Back to skill

Security audit

termix-agent-skills

Security checks for vulnerabilities and agentic risk

Overview

This skill needs Review because it can handle wallet private keys, send live blockchain transactions, cache auth tokens, run background auto-replies, and has an overbroad authenticated API helper.

Install only if you intend to let the skill operate Termix Provider workflows with wallet-level authority. Use a dedicated low-balance wallet, avoid pasting a primary private key into chat or shell history, prefer dry-run before any transaction, verify every contract address and amount, do not pass full external URLs to the authenticated API helper, and stop the autoreply worker when it is no longer needed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (38)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill manifest describes inspection, inbox auto-reply, reads, and dispute checks, but this document adds a new high-risk capability: registering and staking an on-chain agent. That scope expansion matters because it can induce the agent or user to perform asset-affecting actions that are not implied by the advertised purpose, weakening operator trust boundaries and increasing the chance of unauthorized or unexpected transaction workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document instructs use of a backend POST endpoint to stage agent metadata even though the skill description is framed as read-oriented operational support. Hidden write operations to external services are risky in agent settings because they can cause side effects, transmit user-provided data off-platform, and normalize behavior outside the declared capability envelope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This guide instructs execution of blockchain transactions using a private key, including minting an NFT, approving token spending, and depositing USDC. In the context of a skill advertised for operational inspection and reads, introducing private-key-based transaction execution is dangerous because it can directly move or lock assets and conditions users to hand sensitive signing material to an automation workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script includes wallet-based login and provider-agent enumeration capabilities that materially expand scope beyond simple A2A runtime inbox/reply operations. In a skill consumed by an agent, this increases privilege and discovery surface by enabling account/session establishment and listing owned agents, which could be misused to target or operate on unintended identities.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Inbox message contents are sent to an external LLM endpoint using llmReply, which can disclose potentially sensitive buyer/seller communications to a third party. This is especially risky because the skill description emphasizes runtime operations and auto-reply, but does not clearly disclose exfiltration of message content to OpenRouter/OpenAI-compatible services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The autoreply command launches a detached background worker that persists independently of the invoking session, continuing to poll inboxes and send replies. Hidden persistence is dangerous in agent skill contexts because it can outlive operator awareness, continue consuming credentials, and keep acting on live conversations without foreground supervision.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This script is explicitly designed as a generic authenticated API caller for many Provider workflows, including mutating operations. That broad capability exceeds a narrowly scoped skill and can be abused by an agent or prompt flow to perform unintended state-changing actions across the platform using cached credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code accepts any path and, if it starts with 'http', sends the request to an arbitrary full URL while still attaching the bearer token. This creates a clear SSRF/token exfiltration primitive: a malicious caller can direct authenticated requests to attacker-controlled infrastructure and capture session or runtime credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This script is explicitly designed to sign and broadcast blockchain transactions using a private key from the environment, which is a powerful side-effect capability not aligned with the stated skill scope of inspection, inbox polling, and read/check workflows. In an agent skill context, hidden or under-declared transaction execution materially increases the risk of unauthorized asset movement or abuse if the agent is prompted to invoke it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script accepts arbitrary transaction intents containing destination, calldata, and value, then signs and submits them with WALLET_KEY with no policy validation of recipient, function, asset amount, or action type. That makes it a generic wallet drainer primitive in practice: any caller able to supply an intent can cause token approvals, transfers, contract calls, or other irreversible on-chain actions from the configured wallet.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The comment claims the operator or LLM can confirm the plan before broadcast, but the code merely prints a summary and immediately continues to signing and submission unless --dry-run is manually provided. This mismatch creates a deceptive safety assumption that can lead users or higher-level agents to believe there is a confirmation checkpoint when there is none.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file exposes a direct transaction broadcast primitive via eth_sendRawTransaction, which enables irreversible on-chain actions if another part of the skill can assemble signed payloads. That capability is materially outside the stated Termix platform operations scope, so it increases the chance the skill can be repurposed for unauthorized fund movement or hidden blockchain activity without user expectation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file implements a generic JSON-RPC client for blockchain operations including chain ID, nonce, fee estimation, gas estimation, receipt polling, and broadcasting. In a skill described as Termix-focused operational automation, this is unnecessary latent capability that broadens the attack surface and could support covert blockchain interactions if combined with signing logic elsewhere.