Back to skill

Security audit

Basename Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is for wallet-based Basename and email registration, but it gives an agent broad automatic wallet-signing and transaction authority with weak scoping and confirmation controls.

Install only if you are comfortable giving this skill control of a dedicated, low-balance wallet. Do not use a main wallet. Treat every registration, email/account binding, signature, and transaction as irreversible or security-sensitive, and prefer interactive/manual review until the skill enforces strict allowlists and SIWE/transaction validation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 ยท Insecure Skill Coding Practices

Error
Location
scripts/wc-connect.js:231
Finding

WalletConnect Sessions and Signing Requests Are Automatically Approved

Content
View full analysis
Remediation
View remediation

T09 ยท Insecure Skill Coding Practices

Error
Location
SKILL.md:108
Finding

Remote Authentication Challenges Are Signed Without SIWE Validation

Content
View full analysis
r.json()); // 2. Sign + Register (auto-detects your new Basename) const signature = await account.signMessage({ message }); const { token, email } = await fetch('https://api.basemail.ai/api/auth/agent-register', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ address: account.address, signature, message, basename: fullName }), }).then(r => r.json()); ``` The documented Python flow has the same behavior: ```python resp = requests.post('https://api.basemail.ai/api/auth/start', json={'address': wallet.address}).json() sig = wallet.sign_message(encode_defunct(text=resp['message'])) auth = requests.post('https://api.basemail.ai/api/auth/agent-register', json={'address': wallet.address, 'signature': sig.signature.hex(), 'message': resp['message']}).json() ``` ### Technical Analysis The authentication server supplies the complete message that the wallet signs. The documented examples do not parse or validate the message as an EIP-4361 Sign-In with Ethereum challenge before signing it. No checks are performed for: - The expected `basemail.ai` domain. - The expected URI. - The wallet address in the challenge. - The intended chain ID. - A fresh and unpredictable nonce. - Challenge issuance and expiration times. - The authentication statement or requested action. - Resources or other authorization-bearing fields. - Reuse of a previously signed challenge. TLS protects transport under normal conditions, but it does not make arbitr ...[truncated 1983 chars]
Remediation
View remediation

T08 ยท Insecure Dependencies

Warning
Location
package.json:8
Finding

Security-Critical Dependencies Are Not Reproducibly Pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This skill context involves automated WalletConnect pairing, message signing, typed-data signing, and transaction submission from a hot wallet, but these capabilities are not clearly bounded in the top-level declaration. In an autonomous agent environment, undocumented signing authority is dangerous because it can be reused for unintended approvals or wallet actions beyond simple name registration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This skill context involves automated WalletConnect pairing, message signing, typed-data signing, and transaction submission from a hot wallet, but these capabilities are not clearly bounded in the top-level declaration. In an autonomous agent environment, undocumented signing authority is dangerous because it can be reused for unintended approvals or wallet actions beyond simple name registration.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The package description advertises autonomous basename registration over WalletConnect but does not warn that wallet interaction may create onchain transactions, incur fees, or affect user-controlled assets. In the context of an agent skill handling identity registration and wallet connectivity, missing warnings can cause users or host agents to invoke financially sensitive actions without understanding the consequences.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script is a general-purpose WalletConnect signer that can pair with arbitrary dApps and sign transactions or messages, which materially exceeds the stated basename/email registration purpose. In an agent context, especially with non-interactive mode available, this creates a capability for unintended asset transfers or approvals through any paired dApp.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The approved WalletConnect namespace exposes broad wallet methods including transaction sending, transaction signing, and typed-data signing to any connected dApp. That is unjustified for a basename/email registration skill and enables phishing-style signature requests, malicious approvals, or arbitrary transactions if an attacker controls or spoofs the paired dApp.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill demonstrates access to sensitive capabilities such as environment variables for private keys and outbound network calls, but it does not declare any tool scope or permissions. In an agent setting, missing capability declarations reduce transparency and can cause an operator to authorize a skill without realizing it can access wallet secrets and contact third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation encourages automated name purchases, identity registration, and email/account creation without a clear, prominent warning that these actions can spend funds and permanently associate a wallet with a public identity. In this context, the absence of strong consent language increases the chance of accidental financial loss or unintended doxxing/identity linkage by an agent acting automatically.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 42)May include surrounding context.

