T09 ยท Insecure Skill Coding Practices
- Location
scripts/basemail-register.js:74- Finding
Remote-provided authentication message is signed without SIWE validation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This wallet skill is mostly coherent with its stated purpose, but it handles private keys and wallet signatures in ways that need careful review before installation.
Install only if you are comfortable giving this skill access to wallet private keys and signatures. Use a new low-value wallet, avoid storing secrets in managed mode unless you protect the host and backups, review every BaseMail signing action, and do not reuse a valuable wallet for this skill until SIWE validation and wallet-name path validation are fixed.
scripts/basemail-register.js:74Remote-provided authentication message is signed without SIWE validation
scripts/basemail-register.js:49Unvalidated wallet names permit path traversal outside the wallet directory
scripts/create-wallet.js:149Managed mode stores and duplicates unencrypted wallet secrets
The file claims SIWE signing, transaction sending, and autonomous operation, but the documented content does not consistently demonstrate those capabilities and also introduces local secret persistence and possible interactive flows. Misrepresenting what the skill actually does is a security problem because operators may trust it for one purpose while it silently stores secrets or behaves non-autonomously in ways that break security assumptions.
The file claims SIWE signing, transaction sending, and autonomous operation, but the documented content does not consistently demonstrate those capabilities and also introduces local secret persistence and possible interactive flows. Misrepresenting what the skill actually does is a security problem because operators may trust it for one purpose while it silently stores secrets or behaves non-autonomously in ways that break security assumptions.
Referenced artifact was not completely inspected
node scripts/create-wallet.js --env
Referenced artifact was not completely inspected
node scripts/create-wallet.js --env
Referenced artifact was not completely inspected
PRIVATE_KEY="0x..." node scripts/basemail-register.js
Referenced artifact was not completely inspected
PRIVATE_KEY="0x..." node scripts/basemail-register.js
The script prints the raw private key and mnemonic directly to stdout and explicitly recommends copying them into shell commands or a .env file. In agent or automated environments, stdout, shell history, CI logs, terminal capture, and environment-file handling are common exfiltration paths for long-lived secrets, making credential compromise likely if this mode is used carelessly.
// Mode: --env (recommended)
if (isEnv) {
console.log('# ๐ New Wallet Created');
console.log('# Copy these lines to your shell or .env file:');
console.log('');
console.log(`export WALLET_ADDRESS="${wallet.address}"`);
console.log(`export PRIVATE_KEY="${wallet.privateKey}"`);
The skill documents capabilities that use environment variables and external network access, but it does not declare an explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can allow a caller or runtime to underestimate the skill's ability to access secrets and perform outbound actions, increasing the chance of unintended wallet operations or secret exposure.
The skill language strongly encourages autonomous wallet creation and control without emphasizing a human approval boundary for key generation and account use. In agentic environments, creating a wallet automatically can establish a persistent identity that may later be used for external registration, message signing, or financial actions without meaningful operator review.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
| โ
DO | โ DON'T |
|-------|----------|
| Use **environment variables** for private keys | Store private keys in plain text files |
| Set wallet files to **chmod 600** | Commit wallet files to git |
| Use `--env` mode (recommended) | Use `console.log(privateKey)` |
| Back up mnemonics **offline** | Share private keys or mnemonics |
The recommended flow outputs an exportable private key into shell environment state, which can persist for the session and may be inherited by subprocesses, shell history workflows, logs, or debugging tools. In an agent environment, session-persistent secrets increase the blast radius if another tool, plugin, or child process can read environment variables.
# Output as environment variable format (safest)
This reference file documents a distinct BaseMail service with SIWE auth, email registration, inbox access, and credit purchasing, which is outside the stated scope of a wallet/signing/transaction skill. In an agent setting, this kind of scope drift is dangerous because it can silently expand the agent's reachable capabilities to identity creation, message exfiltration, and spending behavior that users did not intend to authorize.
The documented send/read email capability gives the skill access to communications functions unrelated to basic wallet management. In the context of an autonomous Web3 agent, that creates meaningful risk of data exfiltration, phishing, impersonation, or unauthorized outbound communications under a wallet-derived identity, making the mismatch more dangerous than in a general productivity or email skill.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
#!/usr/bin/env node
/**
* Create a new Base/Ethereum wallet
*
* Usage:
* node create-wallet.js # Show help
The dependency on ethers uses a caret range (^6.0.0), which permits automatic installation of newer minor and patch versions. In a security-sensitive wallet skill that creates wallets, signs messages, and sends transactions, an upstream compromised release or breaking behavioral change could directly affect key handling, transaction construction, or signing flows.
"balance": "node scripts/check-balance.js"
},
"dependencies": {
"ethers": "^6.0.0"
},
"keywords": ["base", "ethereum", "wallet", "ai-agent", "siwe"],
"license": "MIT"
The documentation notes that external email requires credits but does not present a clear warning at the point of use that sending may incur spend. For autonomous agents, insufficient cost transparency can lead to unintended credit consumption or onchain top-ups being triggered without the operator fully understanding the financial consequence.
The manifest frames the skill around creating wallets, signing messages, and sending transactions for autonomous Web3 identity. This script additionally creates a local audit log containing registration activity and later updates managed wallet JSON files with BaseMail-specific metadata, which is behavior not suggested by the manifest description of wallet and transaction operations.
After registering an email, the code modifies the managed wallet file by adding basemail metadata and a registration timestamp. The manifest does not mention profile enrichment or mutation of wallet files as part of BaseMail registration, so the implemented behavior exceeds the described scope.
The interactive warning tells the user the private key file location is '~/.openclaw/wallets/.json', creating a specific expectation about where sensitive material will be written. However, the actual storage path is determined by process.env.WALLET_DIR when set, so the documentation shown to the user can be false for the same execution path.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal