Back to skill

Security audit

Basecred ERC-8004 Registration

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it asks an agent to handle raw wallet private keys and source a .env file before signed on-chain actions.

Review before installing. Use only a dedicated low-value wallet, do not put a primary funded wallet private key in `.env`, and do not let an agent source an untrusted `.env` file. Prefer pasting a public address or using an external signer. Treat registration, update, and feedback as real on-chain actions that can cost gas and publish persistent data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:228
Finding

Arbitrary Shell Command Execution Through Sourced Environment File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:228-229
Vulnerability Type: Unsafe evaluation of an environment file as shell code
Risk Level: High

Vulnerable code:

bash
source /path/to/.env
node scripts/register.mjs --json /tmp/registration.json --chain 8453 --yes

Technical Analysis

The registration instructions use the shell built-in source to load .env. This does not parse the file as a passive collection of key-value pairs; it evaluates every line as shell syntax in the current process.

Consequently, a malicious or compromised .env can contain command substitutions, functions, redirections, or arbitrary commands. These execute before the registration script starts and with the same operating-system privileges as the agent process or user running the workflow.

This risk is especially relevant because the Skill explicitly directs the agent to inspect and use .env during its normal registration flow. The following --yes option also bypasses the script's own interactive transaction confirmation, although the Skill separately requires explicit confirmation through chat.

Attack Path

  1. An attacker, compromised dependency, or untrusted project modifies the .env file accessible to the registration workflow.
  2. The attacker inserts shell syntax, for example:
    bash
    PRIVATE_KEY=0x...
    MALICIOUS_VALUE="$(attacker-controlled-command)"
    
  3. A user asks the agent to perform ERC-8004 registration.
  4. The agent follows SKILL.md and runs source /path/to/.env.
  5. The command substitution or other injected shell statement executes before register.mjs.
  6. The malicious command operates with the permissions of the agent process and can access resources available to that account.

Impact Assessment

Successful exploitation provides arbitrary command execution under the account running the Skill. Depending on that account's permissions, an attacker could:

...[truncated 585 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the source /path/to/.env instruction and never evaluate environment files as shell programs.
  2. Load .env as data with a pinned environment-file parser, such as Node.js environment-file support or a reviewed and locked dotenv dependency.
  3. Allow only the expected variable names:
    • PRIVATE_KEY
    • AGENT_PRIVATE_KEY
    • MAIN_WALLET_PRIVATE_KEY
    • RPC_URL
    • CHAIN_ID
    • PINATA_JWT
  4. Validate every value before use:
    • Require private keys to match the expected hexadecimal length and format.
    • Restrict CHAIN_ID to supported numeric values.
    • Require RPC_URL to use an approved HTTPS endpoint or obtain explicit approval for a custom endpoint.
    • Reject control characters, newlines, and malformed entries.
  5. Pass validated variables directly to the Node.js process rather than exporting an entire untrusted file into the shell environment.
  6. Prefer retaining the script's interactive confirmation instead of using --yes. If automation requires --yes, ensure the chat confirmation is bound to the exact chain, contract addresses, wallet, metadata, and transaction action that will be submitted.
  7. Document that .env must have restrictive filesystem permissions and must never be accepted from an untrusted project without validation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (33)

Known Vulnerable Dependency: protobufjs==7.5.4 — 12 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +9 more

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

protobufjs 7.5.4 is flagged with numerous advisories including denial-of-service and code-generation/injection classes of issues. Because it is a substantial parsing/runtime package and appears in the transitive tree of IPFS-related components, keeping a heavily vulnerable version materially increases supply-chain and input-handling risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description says the skill provides an interactive chat workflow for ERC-8004 agent registration and ultimately registers on-chain using agent0-sdk. The supplied code chunk does not do any of that user-facing or blockchain behavior. Instead, it is purely a setup script for the local development/runtime environment: it checks Node.js, initializes package metadata, modifies package.json, installs the agent0-sdk dependency, and prints environment variable guidance. While setup may support the described skill, this chunk’s actual behavior is materially different from the declared primary purpose and includes undeclared capabilities like package initialization and external dependency installation. Therefore this is a mismatch.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill explicitly tells users to place a private key in .env for signing, normalizing credential handling inside a general chat-driven workflow. This increases the chance that agents, logs, or adjacent tooling access highly sensitive key material that should be isolated in a dedicated signer or wallet.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
→ Just paste your 0x... address
          → Agent will be linked to this address on-chain

