Back to skill

Security audit

Coinpilot Hyperliquid Copy Trade

Security checks for vulnerabilities and agentic risk

Overview

Review recommended: this crypto copy-trading skill is coherent, but it sends wallet private keys to Coinpilot servers and stores many keys in a local file.

Install only if you trust Coinpilot and its infrastructure with full control of the configured wallets. Use wallets funded only for this strategy, avoid storing unrelated funds or permissions on them, keep ~/.coinpilot/coinpilot.json tightly permissioned, and prefer pinned installation sources where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/coinpilot_cli.mjs:359
Finding

Primary Wallet Private Key Is Transmitted on Every Coinpilot Request

Content
View full analysis
{ return withCoinpilotLock(async () => { await throttle(); const primary = getPrimaryWallet(wallets); const baseUrl = getApiBaseUrl(wallets); const url = new URL(route, baseUrl); if (query) { for (const [key, value] of Object.entries(query)) { if (value === undefined || value === "") continue; url.searchParams.set(key, String(value)); } } console.log(`[coinpilot] ${method} ${url.toString()}`); const headers = { "Content-Type": "application/json", "x-api-key": wallets.apiKey, "x-wallet-private-key": primary.privateKey, "x-user-id": wallets.userId, ...extraHeaders, }; const res = await fetch(url.toString(), { method, headers, body: body ? JSON.stringify(body) : undefined, }); ``` ### Technical Analysis The common Coinpilot request function attaches the primary funding wallet's reusable raw private key as the `x-wallet-private-key` header. Because every Coinpilot operation uses this function, the key is transmitted not only for trading operations but also for read-only activities such as lead discovery, subscription listing, history retrieval, and activity inspection. This violates least privilege. Public discovery endpoints should not require wallet authority, and authenticated read operations should use a scoped API credential rather than a private key capable of authorizing blockchain transactions. The destination is constrained to HTTPS origins in a hardcoded allowlist, which reduces arbitrary exfiltration risk. However, that allowlist includes production, development, and staging environments under both `coinpilot.bot` and `coi ...[truncated 1638 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/coinpilot_cli.mjs:698
Finding

Raw Primary and Follower Private Keys Are Serialized into Trading Request Bodies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/coinpilot_cli.mjs:67
Finding

Credential File Permissions Are Not Enforced at Runtime

Content
View full analysis
{ const raw = await fs.readFile(filePath, "utf8"); return JSON.parse(raw); }; ``` The CLI then accepts and loads the file directly: ```js const walletsPath = DEFAULT_WALLETS_PATH; // console.log(`[coinpilot] wallets path: ${walletsPath}`); const wallets = validateWallets(await readJson(walletsPath)); loadedSecrets = getLoadedSecrets(wallets); ``` ### Technical Analysis `SKILL.md:64-65` states that the credential file must use owner-only read/write permissions. The executable implementation does not enforce that requirement. It does not inspect file ownership, file type, POSIX mode bits, symlink status, or platform ACLs before loading ten private keys and the API key. No `chmod` or secure credential-file creation routine exists in the CLI. A file created under a permissive umask, copied from another location, restored from a backup, or edited by a tool that changes permissions can therefore remain group-readable or world-readable without any warning. The fixed location reduces accidental path substitution but does not protect the file from other local users or processes when its permissions are unsafe. ### Attack Path 1. The credential file is created or copied to `~/.coinpilot/coinpilot.json` with permissions such as `0644` or another permissive ACL. 2. The CLI loads it without validating ownership or access permissions. 3. Another local user, service account, compromised process, or backup/indexing tool reads the file. 4. The attacker obtains the Coinpilot API key, user ID, primary private key, and nine follower private keys. 5. The attacker uses the private keys directly, without needing to invoke this Skill o ...[truncated 467 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:38
Finding

Installation Instructions Execute Mutable, Unpinned Third-Party Packages

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (40)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 208)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
Use `scripts/coinpilot_cli.mjs` as the primary runtime interface. Before or during an action, quickly check the relevant reference(s) only when you need to conf

Static analysis

No suspicious patterns detected.