Back to skill

Security audit

Audit Verification Pipeline

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Solidity audit verification checklist skill, with no bundled executable code or hidden data access, though its example CI workflow should be hardened before use.

Install only if you are comfortable with a Chinese-language Solidity/Foundry audit workflow. Before copying the CI example into a repository, pin GitHub Actions to full commit SHAs, set explicit least-privilege permissions, and keep the external-submission step under human review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:128
Finding

Mutable GitHub Actions References Create a CI Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 128-129
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

yaml
- uses: actions/checkout@v4
- uses: foundry-rs/foundry-toolchain@v1

Technical Analysis

The proposed GitHub Actions workflow references third-party actions through mutable version tags instead of immutable full commit SHA values. A tag may resolve to code that differs from the version originally reviewed. Following the documented workflow therefore causes CI to retrieve and execute external components whose effective implementations can change after this Skill has been audited.

This is particularly significant because GitHub Actions execute within the CI job context and may have access to the checked-out repository, workflow artifacts, the GITHUB_TOKEN, and any secrets intentionally exposed to the job. The risk depends on the repository's workflow permissions, event triggers, secret configuration, and upstream action security.

Attack Path

  1. A user adopts the workflow documented in SKILL.md.
  2. An attacker compromises an upstream action repository, release process, maintainer account, or mutable version reference.
  3. The referenced @v4 or @v1 tag begins resolving to modified action code.
  4. A push or pull request triggers the audit workflow.
  5. GitHub retrieves and executes the modified action in the CI runner.
  6. The malicious action accesses resources available to the job, potentially reads repository content or exposed credentials, modifies artifacts, or falsifies build and test results.

Impact Assessment

Successful exploitation can execute attacker-controlled code with the permissions of the affected CI job. The potential scope includes repository source code, generated artifacts, writable repository operations allowed by GITHUB_TOKEN, and workflow secrets made available in that execution context. It may also c ...[truncated 374 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every GitHub Action to a reviewed full commit SHA rather than a mutable tag:
    yaml
    - uses: actions/checkout@<reviewed-full-commit-sha>
    - uses: foundry-rs/foundry-toolchain@<reviewed-full-commit-sha>
    
  • Add comments beside each SHA recording the corresponding release version for maintainability.
  • Use dependency-update automation to submit reviewed pull requests when newer action revisions become available.
  • Declare least-privilege workflow permissions explicitly, using permissions: contents: read unless additional access is demonstrably required.
  • Do not expose privileged secrets to workflows triggered by untrusted pull requests.
  • Review the source and provenance of action updates before changing pinned revisions.
  • Apply branch protection and require human review for workflow-file modifications.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is written entirely in Chinese and the document also mixes Chinese-only operational instructions, but there is no indication that the skill is region-specific or that users can opt into that language. This creates a natural-language locale policy issue because the skill implicitly requires a specific language rather than offering a choice.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

Level 3: Auditor Review (novelty, severity, quality)

text

Serial dependency: L1 → L2 → L3. Skipping levels = no verification.

## Level 1: Self-Verification

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The workflow step '提交宝总决策' embeds a specific Chinese-language reviewer reference as part of the required process. In the absence of documented locale constraints or alternatives, this reinforces a fixed language/cultural assumption that may violate organizational language-choice expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.