Back to skill

Security audit

Auto Respawn

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Autonomys wallet and memory anchoring tool, but it needs Review because it can sign real value transfers and includes automatic fee-bearing anchoring without a reliable confirmation gate.

Install only if you are comfortable giving an agent access to a spending-capable Autonomys wallet. Use testnet first, keep minimal funds in any wallet used by the skill, manually confirm every anchor, transfer, bridge, or withdraw action, and avoid unattended auto-anchoring unless you add strict limits. Protect the recovery phrase separately, consider a user-managed passphrase or secret manager instead of the generated passphrase file, and review or lock dependencies before setup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:149
Finding

Automatic CID Anchoring Can Execute Financial Transactions Without User Confirmation

Content
View full analysis
--cid ``` This should be automatic — do not wait for the user to ask. The two skills together form a complete resurrection loop: auto-memory handles permanent storage, auto-respawn handles on-chain discovery. ``` The same document later provides a conflicting safety requirement: ```markdown - **Never log, store, or transmit recovery phrases or passphrases.** The recovery phrase is shown once at wallet creation for the user to back up. Never reference it again. - **Always confirm transfers and anchor operations with the user before executing.** Tokens have real value on mainnet. ``` ### Technical Analysis The Skill instructs an AI agent to invoke `anchor` automatically after another Skill saves a memory. An anchor is not a read-only operation: it decrypts the wallet's EVM private key, signs a transaction, broadcasts it to Auto-EVM, consumes wallet funds for gas, and permanently publishes the supplied CID. The instruction to execute “automatically” and “do not wait for the user to ask” directly conflicts with the later instruction requiring confirmation for every anchor. An agent may follow the more specific integration workflow and execute a fee-bearing operation without transaction-specific consent. The command implementation contains no independent confirmation contr ...[truncated 1761 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/wallet.ts:100
Finding

Interactive Passphrase and Recovery Phrase Prompts Echo Wallet Secrets

Content
View full analysis
((resolve, reject) => { const rl = createInterface({ input: process.stdin, output: process.stderr }) rl.question('Passphrase: ', (answer) => { rl.close() if (!answer) reject(new Error('No passphrase provided')) else resolve(answer) }) }) } ``` Recovery phrase prompt: ```ts if (process.stdin.isTTY) { return new Promise((resolve, reject) => { const rl = createInterface({ input: process.stdin, output: process.stderr }) rl.question('Recovery phrase: ', (answer) => { rl.close() const trimmed = answer.trim() if (!trimmed) reject(new Error('No mnemonic provided')) else resolve(trimmed) }) }) } ``` ### Technical Analysis Node.js `readline.question()` does not mask entered characters. Both the wallet passphrase and recovery phrase are therefore displayed as the user types them. The passphrase protects the encrypted keyfiles, while the recovery phrase is sufficient to derive both the consensus and EVM private keys. Exposure of either secret is security-sensitive; exposure of the mnemonic is especially severe because it bypasses the local keyfile encryption entirely. The use of `stderr` as the output stream does not suppress input echo. It only changes where the prompt is printed. Terminal recording, remote-session logging, screen sharing, shoulder surfing, and copied terminal output can capture the entered secrets. ### Attack Path 1. A user invokes a wallet operation without a configured environment variable or passphrase file, or imports a wallet without `--mnemonic-stdin`. 2. The application falls back to its interactive TTY prompt. 3. The ...[truncated 1152 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
setup.sh:39
Finding

