T08 · Insecure Dependencies
- Location
SKILL.md:60- Finding
Unpinned and Unaudited Third-Party Wallet Integration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:60
Vulnerability Type: Unpinned third-party dependency with access to wallet credentials and transaction authority
Risk Level: MediumVulnerable Code Snippet
markdown **Your agent has no wallet skill yet.** The most direct option is [`Ales375/openclaw-cdp-wallet-skill`](https://github.com/Ales375/openclaw-cdp-wallet-skill) — a minimal wrapper around the official Coinbase CDP server wallet SDK. Three env vars, one command to get the wallet's address, keys held in Coinbase's TEE infrastructure. Handles both donation transfers and x402 evidence-access settlement using the same CDP credentials, so one wallet skill covers everything zooidfund needs. Other valid options that handle both: Coinbase's `agentic-wallet-skills` package (consumer wallet, requires interactive auth — heavier setup), or a custom integration using the `x402` and `@coinbase/cdp-sdk` packages directly. Options that handle donations only (no x402): basic OnchainKit `send-usdc` skills, viem-based EOA `send-usdc` skills, Bankr-style hosted wallets without explicit x402 support. Pick a both-capable option if you want evidence access; pick a donations-only option if you're fine reasoning from prose alone.Technical Analysis
The Skill recommends installing an external wallet Skill using a mutable repository reference without specifying an immutable commit, verified release, package checksum, or reproducible dependency lock. The referenced component would handle Coinbase CDP credentials, x402 payment authorizations, donation destinations, and transaction submission.
Because the external implementation is not included in the audited project, its behavior cannot be verified from this artifact. If the repository, maintainer account, release process, or transitive dependencies were compromised, later installations could execute code different from the version that an operator previously reviewed.
The wa ...[truncated 1678 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the recommended wallet Skill to an immutable, reviewed commit hash or cryptographically signed release rather than a mutable repository reference.
- Publish the expected package version, commit identifier, checksums, and exact installation command.
- Audit and lock all transitive dependencies using a committed lockfile and integrity metadata.
- Prefer reproducible builds and signed release artifacts with documented verification steps.
- Require operators to review the wallet Skill independently before providing CDP credentials or signing authority.
- Use a dedicated donation wallet with a minimal balance and enforce wallet-layer per-transaction and cumulative spending limits.
- Restrict signing policies to Base, the expected USDC contract, approved x402 facilitator contracts, and operator-approved maximum amounts.
- Display and independently validate the chain, token contract, recipient, and amount immediately before each signature.
- Document credential revocation and wallet-rotation procedures for suspected dependency compromise.
