T09 · Insecure Skill Coding Practices
- Location
scripts/venus_deposit.js:43- Finding
Untrusted Venus API Data Controls Signed Transaction Destinations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill provides useful Venus risk analysis, but it also includes live fund-moving commands, raw private-key handling, and unrelated Flux transaction tooling that users should review carefully before installing.
Install only if you intentionally want an execution-capable DeFi operations skill, not just analysis. Do not paste real private keys into commands or AI chats; prefer external wallet signing. Treat broadcast examples as capable of moving funds or changing liquidation risk, and avoid the Flux commands unless you specifically intended to operate on Flux/Fluid as well as Venus.
scripts/venus_deposit.js:43Untrusted Venus API Data Controls Signed Transaction Destinations
scripts/venus_withdraw.js:101Venus Safety Checks Can Inspect a Different Wallet Than the Transaction Signer
references/quick-commands.md:43Private Keys Are Accepted and Documented as Command-Line Arguments
scripts/flux/self_test.sh:11Flux Self-Test Writes Sensitive Position Output to Predictable Temporary Files
The quick commands instruct users to pass a private key directly for transaction broadcasting, which is unjustified for a risk-analysis skill and creates direct key-compromise risk. Private keys supplied on the command line may be exposed through shell history, process listings, logs, screenshots, or telemetry, enabling immediate theft of wallet assets.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
Withdrawal/redeem operations are live asset movements, not analytical guidance. Presenting these under a risk-advice skill creates a serious expectation mismatch that is especially dangerous in DeFi, where a mistaken redemption can trigger health deterioration, liquidation risk, or irreversible fund movements.
The skill claims to be read-only, then later authorizes broadcasting real transactions after confirmation. Contradictory security semantics are particularly dangerous in agent systems because safety controls, user trust, and routing decisions often depend on the declared read-only status.
The documentation explicitly includes broadcast-capable deposit, withdraw, borrow, repay, and collateral-management flows despite the manifest framing the skill as analysis and risk guidance. This is a direct security issue because it obscures dangerous state-changing functionality inside a skill users and orchestrators may treat as read-only.
The file contains Flux protocol addresses on BNB Chain, while the skill is ներկայացված as a Venus Protocol operations skill. In a lending/borrowing risk-analysis context, using addresses from the wrong protocol can cause the agent to query incorrect contracts, produce false health/liquidation guidance, or route users toward unintended markets, which is especially dangerous for financial decisions.
The file documents Flux-specific operational scripts, including lend and withdraw actions, even though the skill is described as Venus-only and risk-analysis focused. This broadens the skill’s effective scope from analysis into cross-protocol transaction guidance, increasing the chance an agent could inappropriately assist with unrelated financial operations or invoke dangerous capabilities outside user expectations.
The documentation explicitly includes broadcast commands that require a raw private key on the command line for lend and withdraw operations. In a skill intended for risk analysis, exposing secret-bearing, state-changing workflows is dangerous because it can normalize unsafe key handling, encourage transaction execution, and enable fund-moving actions far beyond read-only analysis.
The skill is described as analysis and risk guidance for Venus positions, but the quick commands include real transaction broadcasting for deposits. This creates a dangerous scope mismatch: users may trust an advisory skill with execution authority, increasing the chance of unintended onchain actions and asset loss if the skill is invoked in the wrong context or automated by an agent.
The documentation includes real withdraw execution and even a force-risk withdrawal path, despite the stated purpose being risk-first analysis. In a lending protocol context, withdrawals directly affect collateralization and can trigger liquidation or failed safety assumptions, so exposing execution in an analysis-oriented skill materially increases user harm potential.
Borrow, repay, and collateral-management commands go beyond analytics and advisory behavior into active protocol control. In the Venus context these actions can change leverage, debt exposure, and liquidation status, so undocumented execution authority is especially dangerous because users may believe they are only receiving analysis rather than enabling state-changing actions.
The file documents operational scripts for Flux/Fluid on BNB Chain, including live lending and withdrawal workflows, while the skill is described as Venus Protocol analysis with risk-first guidance. This capability mismatch is dangerous because a user or downstream agent could be induced to perform real protocol actions on an unintended protocol, expanding the skill from analysis-only into transaction-affecting behavior without clear authorization boundaries.
The documentation includes explicit broadcast commands with private-key input and confirmation flags, exposing transaction-execution paths that are not justified for a risk-analysis skill. In this context, the presence of ready-to-run live transaction commands materially increases the chance that an agent or user executes blockchain state-changing actions, potentially causing fund movement, loss, or unauthorized operations.
The script clearly fetches Flux protocol market data using a Flux-specific resolver and emits protocol: 'flux', while the skill metadata claims the skill is for Venus Protocol operations. This mismatch can cause users or downstream agents to make lending, borrowing, and liquidation-risk decisions using data from the wrong protocol, which is especially dangerous in a DeFi risk-analysis context where market parameters differ materially between protocols.
This script does not merely analyze Venus Protocol positions as the skill metadata claims; it performs Flux lending operations and can broadcast real on-chain transactions. That mismatch is dangerous because users or higher-level agents may invoke it expecting read-only risk analysis, but instead be exposed to unintended asset approvals and deposits on an unrelated protocol.
The broadcast path accepts a private key, approves token spending, and executes a deposit transaction, giving the skill direct on-chain write capability. In the context of a risk-analysis skill, this is unjustified and especially dangerous because a caller could be misled into providing signing material for what should be a read-only advisory function, leading to unauthorized or unsafe fund movement.
No suspicious patterns detected.