Back to skill

Security audit

Musashi

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly discloses token analysis and optional on-chain publishing, but it includes under-documented blockchain write/admin commands and risky private-key handling.

Install only if you intentionally want a crypto-token analysis skill that can publish on-chain records. Use analysis mode without a private key when possible; if enabling publish mode, use a dedicated low-balance wallet, review every transaction prompt, and treat the packaged admin-style commands and private-key handling as reasons for careful review before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/musashi-core/internal/storage/og_storage.go:90
Finding

Wallet Private Key Exposed Through Child Process Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/musashi-core/internal/storage/og_storage.go:90-96
Vulnerability Type: Sensitive credential exposure through command-line arguments
Risk Level: High

Vulnerable Code

go
out, err := runCLI("upload",
    "--url", c.rpcURL,
    "--key", c.privateKey,
    "--indexer", c.indexer,
    "--file", filePath,
)

The value of c.privateKey, sourced from OG_CHAIN_PRIVATE_KEY, is passed directly to 0g-storage-client through the --key command-line argument.

Technical Analysis

Process command-line arguments are not an appropriate secret-transport mechanism. Depending on the operating system and security configuration, process arguments may be observable through process inspection interfaces, monitoring software, audit logs, diagnostic tools, crash reports, or container orchestration telemetry.

Although exec.Command safely separates arguments and does not introduce shell injection, it places the complete private key in the child process argument vector for the duration of the upload. This exposure is unnecessary because the key only needs to be provided securely to the storage client.

The key is also the same OG_CHAIN_PRIVATE_KEY used by the project to sign on-chain operations. Consequently, compromise is not limited to evidence storage.

Attack Path

  1. A user configures publish mode by setting OG_CHAIN_PRIVATE_KEY.
  2. The Skill reaches the evidence-storage step after the user approves publishing.
  3. UploadFile launches 0g-storage-client with the private key as the value of --key.
  4. A local process, monitoring component, or administrator with permission to inspect process arguments captures the argument vector while the upload is running.
  5. The observer extracts the private key.
  6. The recovered key is imported into another wallet or signing program.
  7. The attacker signs arbitrary transactions permitted by the compromised w ...[truncated 993 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not pass private keys through command-line arguments.
  2. Use a supported secure input mechanism, in this order of preference:
    • Integrate the official 0G Storage library directly and sign in process.
    • Pass the key through a dedicated inherited file descriptor.
    • Use standard input if the client explicitly supports non-interactive secret input.
    • Use an OS keyring, hardware signer, or external signing service.
    • Use a narrowly scoped environment variable only if the client supports it and the deployment prevents environment inspection.
  3. Use a separate, least-privileged storage-signing key rather than reusing the chain wallet key where the platform permits it.
  4. Ensure errors, debug logs, and child-process output never contain the key.
  5. Add an automated test that inspects the generated child-process arguments and fails if any secret value is present.
  6. Rotate the configured wallet key after deploying the fix if the affected publish path has previously been used on a system where process arguments may have been logged or observed.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/musashi-core/internal/storage/og_storage.go:136
Finding

Predictable Temporary Evidence Filename Permits Symlink-Based File Overwrite

Content
View full analysis

Vulnerability Details

File Location: scripts/musashi-core/internal/storage/og_storage.go:136-144
Vulnerability Type: Insecure temporary-file creation and symbolic-link following
Risk Level: Medium

Vulnerable Code

go
// marshal evidence JSON to temp file and upload
func (c *OGStorageClient) StoreEvidence(evidence interface{}) (*StoreResult, error) {
    b, err := json.MarshalIndent(evidence, "", "  ")
    if err != nil {
        return nil, fmt.Errorf("failed to marshal evidence: %w", err)
    }

    tmpFile := filepath.Join(os.TempDir(), fmt.Sprintf("musashi-evidence-%d.json", time.Now().Unix()))
    if err := os.WriteFile(tmpFile, b, 0600); err != nil {
        return nil, fmt.Errorf("failed to write temp file: %w", err)
    }
    defer os.Remove(tmpFile)

    return c.UploadFile(tmpFile)
}

Technical Analysis

The temporary filename is derived solely from the current Unix timestamp in seconds. An attacker can predict a small set of candidate filenames around the expected execution time.

os.WriteFile opens the selected path for creation or truncation and follows an existing symbolic link. The requested 0600 mode applies when a new file is created, but it does not make path selection atomic and does not prevent an existing symlink from being followed.

If an attacker can create the predicted path in the shared temporary directory, the attacker may point it at another file writable by the Skill’s operating account. When os.WriteFile runs, it can truncate and overwrite that target with evidence JSON. Operating-system symlink protections may prevent some cross-user attacks, but they are configuration-dependent and do not eliminate attacks from another process running under the same account.