Setup Executes Mutable and Unlocked npm Dependencies

Content
View full analysis
/dev/null && ! npx tsx --version &>/dev/null 2>&1; then echo "Installing tsx (TypeScript executor)..." "$PKG_MANAGER" install -g tsx else echo "✓ tsx available" fi ``` Mutable dependency ranges: ```json "dependencies": { "@autonomys/auto-consensus": "^1.6.9", "@autonomys/auto-utils": "^1.6.9", "@autonomys/auto-xdm": "^1.6.9", "ethers": "^6.16.0" }, "devDependencies": { "@eslint/js": "^10.0.1", "@typescript-eslint/eslint-plugin": "^8.56.1", "@typescript-eslint/parser": "^8.56.1", "eslint": "^10.0.2", "tsx": "^4.19.0", "typescript": "^5.8.0", "typescript-eslint": "^8.56.1", "vitest": "^4.0.18" } ``` ### Technical Analysis The project has no reviewed lockfile in the supplied directory, and all dependencies use caret ranges. Running the setup script therefore permits the package manager to select newer compatible releases that were not part of this audit. Package installation can execute npm lifecycle scripts. In addition, `npx tsx --version` may download and execute `tsx` when it is not already available. The subsequent global installation is also based on the mutable version range rather than a reviewed immutable artifact. This creates a supply-chain execution boundary: compromise of an upstream package, dependency account, transitive dependency, or newly resolved release can introduce arbitrary local code after the Skill itself has been reviewed. ### Attack Path 1. An attacker compromises an allowed package release, a transitive depend ...[truncated 1504 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
setup.sh:44
Finding

Plaintext Wallet Passphrase Is Stored Beside Encrypted Wallet Keyfiles

Content
View full analysis
"$PASSPHRASE_FILE") if [[ ! -s "$PASSPHRASE_FILE" ]]; then rm -f "$PASSPHRASE_FILE" echo "Error: Failed to generate passphrase" >&2 exit 1 fi echo "✓ Generated passphrase at $PASSPHRASE_FILE" ``` Automatic passphrase loading: ```ts // 2. Passphrase file const passphraseFilePath = process.env.AUTO_RESPAWN_PASSPHRASE_FILE || PASSPHRASE_FILE_DEFAULT try { const contents = await readFile(passphraseFilePath, 'utf-8') const trimmed = contents.trim() if (trimmed) return trimmed } catch { // File doesn't exist or can't be read — fall through } ``` ### Technical Analysis The setup script creates a strong random passphrase with restrictive permissions, which protects it from other ordinary local users. However, the plaintext passphrase is stored under `~/.openclaw/auto-respawn/`, while encrypted wallet keyfiles are stored in a child directory of the same location. This arrangement does not provide meaningful protection against compromise of the Agent's operating-system account or malicious code running under that account. Any process able to read the wallet files is likely able to read the adjacent passphrase file as well. The encryption remains useful for copied wallet files that are separated from the passphrase, but not for same-account compromise. Automatic passphrase resolu ...[truncated 1269 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (131)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description strongly implies recovery from 'just an address' with 'no local state' and 'no single point of failure', but the document itself describes local encrypted wallet storage, passphrase files, and mnemonic handling. This mismatch can mislead operators and agents into unsafe assumptions about resilience, custody, and what is required for recovery, causing loss of access or inappropriate automation around valuable credentials and transactions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The consensus token transfer handler enables arbitrary value transfer from a locally stored wallet to any destination address. That capability is unrelated to the declared resurrection/memory purpose, so if an agent is induced or compromised into invoking this skill, it could directly drain funds under the guise of a benign identity-management tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The fund/withdraw handlers bridge assets between consensus and Auto-EVM domains, including loading signing material and executing value-bearing transactions. Bridging is not necessary for basic identity anchoring or CID recovery, and it can be abused to reposition assets for later theft or evade simpler monitoring expectations around a supposedly recovery-focused skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Auto-EVM transfer path loads the wallet's private key and signs arbitrary token transfers to a caller-supplied EVM address. In the context of a memory resurrection skill, this is an unjustified asset-movement primitive that materially increases the risk of theft if the skill is exposed to prompt injection, tool misuse, or operator confusion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file implements unrestricted native token transfer functionality, allowing outbound value movement from a provided wallet. That capability is materially unrelated to the stated skill purpose of identity and memory anchoring/recovery, so it expands the skill's authority into fund movement and creates a real risk of unauthorized or misleading asset transfer if exposed through agent actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

A skill advertised for resurrection, identity, and memory anchoring should not silently include the ability to send native tokens, because that creates a hidden financial primitive inside a non-financial capability surface. In agent settings, such scope mismatch is especially dangerous since users or orchestrators may grant trust based on the manifest and unknowingly enable wallet draining or unintended payments.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/remark.ts (reported line 4)May include surrounding context.