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file embeds Ethereum cryptographic primitives and exports wallet-style capabilities such as address derivation, message signing, transaction signing, and keccak hashing that are unrelated to the declared Termix operational workflows. In an agent skill whose stated purpose is provider-agent inbox polling, campaign/order reads, and dispute checks, this out-of-scope signing capability materially increases the risk that the skill can be repurposed to handle secrets and authorize blockchain actions without clear business justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The signTransaction function creates raw EIP-1559 signed transactions directly from a provided private key, enabling transfer authorization and arbitrary on-chain actions. In the context of a non-crypto operations skill, this is a severe unauthorized capability because any component that can source a private key and transaction parameters can produce broadcastable transactions, potentially leading to irreversible asset loss.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module exposes addressFromPrivateKey and signMessage, both of which operate directly on caller-supplied private keys. Even absent transaction signing, these functions normalize secret-key handling inside the skill and enable identity proof generation or wallet ownership challenges to be satisfied, which can be abused for account linking, phishing workflows, or preparation for broader wallet compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation states that buyer inbox messages are sent to an external chat-completions API to draft replies, but it does not clearly warn operators that third-party message content will be transmitted off-platform. In this context, inbox messages may contain sensitive commercial, personal, or dispute-related data, so the omission creates a meaningful privacy and compliance risk through uninformed use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs users to upload proof files and submit publicly accessible URLs, but it does not warn that uploaded artifacts may expose personal data, metadata, account identifiers, or other sensitive content. In this provider-workflow context, users are explicitly encouraged to publish evidence externally, so omission of privacy guidance can lead to unintentional disclosure and lasting public exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation instructs users to place a raw wallet private key into an environment variable and run scripts that perform live on-chain transactions, but it provides no safety guidance about key isolation, shell history, process inspection, logging exposure, or using a dedicated low-value key. In an agent-skill context, this is especially dangerous because automated assistants may normalize unsafe secret-handling practices and encourage users to reuse a primary wallet for production funds.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The TEE workflow directs users to encrypt and transmit exchange API credentials to a remote backend/TEE path without a prominent warning about trust boundaries, credential scope, possible misuse, or the consequences if the enclave, backend proxy, or attestation verification process is misunderstood. Because these credentials can authorize trading activity, users may expose exchange accounts to unauthorized orders or financial loss even if the transport format is encrypted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly requires a client wallet private key and instructs the user to export it into an environment variable, but it does not provide concrete safety guidance on secure handling, least-privilege usage, or the risk of key theft from shell history, logs, or shared environments. In a blockchain workflow, compromise of this credential can enable unauthorized irreversible transactions and asset loss well beyond the single operation described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill tells the user to call an on-chain state-changing function to assign a provider but does not prominently warn that this action is irreversible once confirmed and may change job state in a way that cannot be undone without additional transactions or governance logic. Users may execute it as if it were a read-only operational step, increasing the risk of accidental assignment, gas expenditure, and workflow disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation instructs users to pass a wallet private key inline via the WALLET_KEY environment variable to execute an on-chain settlement transaction, but it does not warn about key-handling risks, shell history exposure, process inspection, or the irreversible side effects of broadcasting a blockchain transaction. In an agent-skill context, this is more dangerous because users may copy-paste commands directly into automated or shared environments, increasing the chance of credential leakage or unintended settlement execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation instructs users to pass a raw private key via the WALLET_KEY environment variable to broadcast an on-chain transaction, but it does not include any warning about key handling, use of a dedicated wallet, or risks of exposing secrets through shell history, process inspection, logs, or reused environments. In a skill that operationalizes blockchain actions, this omission can lead users to handle signing keys unsafely and increases the chance of wallet compromise or unintended fund loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs users to place a raw private wallet key directly in an environment variable on the command line (WALLET_KEY=0x… node ...) without any safety warning or guidance on secure key handling. This is dangerous because shell history, process listings, CI logs, or shared terminal environments can expose the key, leading to theft of funds and unauthorized on-chain transactions.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/a2a-runtime.mjs:397

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/a2a-runtime.mjs:44

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/aacp-api.mjs:38

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
docs/client-create-job.md:385

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
docs/register-agent.md:63