Back to skill

Security audit

cdnsoft-wallet

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed crypto wallet skill, but it gives autonomous agents broad, irreversible spending and contract-signing power without mandatory guardrails.

Install only if you are prepared to treat this as a hot-wallet executor. Use a low-balance dedicated wallet, pin and review dependencies, require human approval for every signing action, set --max-amount and preferably --pay-to for x402, always set --min-out for swaps, and avoid --calldata unless the destination contract and function are independently verified.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/x402_request.py:130
Finding

Untrusted x402 endpoint controls critical signed authorization fields

Content
View full analysis
str: """Sign an EIP-712 TransferWithAuthorization and return base64 payment payload.""" now = int(time.time()) nonce = "0x" + os.urandom(32).hex() chain_id = int(accepted["network"].split(":")[1]) amount_atomic = int(accepted.get("maxAmountRequired") or accepted["amount"]) authorization = { "from": wallet_address, "to": accepted["payTo"], "value": amount_atomic, "validAfter": now - 60, "validBefore": now + accepted["maxTimeoutSeconds"], "nonce": nonce, } structured_data = { "types": { "EIP712Domain": [ {"name": "name", "type": "string"}, {"name": "version", "type": "string"}, {"name": "chainId", "type": "uint256"}, {"name": "verifyingContract", "type": "address"}, ], "TransferWithAuthorization": [ {"name": "from", "type": "address"}, {"name": "to", "type": "address"}, {"name": "value", "type": "uint256"}, {"name": "validAfter", "type": "uint256"}, {"name": "validBefore", "type": "uint256"}, {"name": "nonce", "type": "bytes32"}, ], }, "domain": { "name": accepted["extra"]["name"], "version": accepted["extra"]["version"], "chainId": chain_id, "verifyingContract": accepted["asset"], }, "primaryType": "TransferWithAuthorization", "message": authorization, } msg = encode_typed_data(full_messa ...[truncated 3041 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/log_transaction.py:303
Finding

Uniswap swaps execute without mandatory slippage protection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/log_transaction.py:292
Finding

Base-specific swap contracts are used without verifying the active chain

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Security-sensitive dependencies are installed through open-ended version ranges

Content
View full analysis
=0.11.0 requests>=2.28.0 ``` Related installation guidance: ```bash pip install eth-account requests ``` ### Technical Analysis The project uses lower-bound-only dependency constraints and does not provide hashes or a lock file for transitive dependencies. Every installation can therefore resolve to different future package versions. This is particularly sensitive because `eth-account` receives private keys and performs transaction and EIP-712 signing. `requests` handles credentials, payment signatures, API bodies, and RPC traffic. A compromised or unexpectedly incompatible future release would execute in the same process with access to these assets. No evidence was found that the currently named packages are typosquatted or intentionally malicious. The confirmed issue is unsafe and non-reproducible dependency management rather than proof of an existing malicious dependency. ### Attack Path 1. An operator follows the documented installation command at a later date. 2. Package resolution selects newly published versions satisfying the open-ended constraints. 3. A selected direct or transitive dependency contains malicious code, a supply-chain compromise, or a security regression. 4. The package executes during installation or when imported by the wallet scripts. 5. Runtime package code can access private keys, signed transactions, authorization headers, request bodies, and RPC traffic available to the process. ### Impact Assessment A compromised dependency could obtain all privileges of the user running the Skill. Within the wallet process, this includes reading the private key already loaded by the script, altering recipients or amounts before signing, transmitting credentials, or submitting unautho ...[truncated 116 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a general-purpose EVM wallet, but the x402 component performs external HTTP interactions, trusts server-provided payment requirements, and signs protocol-specific EIP-712 payment flows. This hidden behavioral expansion is risky because it enables off-chain services to influence spending decisions and creates a very different trust model than a plain wallet transfer tool, especially when used autonomously.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a general-purpose EVM wallet, but the x402 component performs external HTTP interactions, trusts server-provided payment requirements, and signs protocol-specific EIP-712 payment flows. This hidden behavioral expansion is risky because it enables off-chain services to influence spending decisions and creates a very different trust model than a plain wallet transfer tool, especially when used autonomously.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · index.html (reported line 161)May include surrounding context.

html
<body>
<div class="container">

    <!-- Header -->
    <header>
        <h1>agentwallet</h1>
        <div class="tagline">EVM wallet with accountability for autonomous agents.</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · index.html (reported line 315)May include surrounding context.

html
</table>
    </section>

    <!-- Output format -->
    <section>
        <h2>Output Format</h2>
        <pre><code>{

