Back to skill

Security audit

foundry-solidity

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Foundry/Solidity guide, but it includes copy-pasteable private-key and live blockchain transaction examples without enough local warnings for irreversible actions.

Review this skill before installing if you may use it for real wallets or deployments. Prefer local Anvil or testnet examples first, avoid pasting private keys or seed phrases into shell commands, use keystores or hardware wallets for production, pin dependencies and CI actions for release builds, and treat any --broadcast or cast send command as a deliberate live transaction.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/deployment.md:9
Finding

Blockchain signing secrets are passed through command-line arguments

Content
View full analysis

Vulnerability Details

File Location: references/deployment.md:9-31; additional instances in SKILL.md:127-130 and references/cast-advanced.md:85-112
Vulnerability Type: Sensitive information exposure through process arguments
Risk Level: Medium

Vulnerable Code

bash
# Deploy with constructor args
forge create src/Token.sol:Token \
    --rpc-url sepolia \
    --private-key $PRIVATE_KEY \
    --constructor-args "MyToken" "MTK" 18

# Deploy and verify
forge create src/Token.sol:Token \
    --rpc-url sepolia \
    --private-key $PRIVATE_KEY \
    --broadcast \
    --verify \
    --etherscan-api-key $ETHERSCAN_API_KEY \
    --constructor-args "MyToken" "MTK" 18

# Deploy with value (payable constructor)
forge create src/Vault.sol:Vault \
    --rpc-url sepolia \
    --private-key $PRIVATE_KEY \
    --value 1ether

Related wallet-management examples expose literal private keys or mnemonic phrases in arguments:

bash
# Derive from mnemonic
cast wallet derive-private-key "word1 word2 ... word12"

# Get address from private key
cast wallet address --private-key 0x...

# Get address from mnemonic
cast wallet address --mnemonic "word1 word2..."

# Sign message
cast wallet sign "message" --private-key 0x...

# Import to keystore
cast wallet import my-wallet --private-key 0x...

Technical Analysis

Private keys and mnemonic phrases are bearer credentials that provide direct control over blockchain accounts. Supplying them as command-line arguments can expose their expanded values through operating-system process inspection, shell history when literal values are used, terminal recording, debugging output, CI diagnostics, or endpoint-monitoring software.

Although $PRIVATE_KEY is read from an environment variable in several examples, the shell expands it before launching forge; the resulting private key is therefore included in the child process's argum ...[truncated 1686 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove examples that pass private keys or mnemonic phrases through command-line arguments.
  • Prefer encrypted Foundry keystores with --account, hardware wallets through --ledger or --trezor, or interactive secret entry that does not place the secret in the argument vector.
  • Document secure keystore creation and explicitly instruct users not to enter funded private keys or mnemonic phrases directly into commands.
  • Use dedicated, least-privileged deployment accounts rather than treasury or protocol-administrator wallets.
  • Require transaction simulation, chain-ID validation, destination verification, and human approval before production broadcasts.
  • In CI, use an isolated signer, hardware-backed key-management service, or short-lived signing service rather than exposing a raw private key to the runner.
  • Disable shell tracing around sensitive operations and ensure logs, histories, and deployment artifacts do not contain signing material.
  • Retain throwaway keys exclusively for local and testnet examples, and label every example accordingly.

T08 · Insecure Dependencies

Warning
Location
references/dependencies.md:7
Finding

Dependency and CI examples use mutable third-party references

Content
View full analysis

Vulnerability Details

File Location: references/dependencies.md:7-20, 93-103, 153-160; related CI references in references/cicd.md:18-21, 112-138, 204-232
Vulnerability Type: Supply-chain dependency integrity weakness
Risk Level: Medium

Vulnerable Code

bash
# Install latest master
forge install vectorized/solady

# Install specific tag
forge install vectorized/solady@v0.0.265

# Install specific commit
forge install vectorized/solady@a5bb996e91aae5b0c068087af7594d92068b12f1

# No automatic commit (for CI)
forge install OpenZeppelin/openzeppelin-contracts --no-commit

Additional mutable package examples include:

bash
# From registry (soldeer.xyz)
forge soldeer install @openzeppelin-contracts~5.0.2
forge soldeer install forge-std~1.8.1

# From URL
forge soldeer install @custom~1.0.0 --url https://example.com/lib.zip

# From git
forge soldeer install lib~1.0 --git https://github.com/org/lib.git --tag v1.0

The CI examples similarly use major-version GitHub Action tags rather than immutable commit SHAs:

yaml
- uses: actions/checkout@v4

- name: Install Foundry
  uses: foundry-rs/foundry-toolchain@v1

- name: Upload coverage
  uses: codecov/codecov-action@v4

Technical Analysis

Branch heads such as the latest default branch, semantic-version ranges such as ~5.0.2, archive URLs, Git tags, and GitHub Action major-version tags are not immutable content identifiers. Their effective content can differ between installations or change after the Skill has been reviewed.

