Back to skill

Security audit

CoinFello

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for CoinFello crypto workflows, but it asks users to run a mutable remote CLI with wallet signing and stored session authority, so it belongs in Review before installation.

Install only if you trust CoinFello and the npm package publisher, and prefer a pinned, reviewed CLI version. Avoid `--use-unsafe-private-key`, verify the active signer type before approving delegations, keep the config file private with restrictive permissions, stop the signer daemon when not needed, and review every delegation scope before approval.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:25
Finding

Mutable Remote CLI Is Downloaded and Executed Without Version Pinning

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:25-31
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

markdown
Use the `npx @coinfello/agent-cli@latest` CLI to interact with CoinFello. The CLI handles smart account creation, SIWE authentication, delegation management, prompt-based transactions, and transaction status checks.

## Prerequisites

- Node.js 20 or later (npx is included with Node.js)

The CLI is available via `npx @coinfello/agent-cli@latest`. No manual build step is required.

The same mutable command is subsequently used throughout the documented workflows:

bash
npx @coinfello/agent-cli@latest create_account
npx @coinfello/agent-cli@latest sign_in
npx @coinfello/agent-cli@latest send_prompt "send 5 USDC to 0xRecipient..."
npx @coinfello/agent-cli@latest approve_delegation_request

Technical Analysis

The Skill instructs the Agent to retrieve and execute the npm package identified by the mutable latest distribution tag. The package source is not included in the audited project, and the Skill provides no exact version, integrity digest, signature verification, lockfile, or locally reviewed executable.

Consequently, the effective code executed by the Skill can change after this audit without any modification to the reviewed files. This is particularly dangerous because the downloaded CLI is entrusted with cryptocurrency account creation, SIWE authentication, local credential access, signing operations, and submission of token delegations.

Although no evidence establishes that the current package is malicious, the execution model creates a remote payload and supply-chain trust boundary that cannot be verified from this project.

Attack Path

  1. An attacker compromises the npm publisher account, package build pipeline, registry distribution process, or another dependency used by @coinfello/agent-cli.
  2. The attack ...[truncated 1401 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version, such as @coinfello/agent-cli@X.Y.Z.
  2. Pin and verify the package tarball integrity using an approved cryptographic digest or npm lockfile integrity value.
  3. Include the CLI source or a reproducible build definition in the reviewed project so its sensitive behavior can be audited.
  4. Require signed releases and verify provenance through an appropriate package-signing or build-attestation mechanism.
  5. Review and pin all transitive dependencies used by the CLI.
  6. Run the CLI in a constrained environment with access only to the required configuration files, Unix socket, RPC endpoints, and CoinFello API.
  7. Establish a controlled update process in which new package versions are reviewed before the pinned version is changed.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:49
Finding

Plaintext Wallet Key Fallback and Session Token Co-Location Expose Sensitive Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:49-58; supporting schema at references/REFERENCE.md:19-31
Vulnerability Type: Plaintext sensitive-data storage and unsafe cryptographic-key fallback
Risk Level: High

Vulnerable Code

From SKILL.md:

markdown
- **Key generation and storage**: By default, `create_account` generates a hardware-backed P256 key in the **macOS Secure Enclave** (or TPM 2.0 where available). The private key never leaves the hardware and cannot be exported — only public key coordinates and a key tag are saved to `~/.clawdbot/skills/coinfello/config.json`. If hardware key support is not available, the CLI warns and falls back to a software private key. You can also explicitly opt into a plaintext software key by passing `--use-unsafe-private-key`, which stores a raw private key in the config file — **this is intended only for development and testing**.
- **Signer daemon**: Running `signer-daemon start` authenticates once via Touch ID / password and caches the authorization. All subsequent signing operations reuse this cached context, eliminating repeated auth prompts. The daemon communicates over a user-scoped Unix domain socket with restricted permissions (`0600`). If the daemon is not running, signing operations fall back to direct execution (prompting Touch ID each time).
- **Session token storage**: Running `sign_in` stores a SIWE session token in the same config file.
- **Delegation signing**: Running `send_prompt` may receive a delegation request from the server, which is saved to a local file. Running `approve_delegation_request` creates and signs the delegation, then submits it to the CoinFello API.

The documented plaintext schema in references/REFERENCE.md is:

json
{
  "signer_type": "privateKey",
  "private_key": "0xabc123...def",
  "smart_account_address": "0x1234...abcd",
  "chat_id": "chat_abc123...",
  "session_token": "...",
  "delegation": { ... }

...[truncated 2547 chars]
Remediation
View remediation

Remediation Suggestions

  1. Fail closed when hardware-backed key creation is unavailable. Require a separate, explicit, interactive confirmation before generating any software key.
  2. Do not permit silent or warning-only fallback from a non-exportable key to an exportable key.
  3. Store software keys in an operating-system credential vault or encrypt them using a user-authorized key-encryption key.
  4. Separate wallet key material, session tokens, chat metadata, and delegation state into distinct stores with narrowly scoped access.
  5. Create sensitive files atomically with mode 0600; reject symlinks and refuse operation if ownership or permissions are unsafe.
  6. Avoid placing secrets in broadly synchronized or backed-up paths unless backups provide equivalent encryption and access controls.
  7. Provide session-token expiration, revocation, and logout functionality, and minimize token lifetime and scope.
  8. Clearly display the active signer type before every signing operation and require renewed confirmation when a software signer is active.
  9. Add automated tests verifying permissions, ownership, atomic writes, symlink resistance, secret redaction, and failure behavior.
  10. Include the CLI implementation in future audits so storage protections can be independently verified rather than accepted solely from documentation.
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (51)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

text

- Removes `chat_id` from `~/.clawdbot/skills/coinfello/config.json`
- Use this when you want to reset conversation context (for example, after context-window errors)

### signer-daemon

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.