T09 · Insecure Skill Coding Practices
- Location
scripts/wc-requester.js:57- Finding
Sensitive session and audit files are created without restrictive permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This wallet skill is mostly coherent, but it needs review because it can request overbroad wallet permissions and stores sensitive session/audit data without enforcing tight local protections.
Install only if you are comfortable with an agent requesting wallet transactions and signatures. Use a dedicated wallet, read every wallet prompt carefully, avoid custom --methods unless you understand them, disconnect sessions when finished, and restrict or delete ~/.walletconnect-requester files because they contain sensitive session and activity metadata.
scripts/wc-requester.js:57Sensitive session and audit files are created without restrictive permissions
scripts/wc-requester.js:190Full session topics and transaction hashes are written to the audit log
scripts/wc-requester.js:140Unrestricted method selection permits over-scoped WalletConnect sessions
scripts/package.json:13Mutable npm dependency resolution without a lockfile creates supply-chain risk
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
Referenced artifact was not completely inspected
node scripts/wc-requester.js connect
The skill declares environment variable requirements and persistent local storage, but does not define an explicit tool/permission scope such as allowed tools or permissions. In an agent ecosystem, missing capability declarations weakens policy enforcement and makes it harder for hosts to constrain file and environment access, increasing the chance of unintended secret exposure or overly broad execution.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Step 2: Get WalletConnect Project ID
1. Go to [WalletConnect Cloud](https://cloud.walletconnect.com/)
2. Create a new project
3. Copy your **Project ID**
### Step 3: Set Environment Variable
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
**Security recommendations:**
- Review `audit.log` before sharing
- Delete `sessions.json` when no longer needed
- Set appropriate file permissions: `chmod 600 ~/.walletconnect-requester/*`
### Sensitive Data Handling
The skill explicitly documents that WalletConnect sessions persist for 7 days and elsewhere states that active session data is stored in ~/.walletconnect-requester/sessions.json. Even without private keys, a live WalletConnect session can be abused by a compromised agent or local attacker to send new transaction/signature requests to the user's wallet, enabling phishing, spam prompts, or deceptive approval flows.
## Troubleshooting
### "No active session"
Run `connect` first to create a session.
### "User rejected request"
User declined in their wallet. Ask if they want to retry.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Attacker CANNOT:
- Access private keys (agent never has them)
- Auto-sign transactions (not possible)
- Execute transactions without approval
↓
Attacker CAN ONLY:
- Request transactions (user must approve)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Attacker CANNOT:
- Access private keys (agent never has them)
- Auto-sign transactions (not possible)
- Execute transactions without approval
↓
Attacker CAN ONLY:
- Request transactions (user must approve)
The top-level security claims say every transaction requires user approval and emphasize zero-custody safety, but the tool also supports signature requests and configurable wallet methods. In a wallet agent context, misleading security framing is dangerous because users or downstream integrators may treat the skill as narrower and safer than it is, increasing the chance they approve phishing-style signatures or overbroad session permissions.
The connect flow allows caller-supplied WalletConnect methods via options.methods, and passes them directly into requiredNamespaces without any allowlist enforcement. In an agent setting, this can silently expand wallet capabilities beyond the advertised scope and enable dangerous requests such as arbitrary signing or wallet-specific methods, relying only on the user to notice and reject them in the wallet UI.
The dependency uses a caret range, which permits automatic installation of newer compatible releases instead of an exact reviewed version. This increases supply-chain risk because a newly published compromised or breaking upstream version could be pulled into the skill without explicit review, which is especially relevant for a wallet-interaction tool handling transaction and signature requests.
"sessions": "node scripts/wc-requester.js sessions"
},
"dependencies": {
"@walletconnect/sign-client": "^2.13.0",
"@walletconnect/core": "^2.13.0",
"qrcode": "^1.5.3"
},
The dependency uses a caret range, which permits automatic installation of newer compatible releases instead of an exact reviewed version. This creates a supply-chain exposure where an unintended upstream release of a core WalletConnect package could be incorporated into this wallet-facing skill without prior validation.
},
"dependencies": {
"@walletconnect/sign-client": "^2.13.0",
"@walletconnect/core": "^2.13.0",
"qrcode": "^1.5.3"
},
"keywords": [
Using a version range for qrcode allows future package versions to be resolved during install, which can introduce unreviewed code into the environment. While lower sensitivity than wallet protocol libraries, it still contributes to supply-chain risk and could be abused if the dependency or its transitive tree were compromised.
"dependencies": {
"@walletconnect/sign-client": "^2.13.0",
"@walletconnect/core": "^2.13.0",
"qrcode": "^1.5.3"
},
"keywords": [
"walletconnect",
No suspicious patterns detected.