Back to skill

Security audit

Swimmer Custodial Stock Orders

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed, scoped trading skill, but using it can irreversibly send real tokens to a custodian.

Install only if you understand that this is not an atomic swap: signing sends funds to a custodial recipient and settlement is off-chain. Use a dedicated low-balance wallet, independently verify the recipient, stock mints, and current Swimmer terms from official sources, and authorize only an exact transfer amount and digest you intended.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt automatically encourages use of the trading skill with a broad phrase ('Use $swimmer-stock-trading') rather than narrowly constraining when invocation is appropriate. In a high-risk financial skill that can prepare or facilitate irreversible custodial transfers, this increases the chance of accidental or context-inappropriate activation, which could steer users into risky transaction flows without sufficiently explicit intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_solana_sign_send.py:19