Back to skill

Security audit

Monad开发工具

Security checks for vulnerabilities and agentic risk

Overview

This Monad development skill is mostly purpose-aligned, but it gives unsafe live deployment and third-party verification examples without enough user controls or warnings.

Review deployment commands before running them. Use a test wallet with limited funds, prefer keystore or hardware-wallet signing over `--private-key`, simulate before broadcasting, pin dependencies, and only submit verification data to third-party services after confirming the endpoint and payload are acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:182
Finding

Wallet Private Key Exposed Through Process Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 182-186
Vulnerability Type: Private key exposure through command-line arguments
Risk Level: High

bash
forge script (请参考skill目录中的脚本文件):DeployScript \
  --rpc-url https://testnet-rpc.monad.xyz \
  --private-key $PRIVATE_KEY \
  --broadcast

Technical Analysis

The deployment example passes the wallet private key to Foundry through the --private-key command-line option. The shell expands $PRIVATE_KEY before creating the process, placing the resulting secret in the process argument vector.

Depending on the execution environment and operating-system controls, expanded arguments may be exposed through process-monitoring utilities, CI/CD execution records, shell debugging output, telemetry, crash reports, or other diagnostic tooling. Any local user or service with sufficient process-inspection or log-reading access could consequently recover the key.

Although the document advises users to protect API keys, it does not provide equivalent secure handling guidance for the blockchain private key used to authorize transactions.

Attack Path

  1. A user exports a funded wallet's private key as PRIVATE_KEY.
  2. The user or agent executes the documented forge script command.
  3. The shell expands $PRIVATE_KEY, inserting the plaintext secret into the child process arguments.
  4. An attacker with access to process metadata, command tracing, CI logs, or captured diagnostics reads the expanded argument.
  5. The attacker imports the recovered key into a wallet or signing tool.
  6. The attacker signs and broadcasts unauthorized transactions using the compromised account.

Impact Assessment

Successful exploitation grants the attacker the same blockchain signing authority as the affected wallet. The attacker could transfer native currency and tokens, invoke privileged contract functions, deploy contracts, or otherwise impersonate the account. The ...[truncated 174 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pass raw private keys through command-line arguments.
  • Use a Foundry encrypted keystore with --account, an interactive hardware wallet, or an external signing service.
  • Use a dedicated deployment account with only the funds and privileges required for the operation.
  • Ensure shell tracing such as set -x is disabled during all signing and deployment operations.
  • Configure CI/CD systems to use protected secret stores and signer integrations rather than interpolating private keys into commands.
  • Rotate any private key that may already have appeared in process captures, build logs, shell traces, or diagnostic records.
  • Add explicit documentation warning users never to paste or print a private key and to review generated transactions before signing.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:157
Finding

OpenZeppelin Dependency Installed Without an Immutable Version Pin

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 157
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

bash
forge install OpenZeppelin/openzeppelin-contracts --no-commit

Technical Analysis

The installation command identifies the OpenZeppelin repository but does not select a reviewed release tag or immutable commit hash. Consequently, separate executions may retrieve different revisions as the upstream default branch changes.

This creates a supply-chain integrity and reproducibility weakness. Contract source code may change without a corresponding change to the skill, preventing users from reliably reproducing an audited build. The use of the legitimate OpenZeppelin repository reduces the likelihood of malicious dependency substitution, but it does not eliminate upstream compromise, unexpected breaking changes, or unnoticed dependency drift.

Attack Path

  1. A user follows the documented installation command without specifying a tag or commit.
  2. Foundry resolves the repository's current default revision at installation time.
  3. The upstream revision changes, is compromised, or introduces behavior that the user has not reviewed.
  4. The project imports and compiles the newly retrieved dependency code.
  5. The user deploys a contract whose dependency implementation differs from the previously tested or audited version.
  6. Defects or malicious behavior in that dependency affect the deployed contract.

Impact Assessment

Exploitation could alter inherited token behavior, introduce contract vulnerabilities, break compilation or deployment assumptions, and undermine build reproducibility. The resulting scope is primarily the generated project and contracts deployed with the changed dependency. If a compromised dependency were deployed, affected token assets and any privileges assigned to the resulting contract could be placed at risk.

Remediation
View remediation

Remediation Suggestions

  • Pin OpenZeppelin Contracts to a reviewed release tag or, preferably, an immutable commit hash in the installation command.
  • Record the selected revision in version control and preserve Foundry dependency metadata.
  • Verify the retrieved commit and repository origin before compilation.
  • Run contract tests and static analysis against the exact pinned dependency revision.
  • Use an explicit upgrade process that includes release-note review, source comparison, security review, and regression testing.
  • Ensure production builds fail if dependency revisions differ from the approved lock state.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The deployment example includes a live forge script ... --broadcast command using a private key and RPC endpoint, which can submit irreversible on-chain transactions and spend funds. Without a prominent warning or safer default such as dry-run mode, a user or agent could execute the command unintentionally against a real network.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The curl -X POST example sends locally generated contract verification data to an external domain, creating an outbound data transmission path. In a skill that may be followed by an agent with file access and execution privileges, undocumented external transmission increases the risk of unreviewed disclosure of project metadata or sensitive deployment-related values.

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
STANDARD_INPUT=$(forge verify-contract <TOKEN_ADDRESS> src/MyToken.sol:MyToken --chain 10143 --show-standard-json-input)
COMPILER_VERSION=$(jq -r '.metadata | fromjson | .compiler.version' out/MyToken.sol/MyToken.json)
# ...
curl -X POST https://agents.devnads.com/v1/verify \
  -H "Content-Type: application/json" \
  -d "{
    \"chainId\": 10143,

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill claims command execution is restricted to a whitelist and avoids concatenating user input, but its own examples interpolate variables such as PRIVATE_KEY, TOKEN_ADDRESS, constructor arguments, and JSON payload content directly into shell commands. This mismatch can mislead users and downstream agents into trusting unsafe execution patterns, increasing the risk of command misuse, secret exposure, or unsafe parameter injection in real implementations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The verification example transmits contract metadata, compiler details, address information, and constructor arguments to an external service without clearly disclosing that data leaves the local environment. Even if the data is not always secret, users should be informed before sending build artifacts or deployment metadata to third parties.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest describes a Monad blockchain development skill focused on code generation, debugging, testing, and deployment. L288 broadens this to a general 'API integration' capability for calling external services, which is more expansive than the stated development purpose and is not scoped specifically to Monad tooling or deployment requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.