Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[dApp] Sky Marvel | skyBridge-Backend | Jan2025

Date:

Feb 5, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Sky Marvel team for the collaborative engagement that enabled the execution of this dApp Security Assessment.

Sky Marvel is a financial technology company that offers a diverse range of cryptocurrency-related products and services.

Document

NamedApp Code Review and Security Analysis Report for Sky Marvel
Audited BySam Ronald
Approved ByStephen Ajayi
Websitehttps://skymarvel.io/→
Changelog29/01/2025 - Preliminary Report
Changelog05/02/2025 - Final Report
LanguageTypeScript, JavaScript, Docker
TagsBridge, Whitebox
Methodologyhttps://hackenio.cc/dApp_methodology→
  • Document

    Name
    dApp Code Review and Security Analysis Report for Sky Marvel
    Audited By
    Sam Ronald
    Approved By
    Stephen Ajayi
    Changelog
    29/01/2025 - Preliminary Report
    Changelog
    05/02/2025 - Final Report
    Language
    TypeScript, JavaScript, Docker
    Tags
    Bridge, Whitebox

Review Scope

Repositoryhttps://github.com/TheRavneet/skyBridge-Backend.git→
Commit6b883850ce2963819f8ca9892ff14c70603ec15b
Final Commit77c3dc2ba88cbbdd00849fe67fa5830d3164575b

Audit Summary

13Total Findings
10Resolved
3Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • A structured and modular directory layout enhances codebase navigation.

  • Inclusion of deployment-related files, such as Dockerfile and .dockerignore, indicates deployment readiness.

  • Utilization of TypeScript enables type-safe and well-documented code.

  • Expand the README.md to include detailed setup, deployment, and testing instructions.

  • Improve API documentation security by restricting access in non-development environments.

  • Add more inline comments and comprehensive module-level documentation for better understanding of complex logic.

  • Include contribution guidelines and a changelog to streamline collaboration and version tracking.

Code quality

  • Modular architecture with clear separation of concerns supports maintainability and scalability.

  • Centralized handling of utilities and exception logic promotes code reuse.

  • Adherence to TypeScript ensures enhanced reliability and error reduction.

  • Inclusion of cryptographic key files indicates a focus on secure operations.

  • Implement consistent and centralized error handling to improve resilience and fault tolerance.

  • Optimize batch processing mechanisms to prevent resource overuse and enhance performance.

System Overview

The project is a backend system designed for a blockchain-based bridge solution, enabling cross-chain transactions and interactions. Its architecture and features is focused on managing secure, scalable, and modular operations within a blockchain ecosystem.

Key Features and Functionality

  1. Cross-Chain Operations: Facilitates interactions and transactions across multiple blockchain networks.

  2. Secure Key Management: Includes cryptographic keys (private-key.pem and public-certificate.pem) for secure communications and operations.

  3. API-Driven Architecture: Provides endpoints for managing operations, likely including transaction handling, state synchronization, and administrative actions.

  4. Event and Order Management: Includes services and repositories to manage events and orders effectively within the system.

  5. Containerized Deployment: Supports containerization for deployment via Docker.

Key Project Files

  1. main.ts: The entry point for the application, initializing the core modules and configurations.

  2. app.module.ts: The root module, orchestrating dependency injection and bootstrapping submodules.

  3. app.service.ts: Contains shared application-level business logic.

  4. Dockerfile and .dockerignore: Define the environment and files required for containerized deployment.

  5. package.json: Manages project dependencies and scripts for building, testing, and running the application.

  6. nest-cli.json: Configuration file for the NestJS framework, providing structural and compilation settings.

  7. src/modulesHouses core functional modules, each encapsulating specific features or services.

  8. src/services: Contains service files implementing core business logic, likely interacting with blockchain nodes and external services.

  9. src/repositories: Handles data persistence and retrieval operations, abstracting database interactions.

  10. src/utils: Utility functions supporting generic, reusable operations across the project.

Findings

F-2025-8421Unsecured Order Execution Due to Missing Nonce Validation
Status
fixed
Severity

Medium
F-2025-8492Insufficient CORS Configuration
Status
fixed
Severity

Low
F-2025-8489Insufficient Validation of Client-Provided Data
Status
fixed
Severity

Low
F-2025-8419Inadequate API Rate Limiting for Admin Routes
Status
accepted
Severity

Low
F-2025-8414Lack of Input Validation in handleTrigger
Status
fixed
Severity

Low
F-2025-8306Multiple Vulnerable Third-Party Libraries
Status
accepted
Severity

Low
F-2025-8305Non-Literal Regular Expression Injection Leading to ReDoS
Status
accepted
Severity

Low
F-2025-8495Disabled Logging in Non-Stage Environments
Status
fixed
Severity

Observation
F-2025-8493Disabled HTTPS Configuration
Status
fixed
Severity

Observation
F-2025-8488Missing Error Handling
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2025-8421Unsecured Order Execution Due to Missing Nonce Validation
fixed

Medium
F-2025-8492Insufficient CORS Configuration
fixed

Low
F-2025-8489Insufficient Validation of Client-Provided Data
fixed

Low
F-2025-8419Inadequate API Rate Limiting for Admin Routes
accepted

Low
F-2025-8414Lack of Input Validation in handleTrigger
fixed

Low
F-2025-8306Multiple Vulnerable Third-Party Libraries
accepted

Low
F-2025-8305Non-Literal Regular Expression Injection Leading to ReDoS
accepted

Low
F-2025-8495Disabled Logging in Non-Stage Environments
fixed

Observation
F-2025-8493Disabled HTTPS Configuration
fixed

Observation
F-2025-8488Missing Error Handling
fixed

Observation
1-10 of 13 findings

Protect your dApp with insights like these.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following from the provided repository:

Scope Details

Repositoryhttps://github.com/TheRavneet/skyBridge-Backend.git→
Commit6b883850ce2963819f8ca9892ff14c70603ec15b
Final Cmmit77c3dc2ba88cbbdd00849fe67fa5830d3164575b

Disclaimer