Back to skill

Security audit

流动性管理工具

Security checks for vulnerabilities and agentic risk

Overview

This skill is presented as a Uniswap liquidity manager, but it requests broad local read/write/command authority and lacks clear safety gates for real financial transactions.

Install only if you are prepared to review every proposed transaction and command manually. Do not connect a wallet or grant filesystem/command access unless the host enforces strict confirmations, exact transaction details, limited approvals, verified Uniswap contracts, and sandboxed command execution.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:20
Finding

Excessive Tool Permissions for Underspecified Financial Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–23; supporting behavior at lines 44–48 and 247–251
Vulnerability Type: Excessive system permissions and insecure skill configuration
Risk Level: High

Vulnerable Code Snippet

yaml
tools:
  - read
  - exec
  - write

The requested permissions are combined with instructions to perform financial operations:

text
1. **Add liquidity** — Find the best pool, recommend a range, handle approvals, deposit tokens
2. **Remove liquidity** — Withdraw tokens from an existing position (partial or full)
3. **Collect fees** — Claim accumulated trading fees from a position

Each action delegates to the `liquidity-manager` agent for execution, with optional `pool-researcher` delegation for intelligent pool selection.

The skill also advertises generic filesystem and command-execution functionality:

text
- **文件处理**: 支持多种文件格式的读取、解析和写入操作
- **API集成**: 通过标准化接口调用外部服务并处理响应
- **命令执行**: 在安全沙箱中执行系统命令并收集结果
- **信息检索**: 快速搜索和过滤目标数据

Technical Analysis

The skill requests broad read, write, and exec capabilities even though its declared purpose is managing Uniswap liquidity. The package contains only SKILL.md; it provides no implementation that constrains accessible files, permitted commands, external endpoints, blockchain networks, smart-contract addresses, token approvals, or delegated agents.

The document states that commands should be allowlisted, but this is advisory text rather than an enforceable control. It also promises to handle token approvals, deposits, withdrawals, and fee collection without defining mandatory safeguards such as:

  • Explicit user confirmation immediately before signing.
  • Chain ID and canonical contract allowlists.
  • Token and pool contract verification.
  • Approval amount and duration limits.
  • Slippage, deadline, and transaction-value limits.
  • Transaction simulation ...[truncated 2773 chars]
Remediation
View remediation

Remediation Suggestions

  1. Apply least privilege

    • Remove read, write, and exec unless each capability is essential.
    • Replace generic tools with a narrowly scoped, audited Uniswap or wallet interface.
    • If filesystem access is required, restrict it to explicit project paths and deny credential, wallet, SSH, and environment files.
  2. Constrain command execution

    • Prefer structured APIs over shell commands.
    • If exec remains necessary, implement an enforceable command and argument allowlist.
    • Reject shell metacharacters, command substitution, pipes, redirection, dynamic executable paths, and unsanitized user input.
    • Run commands in a sandbox with no unnecessary network access and minimal filesystem permissions.
  3. Establish transaction safety gates

    • Allowlist supported chain IDs, canonical Uniswap deployments, routers, position managers, and permit contracts.
    • Verify token and pool addresses independently rather than trusting names or user-supplied metadata.
    • Simulate every transaction and reject unexpected transfers, approvals, delegate calls, or contract creation.
    • Decode and show the destination, method, parameters, token amounts, native value, gas estimate, slippage, deadline, and expected balance changes.
    • Require explicit user confirmation immediately before each signature or transaction submission.
  4. Limit token approvals and financial exposure

    • Default to exact-amount approvals rather than unlimited approvals.
    • Set configurable maximum transaction values, approval amounts, slippage, deadlines, and price-impact thresholds.
    • Revoke temporary approvals where technically appropriate.
    • Never request private keys or seed phrases; signing must remain inside a trusted wallet boundary.
  5. Secure delegation

    • Include or precisely identify the liquidity-manager and pool-researcher components.
    • Pin their versio ...[truncated 639 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes adding/removing liquidity and collecting fees, but it does not clearly warn that these are real blockchain transactions that can move user funds, incur gas costs, expose users to slippage/impermanent loss, and be irreversible once signed. In a financial skill, omission of this warning materially increases the risk of user harm through uninformed or accidental execution.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is overly broad, effectively suggesting use whenever a user needs 'tool-related functionality,' which does not meaningfully limit invocation scope. Ambiguous triggers can cause the skill to activate in inappropriate contexts and perform sensitive operations, especially given the presence of exec, write, and blockchain-related actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The premium-features section discusses image-generation-style capabilities such as high-resolution output, style presets, model fine-tuning, and commercial licensing, which are unrelated to Uniswap liquidity management. This inconsistency is a strong indicator of copy-paste or templated documentation drift, reducing trust in the rest of the skill and increasing the risk that hidden or poorly reviewed functionality is also mismatched to the declared purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The display name, summaries, and description interleave Chinese and English text, but the document does not state that language is user-selectable or based on user preference. This can amount to an implicit language policy violation because the skill presents a fixed mixed-language experience without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill declares read, exec, and write capabilities without a clear warning about local system access, file modification, or data exposure risks. Users may reasonably assume a finance-only workflow, while the actual toolset could read or alter files or execute commands, making the mismatch especially dangerous in an agent runtime.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The core capability summary uses vague trigger language rather than precise boundaries for when the skill should run. In a high-risk context involving financial transactions and powerful tools, unclear routing criteria increases the chance of accidental or overbroad invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Advertising command execution for a liquidity-management skill is dangerous because shell access is far more powerful than the stated purpose requires. In an agent environment, this can become a path to running arbitrary commands, accessing local files, or pivoting beyond blockchain operations if prompts or downstream components are compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a narrowly scoped Uniswap liquidity manager, but the documentation also claims generic file handling, API integration, command execution, and information retrieval capabilities. This scope mismatch can mislead users and host agents into granting broader authority than necessary, increasing the chance of arbitrary local actions or unintended data access under the guise of a finance workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.