Back to skill

Security audit

deskcrew-board-owner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed DeskCrew bounty-board workflow that can spend USDC from a dedicated wallet, so users should treat it as a real payment tool but the behavior matches its purpose.

Install only if you intend to use DeskCrew to run a USDC-funded bounty board. Use a dedicated wallet with only the amount you are willing to spend, protect the returned API key, and do not post private questions because bounty content and rejection reasons are public.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation text is broad enough to match ordinary requests about delegating work, outsourcing questions, or paying for answers, which can cause the agent to trigger this skill in situations where the user did not explicitly intend to initiate a blockchain-funded bounty workflow. Because the skill requires a wallet and can lead to on-chain payments or exposure of public task content, accidental invocation increases the risk of unintended spending, confusing routing, or privacy mistakes.

Static analysis

No suspicious patterns detected.