Back to skill

Security audit

Blinko

Security checks for vulnerabilities and agentic risk

Overview

This skill openly plays an on-chain gambling game, but it gives an agent wallet-backed spending authority without per-transaction approval or cumulative limits.

Install only with a dedicated hot wallet funded with the maximum amount you are willing to lose, and do not expose a main wallet private key. Treat gameplay invocations as real gambling transactions that can spend ETH and gas repeatedly. Prefer a version that requires explicit approval for every transaction, removes the default bet, enforces daily/session limits, validates API-returned transaction parameters, and separates read-only stats from spend-capable gameplay.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/play-blinko.js:45
Finding

Autonomous Real-Fund Spending Without Per-Transaction Approval or Cumulative Limits

Content
View full analysis
MAX_BET) { throw new Error(`Bet out of range (0.0001-0.1 ETH). Got: ${betEth}`); } // ... const tx1 = await contract.createGame(params, serverSig, ethers.randomBytes(32), { value: betWei }); console.log(`⛓️ createGame tx: ${tx1.hash}`); await tx1.wait(); ``` ### Technical Analysis The Skill loads `WALLET_PRIVATE_KEY` and uses it to sign and broadcast a payable transaction without requesting per-transaction user confirmation. Although each individual bet is constrained to between 0.0001 and 0.1 ETH, no cumulative, daily, session, invocation-count, or gas-spending limit is enforced. The declared ability for agents to invoke the Skill autonomously expands possession of the environment variable into direct authority to spend wallet funds. This exceeds a least-privilege design because checking statistics does not require transaction-signing authority, and even the gameplay function does not technically require unrestricted repeated authorization. The script also defaults to a 0.001 ETH bet if no amount is supplied, meaning an accidental or incomplete invocation can still initiate a ...[truncated 1406 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/play-blinko.js:56
Finding

Replayable Wallet Authentication Signature Lacks Nonce and Domain Binding

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/play-blinko.js:68
Finding

Unvalidated Server-Controlled Parameters Are Used in a Wallet-Signed Transaction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code clearly implements the core headless commit-reveal play flow: wallet loading, API authentication, game creation, on-chain createGame call, API play call, and on-chain settlement. That aligns with part of the description. However, the declared purpose also says the skill can check game stats, view leaderboards, and track honey rewards, and those capabilities are not present in this code chunk. Additionally, the description mentions simulation, but the script does not perform a separate simulation step; it directly calls create-game, createGame on-chain, play, and settlement. There are no undeclared suspicious capabilities beyond the described game-playing flow, but the description overstates the available functionality in this supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a comprehensive Blinko automation skill that can play on-chain games and manage the full lifecycle of gameplay, including auth, creation, simulation, and settlement. The supplied code does none of that. It only performs unauthenticated GET requests to blinko.gg API endpoints and prints profile, games, leaderboard, or honey data for an address. While 'check game stats, view leaderboards, or track honey rewards' is partially consistent with the code, the primary declared purpose is much broader and materially overstated relative to the actual behavior of this chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
node scripts/play-blinko.js 0.001

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
node scripts/play-blinko.js 0.001

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
node scripts/play-blinko.js 0.001

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
node scripts/play-blinko.js 0.001

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
node scripts/play-blinko.js 0.001

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
node scripts/play-blinko.js 0.001

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
node scripts/play-blinko.js 0.001

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
node scripts/stats.js 0xYourAddress profile

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
node scripts/stats.js 0xYourAddress profile

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
node scripts/stats.js 0xYourAddress profile

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The ABI includes privileged administrative and upgrade functions such as initialize, transferOwnership, acceptOwnership, renounceOwnership, and upgradeToAndCall that are unrelated to normal Blinko gameplay. Even if on-chain access control exists, surfacing these functions through an agent skill is dangerous because it can prompt attempted admin actions, interact with the wrong deployment, or expose high-risk pathways if the configured signer happens to control a privileged account.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares access to a sensitive environment variable and clearly performs networked, transaction-signing behavior, but it does not declare an explicit tool scope such as permissions or allowed-tools. In an autonomous agent setting, this weakens policy boundaries around secret access and outbound network use, increasing the chance that a caller can trigger wallet-backed actions without sufficiently explicit capability gating.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The ABI exposes generic fund-management methods such as deposit, withdraw, depositETH, withdrawETH, and balanceOf that go beyond the stated skill purpose of playing and querying Blinko games. In an agent skill context, including these capabilities increases the risk that the agent can be induced to move or custody assets in unintended ways, expanding blast radius from game play to treasury operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script requires a raw wallet private key to be injected via an environment variable and then uses it to sign messages and send on-chain transactions. In the context of a headless game-playing skill, this creates substantial key-exposure risk because any compromise of the runtime, logs, process environment, or dependent code can lead to immediate theft of funds and full wallet takeover.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency version for ethers is specified with a caret range (^6.0.0), which allows automatic installation of newer minor and patch releases. While this is common practice, it increases supply-chain risk because a compromised or breaking upstream release could be pulled into a security-sensitive skill without review. In this skill's context, that risk matters more because the package is used for on-chain interactions and likely handles transactions or wallet operations.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"author": "Bearish (@BearishAF)",
  "license": "MIT",
  "dependencies": {
    "ethers": "^6.0.0"
  }
}

Static analysis

No suspicious patterns detected.