T09 · Insecure Skill Coding Practices
- Location
scripts/wallet.ts:68- Finding
Predictable Machine-Derived Key Allows Wallet Private-Key Recovery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Solana wallet skill is mostly purpose-aligned, but it handles real wallet keys and on-chain transactions with weak key protection and insufficient transaction safety controls.
Review this carefully before installing. Do not use it with wallets holding meaningful funds unless key storage is changed to a real user passphrase, hardware wallet, OS keychain, or other strong secret store, and transaction signing is changed to show decoded details and require explicit confirmation. Treat swaps as especially risky because the current code signs a transaction returned by a remote API without independently verifying its instructions.
scripts/wallet.ts:68Predictable Machine-Derived Key Allows Wallet Private-Key Recovery
scripts/wallet.ts:78Wallet Name Path Traversal Permits File Access Outside the Wallet Directory
scripts/swap.ts:107Remote Jupiter Transaction Is Signed Without Instruction Verification or Simulation
scripts/send.ts:57Transfers and Swaps Execute Without Mandatory Confirmation or Complete Numeric Bounds
The code partially matches the description: it does manage wallets and check SOL/token balances, including using Helius-compatible RPC/DAS calls for full balance data. However, the declared purpose substantially overstates the implemented functionality. There is no code for sending transactions, transferring tokens, Jupiter integration, swaps, address monitoring, or general-purpose Solana operations. The actual code is a narrower wallet-management and balance-checking utility with local encrypted key storage and a CLI. This is a material description-to-behavior mismatch due to missing major advertised capabilities.
The skill encourages importing private keys or seed phrases without a prominent warning that these credentials grant full wallet control and should almost never be pasted into an agent workflow. In this context, exposing seed phrases to an LLM-integrated system can directly lead to irreversible theft of all associated assets.
The skill describes sending transactions and swaps on mainnet without an upfront warning that these actions are irreversible and affect real funds. In a blockchain wallet context, insufficient warnings and confirmation friction increase the likelihood of accidental transfers, bad swaps, or loss due to user misunderstanding.
Referenced artifact was not completely inspected
See [references/security.md](references/security.md) for detailed security practices.
Referenced artifact was not completely inspected
See [references/security.md](references/security.md) for detailed security practices.
The skill advertises capabilities that require network access and likely access to locally stored secrets, but it does not declare any explicit tool scope or permission boundaries. In a wallet-management skill, missing scope declarations weakens least-privilege controls and can cause the agent to invoke the skill in broader contexts than intended.
The invocation scope is excessively broad, covering essentially any Solana or crypto-wallet request. In an agent ecosystem, such breadth increases the chance the skill is auto-selected for sensitive actions involving wallets, trading, or monitoring even when a narrower, safer skill should be used.
The script invokes npx tsx rather than a fully pinned, locally resolved binary. If dependency resolution or the execution environment allows fetching a different tsx release, a compromised or unexpected package version could execute arbitrary code during wallet-management operations, which is especially sensitive in a blockchain skill.
This script also uses npx tsx without guaranteeing an exact local version. In a package that creates and lists wallets, any execution-time package substitution could expose secrets or alter blockchain operations before the user notices.
Using npx tsx for the balance command introduces supply-chain and execution-path risk because the effective binary may not be a strictly pinned build. In a crypto context, even read-oriented commands can be a foothold for credential theft, address substitution, or malicious side effects.
The send-transaction script depends on npx tsx without an exact trusted version. Because this skill can transfer funds, any hijacked or substituted runtime dependency could directly tamper with transaction destinations, amounts, or signing flow, making the risk more severe than in a non-financial package.
The swap script uses npx tsx with no exact version guarantee. In a DeFi swap workflow, a compromised execution tool could manipulate routes, token approvals, or destination accounts, potentially causing direct financial loss.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Convert raw transactions to human-readable format.
const response = await fetch('https://api.helius.xyz/v0/transactions', {
method: 'POST',
headers: {
'Content-Type': 'application/json'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Convert raw transactions to human-readable format.
const response = await fetch('https://api.helius.xyz/v0/transactions', {
method: 'POST',
headers: {
'Content-Type': 'application/json'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Convert raw transactions to human-readable format.
const response = await fetch('https://api.helius.xyz/v0/transactions', {
method: 'POST',
headers: {
'Content-Type': 'application/json'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| Endpoint | URL |
|----------|-----|
| Quote | `https://api.jup.ag/swap/v1/quote` |
| Swap | `https://api.jup.ag/swap/v1/swap` |
| Price | `https://api.jup.ag/price/v2` |
| Tokens | `https://tokens.jup.ag/tokens?tags=verified` |
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal