Back to skill

Security audit

Base Wallet

Security checks for vulnerabilities and agentic risk

Overview

This wallet skill is mostly coherent with its stated purpose, but it handles private keys and wallet signatures in ways that need careful review before installation.

Install only if you are comfortable giving this skill access to wallet private keys and signatures. Use a new low-value wallet, avoid storing secrets in managed mode unless you protect the host and backups, review every BaseMail signing action, and do not reuse a valuable wallet for this skill until SIWE validation and wallet-name path validation are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 ยท Insecure Skill Coding Practices

Error
Location
scripts/basemail-register.js:74
Finding

Remote-provided authentication message is signed without SIWE validation

Content
View full analysis
Remediation
View remediation

T09 ยท Insecure Skill Coding Practices

Warning
Location
scripts/basemail-register.js:49
Finding

Unvalidated wallet names permit path traversal outside the wallet directory

Content
View full analysis
Remediation
View remediation

T09 ยท Insecure Skill Coding Practices

Warning
Location
scripts/create-wallet.js:149
Finding

Managed mode stores and duplicates unencrypted wallet secrets

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The file claims SIWE signing, transaction sending, and autonomous operation, but the documented content does not consistently demonstrate those capabilities and also introduces local secret persistence and possible interactive flows. Misrepresenting what the skill actually does is a security problem because operators may trust it for one purpose while it silently stores secrets or behaves non-autonomously in ways that break security assumptions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file claims SIWE signing, transaction sending, and autonomous operation, but the documented content does not consistently demonstrate those capabilities and also introduces local secret persistence and possible interactive flows. Misrepresenting what the skill actually does is a security problem because operators may trust it for one purpose while it silently stores secrets or behaves non-autonomously in ways that break security assumptions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 40)May include surrounding context.

md
node scripts/create-wallet.js --env

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 53)May include surrounding context.

md
node scripts/create-wallet.js --env

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 139)May include surrounding context.

md
PRIVATE_KEY="0x..." node scripts/basemail-register.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 142)May include surrounding context.

md
PRIVATE_KEY="0x..." node scripts/basemail-register.js

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The script prints the raw private key and mnemonic directly to stdout and explicitly recommends copying them into shell commands or a .env file. In agent or automated environments, stdout, shell history, CI logs, terminal capture, and environment-file handling are common exfiltration paths for long-lived secrets, making credential compromise likely if this mode is used carelessly.

Content

Scanner excerpt ยท scripts/create-wallet.js (reported line 100)May include surrounding context.

js
// Mode: --env (recommended)
  if (isEnv) {
    console.log('# ๐Ÿ” New Wallet Created');
    console.log('# Copy these lines to your shell or .env file:');
    console.log('');
    console.log(`export WALLET_ADDRESS="${wallet.address}"`);
    console.log(`export PRIVATE_KEY="${wallet.privateKey}"`);

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents capabilities that use environment variables and external network access, but it does not declare an explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can allow a caller or runtime to underestimate the skill's ability to access secrets and perform outbound actions, increasing the chance of unintended wallet operations or secret exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill language strongly encourages autonomous wallet creation and control without emphasizing a human approval boundary for key generation and account use. In agentic environments, creating a wallet automatically can establish a persistent identity that may later be used for external registration, message signing, or financial actions without meaningful operator review.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt ยท SKILL.md (reported line 28)May include surrounding context.

md
| โœ… DO | โŒ DON'T |
|-------|----------|
| Use **environment variables** for private keys | Store private keys in plain text files |
| Set wallet files to **chmod 600** | Commit wallet files to git |
| Use `--env` mode (recommended) | Use `console.log(privateKey)` |
| Back up mnemonics **offline** | Share private keys or mnemonics |

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The recommended flow outputs an exportable private key into shell environment state, which can persist for the session and may be inherited by subprocesses, shell history workflows, logs, or debugging tools. In an agent environment, session-persistent secrets increase the blast radius if another tool, plugin, or child process can read environment variables.

Content

Scanner excerpt ยท SKILL.md (reported line 36)May include surrounding context.

Quick Start

Create a New Wallet (Recommended)

bash
# Output as environment variable format (safest)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This reference file documents a distinct BaseMail service with SIWE auth, email registration, inbox access, and credit purchasing, which is outside the stated scope of a wallet/signing/transaction skill. In an agent setting, this kind of scope drift is dangerous because it can silently expand the agent's reachable capabilities to identity creation, message exfiltration, and spending behavior that users did not intend to authorize.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented send/read email capability gives the skill access to communications functions unrelated to basic wallet management. In the context of an autonomous Web3 agent, that creates meaningful risk of data exfiltration, phishing, impersonation, or unauthorized outbound communications under a wallet-derived identity, making the mismatch more dangerous than in a general productivity or email skill.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt ยท scripts/create-wallet.js (reported line 3)May include surrounding context.

js
#!/usr/bin/env node
/**
 * Create a new Base/Ethereum wallet
 * 
 * Usage:
 *   node create-wallet.js                    # Show help

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The dependency on ethers uses a caret range (^6.0.0), which permits automatic installation of newer minor and patch versions. In a security-sensitive wallet skill that creates wallets, signs messages, and sends transactions, an upstream compromised release or breaking behavioral change could directly affect key handling, transaction construction, or signing flows.

Content

Scanner excerpt ยท package.json (reported line 11)May include surrounding context.

json
"balance": "node scripts/check-balance.js"
  },
  "dependencies": {
    "ethers": "^6.0.0"
  },
  "keywords": ["base", "ethereum", "wallet", "ai-agent", "siwe"],
  "license": "MIT"

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation notes that external email requires credits but does not present a clear warning at the point of use that sending may incur spend. For autonomous agents, insufficient cost transparency can lead to unintended credit consumption or onchain top-ups being triggered without the operator fully understanding the financial consequence.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest frames the skill around creating wallets, signing messages, and sending transactions for autonomous Web3 identity. This script additionally creates a local audit log containing registration activity and later updates managed wallet JSON files with BaseMail-specific metadata, which is behavior not suggested by the manifest description of wallet and transaction operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

After registering an email, the code modifies the managed wallet file by adding basemail metadata and a registration timestamp. The manifest does not mention profile enrichment or mutation of wallet files as part of BaseMail registration, so the implemented behavior exceeds the described scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The interactive warning tells the user the private key file location is '~/.openclaw/wallets/.json', creating a specific expectation about where sensitive material will be written. However, the actual storage path is determined by process.env.WALLET_DIR when set, so the documentation shown to the user can be false for the same execution path.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/basemail-register.js:19

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/create-wallet.js:118

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:186