Introduction
We express our gratitude to the Sky Marvel team for the collaborative engagement that enabled the execution of this dApp Security Assessment.
Sky Marvel is a financial technology company that offers a diverse range of cryptocurrency-related products and services.
Document | |
|---|---|
| Name | dApp Code Review and Security Analysis Report for Sky Marvel |
| Audited By | Sam Ronald |
| Approved By | Stephen Ajayi |
| Website | https://skymarvel.io/→ |
| Changelog | 29/01/2025 - Preliminary Report |
| Changelog | 05/02/2025 - Final Report |
| Language | TypeScript, JavaScript, Docker |
| Tags | Bridge, Whitebox |
| Methodology | https://hackenio.cc/dApp_methodology→ |
Document
- Name
- dApp Code Review and Security Analysis Report for Sky Marvel
- Audited By
- Sam Ronald
- Approved By
- Stephen Ajayi
- Website
- https://skymarvel.io/→
- Changelog
- 29/01/2025 - Preliminary Report
- Changelog
- 05/02/2025 - Final Report
- Language
- TypeScript, JavaScript, Docker
- Tags
- Bridge, Whitebox
- Methodology
- https://hackenio.cc/dApp_methodology→
Review Scope | |
|---|---|
| Repository | https://github.com/TheRavneet/skyBridge-Backend.git→ |
| Commit | 6b883850ce2963819f8ca9892ff14c70603ec15b |
| Final Commit | 77c3dc2ba88cbbdd00849fe67fa5830d3164575b |
Review Scope
- Commit
- 6b883850ce2963819f8ca9892ff14c70603ec15b
- Final Commit
- 77c3dc2ba88cbbdd00849fe67fa5830d3164575b
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
A structured and modular directory layout enhances codebase navigation.
Inclusion of deployment-related files, such as
Dockerfileand.dockerignore, indicates deployment readiness.Utilization of TypeScript enables type-safe and well-documented code.
Expand the
README.mdto include detailed setup, deployment, and testing instructions.Improve API documentation security by restricting access in non-development environments.
Add more inline comments and comprehensive module-level documentation for better understanding of complex logic.
Include contribution guidelines and a changelog to streamline collaboration and version tracking.
Code quality
Modular architecture with clear separation of concerns supports maintainability and scalability.
Centralized handling of utilities and exception logic promotes code reuse.
Adherence to TypeScript ensures enhanced reliability and error reduction.
Inclusion of cryptographic key files indicates a focus on secure operations.
Implement consistent and centralized error handling to improve resilience and fault tolerance.
Optimize batch processing mechanisms to prevent resource overuse and enhance performance.
System Overview
The project is a backend system designed for a blockchain-based bridge solution, enabling cross-chain transactions and interactions. Its architecture and features is focused on managing secure, scalable, and modular operations within a blockchain ecosystem.
Key Features and Functionality
Cross-Chain Operations: Facilitates interactions and transactions across multiple blockchain networks.
Secure Key Management: Includes cryptographic keys (
private-key.pemandpublic-certificate.pem) for secure communications and operations.API-Driven Architecture: Provides endpoints for managing operations, likely including transaction handling, state synchronization, and administrative actions.
Event and Order Management: Includes services and repositories to manage events and orders effectively within the system.
Containerized Deployment: Supports containerization for deployment via Docker.
Key Project Files
main.ts: The entry point for the application, initializing the core modules and configurations.app.module.ts: The root module, orchestrating dependency injection and bootstrapping submodules.app.service.ts: Contains shared application-level business logic.Dockerfileand.dockerignore: Define the environment and files required for containerized deployment.package.json: Manages project dependencies and scripts for building, testing, and running the application.nest-cli.json: Configuration file for the NestJS framework, providing structural and compilation settings.src/modulesHouses core functional modules, each encapsulating specific features or services.src/services: Contains service files implementing core business logic, likely interacting with blockchain nodes and external services.src/repositories: Handles data persistence and retrieval operations, abstracting database interactions.src/utils: Utility functions supporting generic, reusable operations across the project.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-8421 | Unsecured Order Execution Due to Missing Nonce Validation | fixed | Medium | |
| F-2025-8492 | Insufficient CORS Configuration | fixed | Low | |
| F-2025-8489 | Insufficient Validation of Client-Provided Data | fixed | Low | |
| F-2025-8419 | Inadequate API Rate Limiting for Admin Routes | accepted | Low | |
| F-2025-8414 | Lack of Input Validation in handleTrigger | fixed | Low | |
| F-2025-8306 | Multiple Vulnerable Third-Party Libraries | accepted | Low | |
| F-2025-8305 | Non-Literal Regular Expression Injection Leading to ReDoS | accepted | Low | |
| F-2025-8495 | Disabled Logging in Non-Stage Environments | fixed | Observation | |
| F-2025-8493 | Disabled HTTPS Configuration | fixed | Observation | |
| F-2025-8488 | Missing Error Handling | fixed | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the following from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/TheRavneet/skyBridge-Backend.git→ |
| Commit | 6b883850ce2963819f8ca9892ff14c70603ec15b |
| Final Cmmit | 77c3dc2ba88cbbdd00849fe67fa5830d3164575b |
Scope Details
- Commit
- 6b883850ce2963819f8ca9892ff14c70603ec15b
- Final Cmmit
- 77c3dc2ba88cbbdd00849fe67fa5830d3164575b