T09 · Insecure Skill Coding Practices
- Location
SKILL.md:624- Finding
Wallet Private Key Embedded Directly in Executable Source
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 624-648
Vulnerability Type: Plaintext secret handling in source code
Risk Level: HighVulnerable Code
javascript const API = 'https://api.taskmaster.tech'; const PRIVATE_KEY = 'your_key'; const TASK_ID = 'cmnge2qj1000k1ykjl704k7a2'; const RPC = 'https://base.publicnode.com'; // fallback // 1. Login const wallet = new ethers.Wallet(PRIVATE_KEY); const challenge = await fetch(`${API}/auth/challenge`).then(r => r.json()); const sig = await wallet.signMessage(`TaskMaster login\nNonce: ${challenge.nonce}`); const login = await fetch(`${API}/auth/sign-in`, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ walletAddress: wallet.address, nonce: challenge.nonce, signature: sig }) }).then(r => r.json()); const jwt = login.token; // 2. Get task const task = await fetch(`${API}/tasks/${TASK_ID}`, { headers: { 'Authorization': `Bearer ${jwt}` } }).then(r => r.json()); const { escrowId, chain, contractAddress } = task; const chains = await fetch(`${API}/chains`).then(r => r.json()); const chainConfig = chains[chain]; // 3. Accept on-chain const provider = new ethers.JsonRpcProvider(RPC); const signer = new ethers.Wallet(PRIVATE_KEY, provider);The quickstart workflow at
SKILL.md:32-47also documents a remote API response containing a generated wallet private key and mnemonic:json { "apiKey": "tm_...", "wallet": { "address": "0x...", "privateKey": "0x...", "mnemonic": "..." }, "gasDrip": { "chains": ["base", "op", "arb"], "amount": "0.00001 ETH per chain" } }Technical Analysis
The executable example instructs users to place a cryptocurrency private key in a plaintext source-code constant. Source files are commonly exposed through version-control commits, backups, logs, support bundle ...[truncated 2100 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the plaintext
PRIVATE_KEYconstant from all examples. - Use a hardware wallet, isolated signing service, encrypted keystore, or operating-system secret manager.
- If environment variables are demonstrated, clearly state that they are only an improvement over source embedding and may still leak through process inspection, debug output, CI configuration, or shell history.
- Generate wallets locally with audited software instead of relying on a remote service to generate private keys.
- Clearly warn users not to place substantial funds in remotely generated wallets.
- Use a dedicated low-value wallet with only the assets and permissions required for the current task.
- Never log private keys, mnemonics, signed raw transactions, or bearer tokens.
- Add secret-scanning controls to repositories and CI pipelines.
- If exposure is suspected, immediately migrate assets to a newly generated wallet and revoke token allowances associated with the compromised address.
- Remove the plaintext