ts
import { transfer } from '@autonomys/auto-consensus'
import { signAndSendTx, ai3ToShannons, address as formatAddress } from '@autonomys/auto-utils'
import type { ApiPromise } from '@polkadot/api'
import type { KeyringPair } from '@polkadot/keyring/types'
import { type NetworkId, tokenSymbol, isMainnet } from './network.js'
import { normalizeAddress } from './address.js'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/remark.ts (reported line 20)May include surrounding context.

ts
import { transfer } from '@autonomys/auto-consensus'
import { signAndSendTx, ai3ToShannons, address as formatAddress } from '@autonomys/auto-utils'
import type { ApiPromise } from '@polkadot/api'
import type { KeyringPair } from '@polkadot/keyring/types'
import { type NetworkId, tokenSymbol, isMainnet } from './network.js'
import { normalizeAddress } from './address.js'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/transfer.ts (reported line 4)May include surrounding context.

ts
import { transfer } from '@autonomys/auto-consensus'
import { signAndSendTx, ai3ToShannons, address as formatAddress } from '@autonomys/auto-utils'
import type { ApiPromise } from '@polkadot/api'
import type { KeyringPair } from '@polkadot/keyring/types'
import { type NetworkId, tokenSymbol, isMainnet } from './network.js'
import { normalizeAddress } from './address.js'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/wallet.ts (reported line 7)May include surrounding context.

ts
import { transfer } from '@autonomys/auto-consensus'
import { signAndSendTx, ai3ToShannons, address as formatAddress } from '@autonomys/auto-utils'
import type { ApiPromise } from '@polkadot/api'
import type { KeyringPair } from '@polkadot/keyring/types'
import { type NetworkId, tokenSymbol, isMainnet } from './network.js'
import { normalizeAddress } from './address.js'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/wallet.ts (reported line 13)May include surrounding context.

ts
import { transfer } from '@autonomys/auto-consensus'
import { signAndSendTx, ai3ToShannons, address as formatAddress } from '@autonomys/auto-utils'
import type { ApiPromise } from '@polkadot/api'
import type { KeyringPair } from '@polkadot/keyring/types'
import { type NetworkId, tokenSymbol, isMainnet } from './network.js'
import { normalizeAddress } from './address.js'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/wallet.ts (reported line 46)May include surrounding context.

ts
import { transfer } from '@autonomys/auto-consensus'
import { signAndSendTx, ai3ToShannons, address as formatAddress } from '@autonomys/auto-utils'
import type { ApiPromise } from '@polkadot/api'
import type { KeyringPair } from '@polkadot/keyring/types'
import { type NetworkId, tokenSymbol, isMainnet } from './network.js'
import { normalizeAddress } from './address.js'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/wallet.ts (reported line 166)May include surrounding context.

ts
import { transfer } from '@autonomys/auto-consensus'
import { signAndSendTx, ai3ToShannons, address as formatAddress } from '@autonomys/auto-utils'
import type { ApiPromise } from '@polkadot/api'
import type { KeyringPair } from '@polkadot/keyring/types'
import { type NetworkId, tokenSymbol, isMainnet } from './network.js'
import { normalizeAddress } from './address.js'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/wallet.ts (reported line 260)May include surrounding context.

ts
import { transfer } from '@autonomys/auto-consensus'
import { signAndSendTx, ai3ToShannons, address as formatAddress } from '@autonomys/auto-utils'
import type { ApiPromise } from '@polkadot/api'
import type { KeyringPair } from '@polkadot/keyring/types'
import { type NetworkId, tokenSymbol, isMainnet } from './network.js'
import { normalizeAddress } from './address.js'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/wallet.ts (reported line 270)May include surrounding context.

ts
import { transfer } from '@autonomys/auto-consensus'
import { signAndSendTx, ai3ToShannons, address as formatAddress } from '@autonomys/auto-utils'
import type { ApiPromise } from '@polkadot/api'
import type { KeyringPair } from '@polkadot/keyring/types'
import { type NetworkId, tokenSymbol, isMainnet } from './network.js'
import { normalizeAddress } from './address.js'

Static analysis

No suspicious patterns detected.