skill Coding Practices

Warning
Location
references/reputation.md:117
Finding

Potential Disclosure of Sensitive Session and Payment Metadata Through Public Feedback Files

Content
View full analysis

Vulnerability Details

File Location: references/reputation.md:117-132; related examples in SKILL.md:126-139, references/sdk-typescript.md:324-350, and schema guidance in references/spec.md:225-248
Vulnerability Type: Unsafe publication of potentially sensitive metadata
Risk Level: Medium

Vulnerable Code

references/reputation.md:117-132:

typescript
// Full with off-chain file
const feedbackFile = await sdk.prepareFeedbackFile({
  text: 'Accurate market analysis with fast response times',
  capability: 'tools',          // MCP capability type
  name: 'financial_analyzer',   // MCP tool name
  skill: 'trading_analysis',    // A2A skill
  task: 'analyze_portfolio',    // A2A task
  context: { sessionId: 'abc', duration: 1200 },
  proofOfPayment: {
    txHash: '0x...', chainId: '8453',
    fromAddress: '0x...', toAddress: '0x...',
  },
});

const tx = await sdk.giveFeedback('84532:42', 85, 'starred', '', '', feedbackFile);
await tx.waitConfirmed();

The documented feedback-file schema in references/reputation.md:48-77 also includes linkable identity and interaction data:

json
{
  "clientAddress": "eip155:8453:0xReviewerAddress",
  "endpoint": "https://mcp.agent.example.com",
  "a2a": {
    "skills": ["trading_analysis"],
    "contextId": "ctx-123",
    "taskId": "task-456"
  },
  "proofOfPayment": {
    "fromAddress": "0xReviewer...",
    "toAddress": "0xAgent...",
    "chainId": "8453",
    "txHash": "0xPaymentTx..."
  }
}

Technical Analysis

The Skill explains that rich feedback files can be uploaded to IPFS or made available over HTTPS, with their URI or hash referenced by an on-chain event and indexed by subgraphs. The examples encourage inclusion of a session identifier, context and task identifiers, endpoint information, wallet addresses, and a payment transaction hash without prominently warning that these values can become ...[truncated 2495 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add a prominent warning immediately before all registration and feedback publication examples explaining that IPFS content, blockchain events, and indexed data are public and effectively permanent.
  2. Explicitly prohibit publishing:
    • Authentication tokens or bearer session IDs.
    • Private keys, API keys, JWTs, or cookies.
    • Personal data and confidential task content.
    • Internal-only endpoint information.
  3. Remove sessionId from the default example. If correlation is required, use a non-secret, one-time identifier or a domain-separated salted hash that cannot be reversed or reused for authentication.
  4. Make proofOfPayment opt-in and explain that it links the reviewer, recipient, transaction, agent, and interaction context.
  5. Minimize feedback files to the fields strictly required for the reputation claim.
  6. Require explicit user confirmation showing the exact serialized document before uploading it or referencing it on-chain.
  7. Add schema-level validation that rejects fields resembling private keys, JWTs, access tokens, cookies, or high-entropy session credentials.
  8. Recommend encrypted, access-controlled storage when interaction details must remain confidential; only a non-sensitive commitment or hash should be published.
  9. Explain that revocation does not delete content already stored by IPFS peers, gateways, blockchains, indexers, or archival services.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation encourages storing and publishing reviewer-linked feedback metadata including clientAddress, endpoint details, timestamps, context/task identifiers, skills, domains, and proof-of-payment fields, but it does not warn that this creates a public, linkable activity graph. In an on-chain reputation system, these identifiers can deanonymize reviewers, reveal business relationships, and expose sensitive operational or financial metadata that is difficult or impossible to retract once published or hashed on-chain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly shows use of sensitive credentials such as a raw private key, Pinata JWT, and Filecoin private key in SDK initialization without any adjacent warning about secure storage, server-only usage, or the risk of embedding secrets in client code. In a blockchain/agent SDK context, this can directly lead developers to hardcode or mishandle signing and storage credentials, enabling wallet compromise, unauthorized registrations, or abuse of IPFS pinning accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The registration workflow documents minting, URI updates, and agent transfer operations without prominently warning that these are real blockchain writes that may incur fees and can be difficult or impossible to reverse once confirmed. In this skill's context, users are specifically interacting with on-chain agent identity and ownership, so lack of transaction-risk warnings increases the chance of accidental permanent state changes or transfers to the wrong address.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly states that semantic search sends user-provided keywords to an external service (semantic-search.ag0.xyz). Search terms can contain sensitive business intent, wallet-related investigations, or internal investigative queries, and the lack of any privacy warning or guidance can lead users to disclose data to a third party unintentionally. In an agent discovery context, this is more dangerous because search inputs may reflect operational plans, counterparties, or reputation-analysis targets across chains.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 27)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 31)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 54)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 147)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The docs describe setMCP() and setA2A() as automatically fetching remote content from supplied URLs but do not warn that invoking these methods causes outbound network requests to attacker-controlled endpoints. In an agent ecosystem, this can create SSRF-like exposure, metadata leakage, unexpected egress, and trust in unvalidated remote capability data if developers pass untrusted URLs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.