Back to skill

Security audit

Trustless Workflow Automation on EVM networks for Agents (powered by Ditto Network)

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Ditto on-chain automation, but it gives unpinned tooling wallet-signing authority and includes an unsafe production swap recipe that could expose real funds.

Review before installing or using with real funds. Use a dedicated low-value wallet, pin and verify SDK/tooling versions with a lockfile, test on testnet first, require explicit confirmation before production deployment, and replace the production swap example with bounded slippage, short deadlines, verified addresses, and clear spend limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:16
Finding

Unpinned Third-Party SDK Is Given Wallet Signing Authority

Content
View full analysis
Remediation
View remediation
``` 2. Commit a lockfile and use `npm ci` in automated or reproducible environments. 3. Verify package integrity, publisher provenance, release signatures, and the resolved dependency tree before execution. 4. Reference a reviewed commit hash or signed release tag instead of the mutable `master` branch. 5. Audit the SDK paths responsible for: - Signer handling - Session-permission construction - Executor-address selection - Workflow serialization - Network requests - On-chain transaction submission 6. Do not prohibit security review of upstream source and documentation. Clearly distinguish unsupported examples from material that should still be inspected for security purposes. 7. Use a dedicated low-value wallet for workflow deployment rather than a primary wallet. 8. Add explicit transaction and permission previews before requesting signatures, including chain, target, function, value, token allowance, validity period, execution count, and executor address. 9. Where supported, use a constrained signing interface or hardware wallet requiring user confirmation instead of exposing an unattended software signer to the SDK. 10. Validate the SDK-provided executor address against a separately published, versioned allowlist before granting permissions. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:340
Finding

Production Swap Recipe Allows Unlimited Slippage

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
77% confidence
Finding

The skill instructs users to run the workflow via npx ts-node, which can resolve and execute code from the local dependency graph or fetch packages if not already present, without any version pinning or integrity guidance. In a web3 automation skill that handles private keys and deploys on-chain actions, this increases supply-chain risk because a compromised or unexpected toolchain component could execute arbitrary code in an environment containing sensitive secrets.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

npx ts-node your-workflow-script.ts

text

Expected output: IPFS hash and transaction receipt(s). The Ditto Network will now automatically execute this workflow according to the triggers. If submission fails, check the Troubleshooting section.

## Supported Chains

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The production recipe automates recurring token approval and swap transactions on a live chain, but it does not place a prominent user-facing warning directly in the example about irreversible financial loss, approval risk, slippage, or the danger of using placeholder addresses and minAmountOut set to zero. In this skill context, users are explicitly being guided to deploy autonomous DeFi workflows, so omission of strong transactional risk warnings makes accidental loss materially more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.