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill metadata and usage framing present this tool as a wallet for ETH/ERC20 transfers with logging, but the implementation also supports Uniswap swaps and arbitrary contract interaction via raw calldata. That capability expansion materially increases the attack surface because an agent or prompt-injected workflow could invoke functionality far beyond simple payments, including interacting with untrusted contracts and executing irreversible on-chain actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The --calldata path lets the caller send arbitrary contract calls signed by the wallet, with optional ETH value, to any destination address. In an autonomous-agent context this effectively turns a transfer tool into a general-purpose hot-wallet executor, enabling prompt injection or task confusion to trigger approvals, swaps, contract exploitation, asset locking, or full fund drain through malicious contract interactions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises and documents capabilities that read wallet keys from disk, write transaction logs, and make network requests, but it does not declare any tool scope or permission boundaries. In an autonomous-agent context, missing explicit scope increases the chance the skill is invoked with broader-than-expected file and network access, making high-impact crypto operations less governable and harder to sandbox safely.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

{ "private_key": "0x..." }

text

Keep at `chmod 600`. Never commit to git.

## Log format

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation presents capabilities beyond the stated skill description, including swaps, x402 payment handling, and arbitrary contract calls. For a wallet skill used by autonomous agents, this scope expansion materially increases the actions an agent may take and can enable higher-risk on-chain behavior than operators expect.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · index.html (reported line 235)May include surrounding context.

html
<p>Wallet JSON format expected by <code>--wallet-key</code>:</p>
            <pre><code>{ "private_key": "0x..." }</code></pre>
            <div class="warn">
                ⚠ Keep your wallet file at <code>chmod 600</code>. Never commit it to git.
                The <code>agentwallet.json</code> log is yours to publish — the private key never is.
            </div>
        </div>

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/log_transaction.py (reported line 115)May include surrounding context.

python
def rpc_call(rpc_url: str, method: str, params: list):
    resp = requests.post(rpc_url, json={
        "jsonrpc": "2.0", "id": 1,
        "method": method, "params": params,
    }, timeout=30)

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/x402_request.py (reported line 193)May include surrounding context.

python
def rpc_call(rpc_url: str, method: str, params: list):
    resp = requests.post(rpc_url, json={
        "jsonrpc": "2.0", "id": 1,
        "method": method, "params": params,
    }, timeout=30)

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/x402_request.py (reported line 273)May include surrounding context.

python
def rpc_call(rpc_url: str, method: str, params: list):
    resp = requests.post(rpc_url, json={
        "jsonrpc": "2.0", "id": 1,
        "method": method, "params": params,
    }, timeout=30)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code reads a wallet JSON file and extracts a private key to sign transactions, which is a sensitive credential access operation. Although the script documents the required flag, it does not explicitly warn the user that the private key will be loaded and used for signing, nor does it provide a confirmation step before doing so.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.html (reported line 377)May include surrounding context.

html
# Solve a captcha via GateSkip
    python3 x402_request.py \\
        --url https://api.gateskip.org/solve/funcaptcha \\
        --wallet-key ~/.secrets/eth_wallet.json \\
        --rpc https://mainnet.base.org \\
        --output ~/website/treasury.json \\

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/x402_request.py (reported line 54)May include surrounding context.

python
# Solve a captcha via GateSkip
    python3 x402_request.py \\
        --url https://api.gateskip.org/solve/funcaptcha \\
        --wallet-key ~/.secrets/eth_wallet.json \\
        --rpc https://mainnet.base.org \\
        --output ~/website/treasury.json \\

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency specifier eth-account>=0.11.0 is unpinned, so builds may resolve to different versions over time, harming reproducibility and making it harder to ensure vulnerable releases are excluded. In a wallet/signing tool, dependency drift is more dangerous because library behavior directly affects private-key handling, transaction signing, and chain interactions.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
eth-account>=0.11.0
requests>=2.28.0

Unverifiable Dependency: eth-account has 2 known advisory(ies) (CVE-2022-1930 (Regular expression denial of service in eth-account); CVE-2022-1930 (Regular expression denial of service in eth-account)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

eth-account has known advisories, and because the manifest does not pin a specific version, there is no reliable way to determine whether deployments will install a fixed or affected release. In the context of an autonomous EVM wallet, uncertainty around the security state of a signing library materially increases risk because failures or denial-of-service conditions can interrupt or destabilize transaction handling.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency specifier requests>=2.28.0 is unpinned, allowing uncontrolled upgrades or environment-specific resolution to versions with different security properties. Because this skill performs network operations for autonomous crypto transfers, an unsafe or behavior-changing requests version could affect RPC/API communication and potentially expose sensitive data or alter trust assumptions.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
eth-account>=0.11.0
requests>=2.28.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

requests has multiple published advisories, and the absence of version pinning makes the installed version unverifiable from the manifest alone. This is particularly concerning for a wallet tool that likely communicates with remote services, since request-handling flaws can lead to credential leakage, TLS/trust issues, or other network-layer weaknesses that impact transaction workflows and sensitive metadata.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.