          Option B: Add private key to .env (for signing)
          → Set PRIVATE_KEY=0x... in your .env file
          → Wallet auto-detected + can sign transactions
          → Enables setWallet() via EIP-712 after registration

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The workflow continues to promote .env-based private key usage as a normal option for wallet linking and signing. Any design that couples agent execution with direct access to raw private keys creates severe compromise risk if prompts, logs, telemetry, or tools mishandle the environment.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
→ Agent will be linked to this address on-chain

          Option B: Add private key to .env (for signing)
          → Set PRIVATE_KEY=0x... in your .env file
          → Wallet auto-detected + can sign transactions
          → Enables setWallet() via EIP-712 after registration

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

text
Buttons: `[↩️ Back to Draft]`

#### Edit Skills & Domains
Toggleable inline buttons (multi-select). Each button shows a **human-readable label** but stores the full **OASF taxonomy path** as the value.

**Skills:** (OASF taxonomy paths)

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The execution step instructs sourcing /path/to/.env before running the registration script, directly importing secret-bearing environment variables into the execution context. This can leak credentials through process environments, shell history, logs, or downstream tooling, especially in agentic systems with broad observability.

Content

Scanner excerpt · SKILL.md (reported line 228)May include surrounding context.

  1. Run the script:
bash
source /path/to/.env
node scripts/register.mjs --json /tmp/registration.json --chain 8453 --yes

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The error-handling guidance again steers users toward placing PRIVATE_KEY in .env, reinforcing insecure secret handling as a standard remediation path. Repetition in user-facing instructions makes accidental key exposure more likely and increases the chance operators follow unsafe practices.

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

text
⚠️ No wallet detected. You need one to register:
  Option A: Paste your 0x... address
  Option B: Add PRIVATE_KEY to your .env file

Transaction Failures

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · package-lock.json (reported line 157)May include surrounding context.

json
"multiformats": "^13.0.0"
      }
    },
    "node_modules/@libp2p/interface-keychain": {
      "version": "2.0.5",
      "license": "Apache-2.0 OR MIT",
      "dependencies": {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · package-lock.json (reported line 776)May include surrounding context.

json
"multiformats": "^13.0.0"
      }
    },
    "node_modules/@libp2p/interface-keychain": {
      "version": "2.0.5",
      "license": "Apache-2.0 OR MIT",
      "dependencies": {

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

brace-expansion 1.1.12 is flagged for multiple denial-of-service issues related to pathological pattern expansion. Even though it is transitive and likely used for globbing utilities rather than direct network parsing, a vulnerable package in the dependency tree can still be abused if attacker-controlled patterns reach it.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.11 — 3 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
80% confidence
Finding

nanoid 3.3.11 is present with advisories involving hangs, loops, and integer-handling bugs in non-default or custom generator usage. This is a real supply-chain risk, though practical impact depends on whether the affected APIs are exposed in this skill's execution paths.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: minimatch==3.1.2 — 3 advisory(ies): CVE-2026-27904 (minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regu); CVE-2026-26996 (minimatch has a ReDoS via repeated wildcards with non-matching literal in patter); CVE-2026-27903 (minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adja)

High
Category
Supply Chain
Confidence
84% confidence
Finding

minimatch 3.1.2 is reported vulnerable to several ReDoS conditions from crafted glob patterns. If any dependency accepts attacker-controlled patterns, this can cause excessive CPU consumption and service degradation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==4.0.2 — 4 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2024-55565 (Predictable results in nanoid generation when given non-integer values) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

nanoid 4.0.2 is a known vulnerable version with issues including predictable output for malformed inputs and potential looping behavior. For an agent registration flow, weak or faulty identifier generation could affect reliability and, in some cases, security properties tied to uniqueness or unpredictability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: parse-duration==1.1.2 — 1 advisory(ies): CVE-2025-25283 (parse-duration has a Regex Denial of Service that results in event loop delay an)