The document includes one good commit-pinned Forge example, but presents mutable installation methods as normal development or production practices and does not consistently require lockfiles, checksums, full commit hashes, or GitHub Action SHAs.

This creates a supply-chain trust boundary. If an upstream account, repository, release process, package registry, DNS path, or mutable ta ...[truncated 2002 chars]

Remediation
View remediation

Remediation Suggestions

  • Require production Forge dependencies to be pinned to reviewed full commit hashes.
  • Commit and verify Soldeer lockfiles, and use exact package versions with integrity hashes rather than semantic ranges.
  • Pin every GitHub Action to a full commit SHA; retain the release version only as an explanatory comment.
  • Avoid arbitrary archive URLs. If unavoidable, restrict them to approved HTTPS origins and verify a cryptographic checksum before use.
  • Generate and retain a software bill of materials for release and deployment builds.
  • Configure dependency-update automation to open reviewed pull requests rather than updating dependencies automatically during production builds.
  • Rebuild in isolated, reproducible environments and compare artifact hashes before deployment.
  • Restrict CI workflow-token permissions and separate untrusted build/test jobs from jobs that have production environments or signing credentials.
  • Require manual approval for deployment environments and verify deployed bytecode against independently reproduced artifacts.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/testing.md (reported line 526)May include surrounding context.

Environment

solidity
// Read .env
string memory value = vm.envString("KEY");
uint256 value = vm.envUint("KEY");
address value = vm.envAddress("KEY");

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The deployment examples include commands that can broadcast real transactions to a live network, and one example explicitly uses --broadcast --verify without an adjacent warning about spending funds and interacting with real chains. In a developer skill that may be followed verbatim, this omission increases the risk of accidental mainnet/testnet transactions, especially when environment variables such as private keys and RPC URLs are already documented in the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The cast send example is a live transaction command that signs with a private key and submits an on-chain state-changing transaction, but the skill does not explicitly warn that this will spend funds and can have irreversible effects. Because this skill is specifically for Ethereum tooling and exposes private-key-based workflows, users may copy the example directly and unintentionally execute a real transfer or contract call.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes commands that directly handle highly sensitive material such as raw private keys and mnemonics, but it provides no warning about secret exposure, shell history leakage, or the risks of copying production credentials into CLI arguments. In a blockchain tooling skill, users may paste real wallet material into these examples, which can lead to irreversible asset loss if the secrets are logged, shoulder-surfed, or reused on compromised systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The keystore import example demonstrates passing a raw private key on the command line, which is dangerous because CLI arguments may be captured in shell history, process listings, terminal logs, or remote session recordings. Even though the goal is legitimate wallet setup, the lack of safe-handling guidance increases the chance that users expose real blockchain credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples show real state-changing transactions, including transfers and deposits, using mainnet RPC and a private key, without warning that these actions are irreversible and may spend real assets. In the context of a Foundry/cast skill, this is especially risky because users may run snippets verbatim against production networks and unintentionally move funds or interact with the wrong contract.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The deployment example uses forge script ... --broadcast --verify together with a private key in a production environment, which performs a real on-chain state-changing deployment. In documentation for a developer skill, omitting an explicit warning that this step will spend funds and can irreversibly deploy contracts increases the chance of accidental mainnet execution, especially if users copy-paste the workflow into CI.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/configuration.md (reported line 225)May include surrounding context.

base = { key = "${BASESCAN_API_KEY}" }

Custom chain

custom = { key = "${CUSTOM_API_KEY}", url = "https://api.custom-explorer.com/api" }

text

## Formatting

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The examples instruct users to pass private keys and API keys via environment variables and shell commands without explicitly warning about secret handling risks such as shell history leakage, shared terminal exposure, CI log disclosure, or accidental plaintext storage. While this is common documentation practice, omission of handling guidance in a deployment skill increases the chance of credential compromise that could enable unauthorized contract deployment or account theft.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The deployment script examples actively broadcast transactions and perform privileged state changes such as minting tokens, granting roles, and setting governance, but the guide does not clearly warn that using --broadcast causes irreversible on-chain actions and real fund expenditure. In a developer-facing skill, this omission can lead users to run examples against production networks by mistake, causing unintended deployments, permission changes, or token minting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes a deployment example that accesses PRIVATE_KEY via vm.envUint("PRIVATE_KEY"), which is a sensitive credential operation. The surrounding documentation presents this as a normal step but does not warn users about secret handling, exposure risks, or safer alternatives, which fits the markdown-file criteria for missing user warnings.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 27)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 31)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 54)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 147)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.generated_source_template_injection

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/cicd.md:238

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
references/configuration.md:210

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
references/deployment.md:368

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
references/testing.md:417

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:284