T09 · Insecure Skill Coding Practices
- Location
SKILL.md:180- Finding
Wallet Private Key Exposed Through Command-Line Arguments
- Content
View full analysis
,,1,,0x73ad2146,,,)" \ "" "" \ --private-key "$PRIVATE_KEY" \ --rpc-url "$BASE_MAINNET_RPC" ``` The same `--private-key "$PRIVATE_KEY"` pattern is repeated in the documented commands for creating, cancelling, bidding on, and claiming auctions, as well as token and NFT approval operations. ### Technical Analysis Although the private key is read from an environment variable and the instructions explicitly prohibit printing or logging it, passing it to `cast` using the `--private-key` option places the expanded secret in the process argument vector. Depending on the operating system, container configuration, process-monitoring software, shell instrumentation, and CI/CD environment, command-line arguments may be observable through: - Process inspection utilities and `/proc//cmdline`. - Endpoint monitoring or process-accounting systems. - CI/CD command telemetry and diagnostic collectors. - Shell wrappers, debugging modes, or audit frameworks that record executed commands. - Other processes operating under the same user identity or with elevated process-inspection privileges. The private key is the primary credential for this Skill and authorizes irreversible Base mainnet transactions. The safety measures involving `DRY_RUN`, chain-ID checks, address alignment, simul ...[truncated 2278 chars]- Remediation
View remediation
