T09 · Insecure Skill Coding Practices
- Location
scripts/import-wallet.js:14- Finding
Wallet Secrets Exposed Through Command-Line Arguments
- Content
View full analysis
" ``` or: ```text node scripts/import-wallet.js --privateKey=0x... ``` ### Technical Analysis The import workflow reads seed phrases and private keys directly from `process.argv`. Command-line arguments are not an appropriate transport for high-value secrets because they can be exposed through: - Shell history files. - Process inspection utilities and operating-system process metadata. - Terminal session recording. - CI/CD and automation logs. - Agent tool-call histories or execution traces. - Diagnostic and monitoring systems that record process arguments. Encrypting the secret before writing `wallet/signer.json` does not address this exposure because the plaintext secret has already crossed several observable interfaces before encryption occurs. This also conflicts with the Skill's stated rule that full seed phrases and private keys must not be exposed in logs. ### Attack Path 1. A user follows the documented import command and supplies a seed phrase or private key as a CLI argument. 2. The shell records the command in its history, or the operating system exposes the process arguments while the process is running. 3. Another local user, monitoring service, terminal logger, CI system, or compromised process reads the argument. 4. The attacker obtains the complete seed phrase or private key. 5. The ...[truncated 633 chars]- Remediation
View remediation
| ...`, since that can still disclose the secret through shell history and process arguments. - Ensure errors, debug output, telemetry, and execution traces never include the supplied secret. - Clear temporary in-memory buffers where practical after account derivation and encryption. - Update every example in `SKILL.md` so that no wallet secret appears in a command-line argument. - Add automated tests that reject secret-bearing CLI options and verify that failure output does not contain supplied secret values. ]]>
