Back to skill

Security audit

Walletconnect Requester

Security checks for vulnerabilities and agentic risk

Overview

This wallet skill is mostly coherent, but it needs review because it can request overbroad wallet permissions and stores sensitive session/audit data without enforcing tight local protections.

Install only if you are comfortable with an agent requesting wallet transactions and signatures. Use a dedicated wallet, read every wallet prompt carefully, avoid custom --methods unless you understand them, disconnect sessions when finished, and restrict or delete ~/.walletconnect-requester files because they contain sensitive session and activity metadata.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wc-requester.js:57
Finding

Sensitive session and audit files are created without restrictive permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wc-requester.js:190
Finding

Full session topics and transaction hashes are written to the audit log

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/wc-requester.js:140
Finding

Unrestricted method selection permits over-scoped WalletConnect sessions

Content
View full analysis
`eip155:${id}`), methods: methods, events: ['accountsChanged', 'chainChanged'] } }; ``` ```js case 'connect': await requester.connect({ chains: options.chains?.split(','), methods: options.methods?.split(','), qr: options.qr }); break; ``` ### Technical Analysis The `--methods` option is split into an arbitrary array and inserted directly into `requiredNamespaces`. No allowlist rejects dangerous, unsupported, or unnecessary RPC methods. Consequently, a caller can request capabilities such as `eth_sign` even though `references/SECURITY.md` and `CHANGELOG.md` state that this method is blocked. The current transaction and signature commands issue hard-coded RPC methods, so the existing CLI does not directly invoke arbitrary methods after connection. Nevertheless, the established session can be broader than the Skill's declared needs and could be abused by modified, extended, or compromised code that has access to the WalletConnect client state. The wallet still presents the requested namespace and must approve the session. Therefore, this is an excessive-permission and policy-enforcement weakness rather than an automatic approval bypass. ### Attack Path 1. An attacker or compromised automation invokes the Skill with an over-scoped argument, such as `connect --methods eth_sign,eth_signTransaction,eth_sendTransaction`. 2. The script forwards those method names into the WalletConnect required namespace without validation. 3. The user is presented with a bro ...[truncated 888 chars]
Remediation
View remediation
!ALLOWED_METHODS.has(method) ); if (invalidMethods.length > 0) { throw new Error(`Unsupported WalletConnect methods: ${invalidMethods.join(', ')}`); } ``` - Explicitly reject `eth_sign`, `eth_signTransaction`, and unknown method names regardless of CLI input. - Validate chain identifiers using a numeric format and, where appropriate, an approved-chain list. - Remove or isolate the `full` profile in `config/namespaces.json`, which includes `eth_signTransaction`. - Display the exact requested chains and methods before producing the WalletConnect URI. - Add tests proving forbidden methods cannot be added through command-line options. ]]>

T08 · Insecure Dependencies

Note
Location
scripts/package.json:13
Finding

Mutable npm dependency resolution without a lockfile creates supply-chain risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (25)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 269)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

md
node scripts/wc-requester.js connect

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 285)May include surrounding context.

md
node scripts/wc-requester.js connect

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares environment variable requirements and persistent local storage, but does not define an explicit tool/permission scope such as allowed tools or permissions. In an agent ecosystem, missing capability declarations weakens policy enforcement and makes it harder for hosts to constrain file and environment access, increasing the chance of unintended secret exposure or overly broad execution.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
### Step 2: Get WalletConnect Project ID

1. Go to [WalletConnect Cloud](https://cloud.walletconnect.com/)
2. Create a new project
3. Copy your **Project ID**

### Step 3: Set Environment Variable

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 217)May include surrounding context.

md
**Security recommendations:**
- Review `audit.log` before sharing
- Delete `sessions.json` when no longer needed
- Set appropriate file permissions: `chmod 600 ~/.walletconnect-requester/*`

### Sensitive Data Handling

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill explicitly documents that WalletConnect sessions persist for 7 days and elsewhere states that active session data is stored in ~/.walletconnect-requester/sessions.json. Even without private keys, a live WalletConnect session can be abused by a compromised agent or local attacker to send new transaction/signature requests to the user's wallet, enabling phishing, spam prompts, or deceptive approval flows.

Content

Scanner excerpt · SKILL.md (reported line 316)May include surrounding context.

md
## Troubleshooting

### "No active session"
Run `connect` first to create a session.

### "User rejected request"
User declined in their wallet. Ask if they want to retry.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
Attacker CANNOT:
  - Access private keys (agent never has them)
  - Auto-sign transactions (not possible)
  - Execute transactions without approval
         ↓
Attacker CAN ONLY:
  - Request transactions (user must approve)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/SECURITY.md (reported line 49)May include surrounding context.

md
Attacker CANNOT:
  - Access private keys (agent never has them)
  - Auto-sign transactions (not possible)
  - Execute transactions without approval
         ↓
Attacker CAN ONLY:
  - Request transactions (user must approve)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The top-level security claims say every transaction requires user approval and emphasize zero-custody safety, but the tool also supports signature requests and configurable wallet methods. In a wallet agent context, misleading security framing is dangerous because users or downstream integrators may treat the skill as narrower and safer than it is, increasing the chance they approve phishing-style signatures or overbroad session permissions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The connect flow allows caller-supplied WalletConnect methods via options.methods, and passes them directly into requiredNamespaces without any allowlist enforcement. In an agent setting, this can silently expand wallet capabilities beyond the advertised scope and enable dangerous requests such as arbitrary signing or wallet-specific methods, relying only on the user to notice and reject them in the wallet UI.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency uses a caret range, which permits automatic installation of newer compatible releases instead of an exact reviewed version. This increases supply-chain risk because a newly published compromised or breaking upstream version could be pulled into the skill without explicit review, which is especially relevant for a wallet-interaction tool handling transaction and signature requests.

Content

Scanner excerpt · scripts/package.json (reported line 14)May include surrounding context.

json
"sessions": "node scripts/wc-requester.js sessions"
  },
  "dependencies": {
    "@walletconnect/sign-client": "^2.13.0",
    "@walletconnect/core": "^2.13.0",
    "qrcode": "^1.5.3"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency uses a caret range, which permits automatic installation of newer compatible releases instead of an exact reviewed version. This creates a supply-chain exposure where an unintended upstream release of a core WalletConnect package could be incorporated into this wallet-facing skill without prior validation.

Content

Scanner excerpt · scripts/package.json (reported line 15)May include surrounding context.

json
},
  "dependencies": {
    "@walletconnect/sign-client": "^2.13.0",
    "@walletconnect/core": "^2.13.0",
    "qrcode": "^1.5.3"
  },
  "keywords": [

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Using a version range for qrcode allows future package versions to be resolved during install, which can introduce unreviewed code into the environment. While lower sensitivity than wallet protocol libraries, it still contributes to supply-chain risk and could be abused if the dependency or its transitive tree were compromised.

Content

Scanner excerpt · scripts/package.json (reported line 16)May include surrounding context.

json
"dependencies": {
    "@walletconnect/sign-client": "^2.13.0",
    "@walletconnect/core": "^2.13.0",
    "qrcode": "^1.5.3"
  },
  "keywords": [
    "walletconnect",

Static analysis

No suspicious patterns detected.