Back to plugin

Security audit

AC2 Reference

Security checks for vulnerabilities and agentic risk

Overview

This wallet-signing plugin is mostly coherent, but it can initiate paid wallet approval flows for ordinary weather questions and broad git-signing workflows.

Before installing, confirm you want this agent connected to a wallet for signing, x402 payments, automatic swap-funded payments, and git commit signing. Treat wallet approval prompts as real financial or signing actions, and consider lowering x402 spend limits or using recipient/network allow-lists.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to invoke a paid x402 flow for ordinary weather questions, even when the user did not explicitly request a wallet-backed payment or provide a target URL. That broad trigger can cause unintended wallet prompts and possible spending from a connected account for a low-risk informational request, weakening user intent verification around financial authorization.

Vague Triggers

High
Confidence
96% confidence
Finding
The manifest description says to use this skill whenever the user asks to 'sign', 'approve', or 'authorize' something with their wallet, even if they do not mention AC2, and also makes it mandatory for any git work. Those broad activation conditions can over-trigger wallet signing behavior in ambiguous contexts, leading the agent to solicit signatures or approvals without sufficiently specific user intent or transaction context.

Static analysis

No suspicious patterns detected.