High
Category
Supply Chain
Confidence
87% confidence
Finding

parse-duration 1.1.2 has a reported ReDoS issue that can delay the event loop when parsing crafted duration strings. In an interactive chat skill, any reachable parsing of user-supplied durations would make this more relevant because a remote user could trigger service slowdown or hangs.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==5.29.0 — 12 advisory(ies): CVE-2026-1525 (Undici has an HTTP Request/Response Smuggling issue); CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-1527 (Undici has CRLF Injection in undici via `upgrade` option) +9 more

High
Category
Supply Chain
Confidence
86% confidence
Finding

undici 5.29.0 is reported vulnerable to request smuggling, queue poisoning, and CRLF-related issues. Since this skill depends on network-heavy libraries for GraphQL, IPFS, and blockchain interactions, an HTTP client flaw is more dangerous here than in an offline package because remote inputs and upstream services are central to operation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.18.3 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
82% confidence
Finding

ws 8.18.3 is flagged for memory disclosure and memory exhaustion issues. In a chat-integrated, network-connected agent stack, websocket flaws can be reachable through RPC or event subscriptions and could enable denial of service or unintended data exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file adds an on-chain feedback/rating capability that is outside the stated purpose of the skill, which is limited to ERC-8004 agent registration. Because it reads a signing key from environment variables and submits a blockchain transaction via sdk.giveFeedback, a user or orchestrator invoking this script could cause unintended signed transactions and spending under the operator's credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README instructs users to place raw private keys in a .env file and shows accepted variable names, but it does not pair that guidance with strong warnings about key-handling risks, use of burner wallets, avoiding committed secrets, or preferring safer signing methods. Because this skill performs on-chain registration and wallet linking, normalizing direct private-key placement can lead to credential compromise and loss of funds if users reuse funded wallets or mishandle environment files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase "Register me on ERC-8004" is broad enough that a user may invoke on-chain registration unintentionally without clearly signaling they want to begin a sensitive blockchain workflow. In an agent/chat context, overly permissive triggers increase the chance of accidental execution of wallet-related flows, exposure of sensitive setup steps, or social-engineering abuse where benign conversation is interpreted as consent to start registration.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill clearly expects access to sensitive local resources such as environment variables, but it does not declare any explicit tool scope or permission boundary. That creates an authorization ambiguity where the agent may access secrets or local context beyond what a user reasonably expects during a chat-based registration flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs reading .env and deriving wallet information from private-key material without an explicit sensitivity warning or consent gate. Even if only the address is intended to be used, access to private-key-bearing env files materially increases the risk of secret exposure or over-collection.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to mine prior conversation, local identity files, and wallet-derived environment data to auto-populate a user-facing form. This broad contextual harvesting can expose sensitive or unrelated personal data and exceeds strict data minimization for a registration workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description says the skill performs interactive ERC-8004 agent registration via chat, but the package exposes additional entry points for search, update, feedback, setup, and template generation. Search, update, and feedback especially indicate broader lifecycle operations than registration alone, which expands the skill's behavior beyond the stated scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file includes a required privateKey and related IPFS credential fields in the SDK initialization example, but provides no warning about handling secrets securely or avoiding hardcoding credentials. For markdown files, omission of warnings about behaviors affecting privacy or system integrity is in scope, and exposing credential usage without guidance can lead to unsafe copying into real code.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script accesses PRIVATE_KEY or AGENT_PRIVATE_KEY to enable a feedback action that is not justified by the declared registration-only behavior of the skill. Pulling signing credentials into an undocumented auxiliary capability increases the chance of secret misuse and unauthorized transaction signing if the script is invoked in an automated agent environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.