Back to skill

Security audit

Venus Agent Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill provides useful Venus risk analysis, but it also includes live fund-moving commands, raw private-key handling, and unrelated Flux transaction tooling that users should review carefully before installing.

Install only if you intentionally want an execution-capable DeFi operations skill, not just analysis. Do not paste real private keys into commands or AI chats; prefer external wallet signing. Treat broadcast examples as capable of moving funds or changing liquidation risk, and avoid the Flux commands unless you specifically intended to operate on Flux/Fluid as well as Venus.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/venus_deposit.js:43
Finding

Untrusted Venus API Data Controls Signed Transaction Destinations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/venus_withdraw.js:101
Finding

Venus Safety Checks Can Inspect a Different Wallet Than the Transaction Signer

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/quick-commands.md:43
Finding

Private Keys Are Accepted and Documented as Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/flux/self_test.sh:11
Finding

Flux Self-Test Writes Sensitive Position Output to Predictable Temporary Files

Content
View full analysis
/tmp/flux_markets_test.json echo "[2/4] position" node "$ROOT/position.js" --wallet "$WALLET" >/tmp/flux_position_test.json echo "[3/4] lend simulate" node "$ROOT/lend.js" --asset fUSDC --amount 0.01 --wallet "$WALLET" --mode simulate >/tmp/flux_lend_sim_test.json echo "[4/4] withdraw simulate" node "$ROOT/withdraw.js" --asset fUSDC --amount 0.01 --wallet "$WALLET" --mode simulate >/tmp/flux_withdraw_sim_test.json ``` ### Technical Analysis The script writes output to fixed filenames in the shared `/tmp` directory. It does not create the files atomically, check for symbolic links, set restrictive permissions, or remove the files after execution. On systems where `/tmp` is writable by multiple users, an attacker can pre-create one of these paths as a symbolic link. Shell redirection can then follow the link and truncate or overwrite another file writable by the user running the self-test. The output also remains available after completion and contains the wallet address and public on-chain position details. ### Attack Path 1. A local attacker predicts the fixed filename, such as `/tmp/flux_position_test.json`. 2. The attacker creates that path as a symbolic link to another file writable by the victim. 3. The victim runs `scripts/flux/self_test.sh`. 4. Shell redirection follows the symbolic link and truncates or overwrites the target with JSON output. 5. Alternatively, another local process reads the residual output file to associate a wallet with its Flux positions. ### Impact Assessment The attacker does not gain blockchain signing authority or private keys. The likely impact is local file corruption within the invoking user's existing permissions and disclosure of public w ...[truncated 153 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (61)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The quick commands instruct users to pass a private key directly for transaction broadcasting, which is unjustified for a risk-analysis skill and creates direct key-compromise risk. Private keys supplied on the command line may be exposed through shell history, process listings, logs, screenshots, or telemetry, enabling immediate theft of wallet assets.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill claims to be read-only, then later authorizes broadcasting real transactions after confirmation. Contradictory security semantics are particularly dangerous in agent systems because safety controls, user trust, and routing decisions often depend on the declared read-only status.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation explicitly includes broadcast-capable deposit, withdraw, borrow, repay, and collateral-management flows despite the manifest framing the skill as analysis and risk guidance. This is a direct security issue because it obscures dangerous state-changing functionality inside a skill users and orchestrators may treat as read-only.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains Flux protocol addresses on BNB Chain, while the skill is ներկայացված as a Venus Protocol operations skill. In a lending/borrowing risk-analysis context, using addresses from the wrong protocol can cause the agent to query incorrect contracts, produce false health/liquidation guidance, or route users toward unintended markets, which is especially dangerous for financial decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file documents Flux-specific operational scripts, including lend and withdraw actions, even though the skill is described as Venus-only and risk-analysis focused. This broadens the skill’s effective scope from analysis into cross-protocol transaction guidance, increasing the chance an agent could inappropriately assist with unrelated financial operations or invoke dangerous capabilities outside user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation explicitly includes broadcast commands that require a raw private key on the command line for lend and withdraw operations. In a skill intended for risk analysis, exposing secret-bearing, state-changing workflows is dangerous because it can normalize unsafe key handling, encourage transaction execution, and enable fund-moving actions far beyond read-only analysis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is described as analysis and risk guidance for Venus positions, but the quick commands include real transaction broadcasting for deposits. This creates a dangerous scope mismatch: users may trust an advisory skill with execution authority, increasing the chance of unintended onchain actions and asset loss if the skill is invoked in the wrong context or automated by an agent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation includes real withdraw execution and even a force-risk withdrawal path, despite the stated purpose being risk-first analysis. In a lending protocol context, withdrawals directly affect collateralization and can trigger liquidation or failed safety assumptions, so exposing execution in an analysis-oriented skill materially increases user harm potential.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Borrow, repay, and collateral-management commands go beyond analytics and advisory behavior into active protocol control. In the Venus context these actions can change leverage, debt exposure, and liquidation status, so undocumented execution authority is especially dangerous because users may believe they are only receiving analysis rather than enabling state-changing actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file documents operational scripts for Flux/Fluid on BNB Chain, including live lending and withdrawal workflows, while the skill is described as Venus Protocol analysis with risk-first guidance. This capability mismatch is dangerous because a user or downstream agent could be induced to perform real protocol actions on an unintended protocol, expanding the skill from analysis-only into transaction-affecting behavior without clear authorization boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation includes explicit broadcast commands with private-key input and confirmation flags, exposing transaction-execution paths that are not justified for a risk-analysis skill. In this context, the presence of ready-to-run live transaction commands materially increases the chance that an agent or user executes blockchain state-changing actions, potentially causing fund movement, loss, or unauthorized operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script clearly fetches Flux protocol market data using a Flux-specific resolver and emits protocol: 'flux', while the skill metadata claims the skill is for Venus Protocol operations. This mismatch can cause users or downstream agents to make lending, borrowing, and liquidation-risk decisions using data from the wrong protocol, which is especially dangerous in a DeFi risk-analysis context where market parameters differ materially between protocols.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This script does not merely analyze Venus Protocol positions as the skill metadata claims; it performs Flux lending operations and can broadcast real on-chain transactions. That mismatch is dangerous because users or higher-level agents may invoke it expecting read-only risk analysis, but instead be exposed to unintended asset approvals and deposits on an unrelated protocol.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The broadcast path accepts a private key, approves token spending, and executes a deposit transaction, giving the skill direct on-chain write capability. In the context of a risk-analysis skill, this is unjustified and especially dangerous because a caller could be misled into providing signing material for what should be a read-only advisory function, leading to unauthorized or unsafe fund movement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.