AgentStack
SKILL verified MIT Self-run

Tx Context Misuse

skill-omermaksutii-rugproof-tx-context-misuse · by omermaksutii

Detect misuse of tx.origin, block.timestamp, block.number — phishing via tx.origin, timestamp dependence, L2-block-number assumptions. Activate on `tx.origin`, `block.timestamp`, `block.number`, `blockhash`, `block.prevrandao`, `block.coinbase`.

No reviews yet
0 installs
26 views
0.0% view→install

Install

$ agentstack add skill-omermaksutii-rugproof-tx-context-misuse

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README — it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-omermaksutii-rugproof-tx-context-misuse)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Tx Context Misuse? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

tx.origin / timestamp / block-number misuse

When this applies

  • Auth checks using tx.origin
  • Time-based logic (lockups, deadlines, vesting, auctions)
  • Block-number-based rate limits or cooldowns
  • L2 deployments where block semantics differ from L1
  • Randomness derived from block data

Detection patterns

tx.origin for authorization (HIGH)

require(tx.origin == owner);   // ← phishable via intermediate contract

A contract the owner has interacted with can drain by calling back into this function — owner-EOA is tx.origin even if direct caller is the malicious contract.

Exception: tx.origin == msg.sender check to enforce EOA-only is sometimes valid for limiting bots — but EIP-7702 will invalidate even this. Flag as outdated pattern.

block.timestamp for high-precision deadlines (MEDIUM)

Miners (post-merge: validators) can skew timestamp ±~15s. Don't use for sub-15s precision.

block.timestamp as randomness (HIGH)

uint r = uint(keccak256(abi.encode(block.timestamp, msg.sender)));   // ← validator can simulate

block.number on L2 (HIGH)

Arbitrum: block.number is L1 block number, NOT L2. block.timestamp is L2. Optimism: block.number is L2. Get this wrong and rate limits fire 12x too fast (or too slow).

blockhash(n) with n outside [block.number-256, block.number-1] returns 0 (MEDIUM)

Random distribution becomes biased / predictable.

block.coinbase (validator address) used in logic (HIGH)

Validator can rotate addresses; using coinbase for auth or whitelisting is unsafe.

block.prevrandao for high-value randomness (HIGH)

Post-merge prevrandao is the previous block's randao; validators can sometimes choose to skip producing a block to influence it (limited but real). Don't use for valuable mints.

block.basefee as anti-MEV gate (LOW-MEDIUM)

Basefee can be manipulated within bounds by miners. Use sparingly.

Timestamp-based vesting cliffs (LOW)

Generally fine, but document tolerance for ±15s.

Severity rubric

| Pattern | Severity | |---|---| | tx.origin == admin for sensitive auth | High | | block.timestamp as RNG seed for valuable outcomes | High | | block.number confused L1-vs-L2 on Arbitrum | High | | block.coinbase for auth | High | | block.prevrandao for high-value mint | High | | Timestamp deadline with 0` but understand its limits.

  • Randomness: Chainlink VRF or commit-reveal.
  • L2 block-number: use chain-specific helper (ArbSys.arbBlockNumber() on Arbitrum, block.number on Optimism).
  • Timestamps: round to ~minute granularity for fairness-sensitive flows.
  • Validators-can-skew tolerance: bake in slack in deadlines (≥1 minute).

False-positive notes

  • block.timestamp for week/month-scale vesting → fine.
  • tx.origin in events for analytics → fine, not used for auth.
  • L2 chain-id detection via block.chainid is correct (always returns the canonical chain id).

Related

  • [[mev-frontrunning]] — randomness/RNG
  • [[access-control]]
  • [[signature-replay]]

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.