The one-second filename resolution also creates collision risks when multiple storage operations execute in the same second.

Attack Path

  1. An attacker with local filesystem acces ...[truncated 1357 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace timestamp-based path construction with atomic temporary-file creation:

    go
    tmp, err := os.CreateTemp("", "musashi-evidence-*.json")
    if err != nil {
        return nil, fmt.Errorf("failed to create temp file: %w", err)
    }
    tmpFile := tmp.Name()
    defer os.Remove(tmpFile)
    
    if err := tmp.Chmod(0600); err != nil {
        tmp.Close()
        return nil, fmt.Errorf("failed to secure temp file: %w", err)
    }
    if _, err := tmp.Write(b); err != nil {
        tmp.Close()
        return nil, fmt.Errorf("failed to write temp file: %w", err)
    }
    if err := tmp.Close(); err != nil {
        return nil, fmt.Errorf("failed to close temp file: %w", err)
    }
    
    return c.UploadFile(tmpFile)
    
  2. Keep the atomically created file descriptor open while writing; do not generate a name and then separately create it.

  3. Where supported, upload through an already-open file descriptor rather than reopening the pathname.

  4. Run the Skill under a dedicated, unprivileged operating-system account with access only to required files.

  5. Add concurrent-execution and symlink-resistance tests to verify that temporary files cannot collide with or overwrite pre-existing paths.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill accepts publication parameters and performs blockchain submission despite being described mainly as trigger-driven analysis. This context makes the issue more dangerous because it operates in a financial domain where a misleadingly labeled skill could cause unauthorized or accidental on-chain actions with real cost.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The strike command performs an on-chain publish operation, which is a state-changing blockchain action outside the skill's declared token-analysis scope. In an agent skill context, exposing transaction-capable commands materially increases risk because a caller may trigger irreversible writes, spend funds, or create authoritative records when they expected read-only analysis behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

These commands substantially broaden capability beyond token analysis, including discovery, minting, reputation/state queries, outcome recording, contract linking, and agent updates. In an agent setting, such scope expansion increases the blast radius from informational analysis to administrative and transactional blockchain actions, creating opportunities for misuse or accidental invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

set-inft links contracts in what is described as a one-time setup operation, effectively an administrative capability unrelated to ordinary token analysis. If accessible through a general-purpose skill, it could alter contract relationships or system configuration irreversibly, causing operational disruption or abuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

PublishStrike performs a signed, on-chain state-changing transaction using a locally available private key, which goes beyond passive token analysis and can spend gas and mutate contract state. In the context of an agent skill advertised for token intelligence, this expands capability into autonomous blockchain write actions, increasing the risk of unintended or prompted transaction submission.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

SetINFT can perform a one-time administrative contract linkage by sending a signed transaction, which is a privileged action unrelated to ordinary token analysis. If exposed through an agent workflow, a prompt-triggered or accidental invocation could permanently alter contract configuration and disrupt trust or ownership assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

RecordOutcome submits a signed transaction that updates on-chain strike outcome data, enabling the skill to modify system records rather than merely analyze them. In an agent setting, this is dangerous because prompted misuse, logic bugs, or compromised inputs could irreversibly write incorrect or manipulative outcomes to the blockchain while consuming funds.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This function mints an on-chain INFT by constructing, signing, and broadcasting a transaction, which is a state-changing blockchain action unrelated to the stated token-analysis scope. In a skill advertised as analysis/intelligence only, hidden write capabilities create a significant trust-boundary violation and can cause unauthorized asset creation or fee expenditure if invoked.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Reading a blockchain private key from environment variables gives the skill direct signing authority, which is unjustified for a token-analysis feature. In this context, the key enables silent value-bearing or state-changing transactions if any callable path reaches the signing logic, making the mismatch between declared scope and actual privilege especially dangerous.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This block signs and broadcasts a transaction using a privileged private key, confirming the skill has active transaction authority rather than passive analysis behavior. In a skill marketed for token intelligence, such hidden execution capability increases the chance of unauthorized chain writes, gas spending, and abuse if triggered by prompts or internal orchestration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This function updates on-chain contract state by signing and sending an updateIntelligence transaction, which exceeds an analysis-oriented skill's declared purpose. Because it can mutate blockchain state and spend gas using a loaded private key, it materially expands the skill's authority beyond what a user would reasonably expect.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares environment-variable requirements and invokes external binaries, but it does not declare an explicit tool/permission scope. That weakens sandboxing and reviewer visibility, making it easier for the skill to access sensitive configuration or execution capabilities without clear user/admin approval.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.