T09 · Insecure Skill Coding Practices
- Location
scripts/_helpers.js:139- Finding
Wallet Password Exposure Through Command-Line Arguments
- Content
View full analysis
or run in an interactive terminal"); } ``` The Skill instructions explicitly direct the agent to use this mechanism: ```text When the user asks to create a wallet: 1. Ask the user for a password first (do NOT generate one). 2. Pass it via `--password ` to the script when running non-interactively. 3. The password is auto-saved to secure storage after creation. 4. Never print the password back to the chat. ``` The same command-line password is also used while loading an existing wallet: ```js export async function loadWallet(client, address, args) { try { return await client.wallet.load(address); } catch { if (args.password) { return await client.wallet.load(address, args.password); } const ttyPassword = await promptHidden(`Password for ${address}: `); if (ttyPassword) { return await client.wallet.load(address, ttyPassword); } exitError(`Password required for ${address}: use --password or run in an interactive terminal`); } } ``` ### Technical Analysis Supplying a wallet password as `--password ` places the secret in the process argument vector. Depending on the operating system and execution environment, command-line arguments may be exposed through: - Process inspection facilities such as `/proc//cmdline` or process-monitoring tools. - Shell history. - Agent tool-call transcripts and execution logs. - CI/CD, terminal, audit, or endpoint-monitoring telemetry. - Error reports that capture the executed comma ...[truncated 1265 chars]- Remediation
View remediation