Step 1: Check Price

bash
curl https://api.basemail.ai/api/donate-buy/quote/yourname

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 86)May include surrounding context.

Step 1: Check Price

bash
curl https://api.basemail.ai/api/donate-buy/quote/yourname

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 103)May include surrounding context.

Step 1: Check Price

bash
curl https://api.basemail.ai/api/donate-buy/quote/yourname

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 148)May include surrounding context.

Step 1: Check Price

bash
curl https://api.basemail.ai/api/donate-buy/quote/yourname

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 151)May include surrounding context.

Step 1: Check Price

bash
curl https://api.basemail.ai/api/donate-buy/quote/yourname

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 178)May include surrounding context.

Step 1: Check Price

bash
curl https://api.basemail.ai/api/donate-buy/quote/yourname

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 263)May include surrounding context.

Step 1: Check Price

bash
curl https://api.basemail.ai/api/donate-buy/quote/yourname

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 103)May include surrounding context.

javascript
// 1. Auth
const { message } = await fetch('https://api.basemail.ai/api/auth/start', {
  method: 'POST', headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ address: account.address }),
}).then(r => r.json());

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This duplicate finding again captures transmission of wallet-authentication signatures to a remote service. In this skill context, automatic handling of signed identity assertions raises risk of unintended account binding or misuse if users are not clearly warned.

Content

Scanner excerpt ยท SKILL.md (reported line 110)May include surrounding context.

md
// 2. Sign + Register (auto-detects your new Basename)
const signature = await account.signMessage({ message });
const { token, email } = await fetch('https://api.basemail.ai/api/auth/agent-register', {
  method: 'POST', headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ address: account.address, signature, message, basename: fullName }),
}).then(r => r.json());

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This duplicate finding again captures transmission of wallet-authentication signatures to a remote service. In this skill context, automatic handling of signed identity assertions raises risk of unintended account binding or misuse if users are not clearly warned.

Content

Scanner excerpt ยท SKILL.md (reported line 110)May include surrounding context.

md
// 2. Sign + Register (auto-detects your new Basename)
const signature = await account.signMessage({ message });
const { token, email } = await fetch('https://api.basemail.ai/api/auth/agent-register', {
  method: 'POST', headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ address: account.address, signature, message, basename: fullName }),
}).then(r => r.json());

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 148)May include surrounding context.

bash
# 1. Check availability
curl https://api.basemail.ai/api/register/check/yourname

# 2. Get SIWE message
curl -X POST https://api.basemail.ai/api/auth/start \

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This request sends signed authentication material to the third-party registration service. Because the signature can authorize account creation or linkage, it is a sensitive external transmission in the context of an agent skill with wallet access.

Content

Scanner excerpt ยท SKILL.md (reported line 156)May include surrounding context.

md
-d '{"address":"YOUR_WALLET_ADDRESS"}'

# 3. Sign + Register
curl -X POST https://api.basemail.ai/api/auth/agent-register \
  -H "Content-Type: application/json" \
  -d '{"address":"...","signature":"0x...","message":"..."}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This authenticated upgrade request instructs a third-party service to auto-register a basename and upgrade email state. It is sensitive because it triggers persistent account and identity changes using a bearer token over the network.

Content

Scanner excerpt ยท SKILL.md (reported line 161)May include surrounding context.

md
-d '{"address":"...","signature":"0x...","message":"..."}'

# 4. Auto-buy Basename + upgrade email
curl -X PUT https://api.basemail.ai/api/register/upgrade \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -d '{"auto_basename": true, "basename_name": "yourname"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 178)May include surrounding context.

md
wallet = Account.from_key(PRIVATE_KEY)

# Auth
resp = requests.post('https://api.basemail.ai/api/auth/start',
    json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt ยท SKILL.md (reported line 178)May include surrounding context.

md
wallet = Account.from_key(PRIVATE_KEY)

# Auth
resp = requests.post('https://api.basemail.ai/api/auth/start',
    json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This duplicate reflects transmission of signature-based authentication data to the service, which is security-sensitive because it binds the wallet identity to a remote account. The risk is amplified in an agent workflow that may perform the action automatically.

Content

Scanner excerpt ยท SKILL.md (reported line 181)May include surrounding context.

md
resp = requests.post('https://api.basemail.ai/api/auth/start',
    json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',
    json={'address': wallet.address, 'signature': sig.signature.hex(),
          'message': resp['message']}).json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This duplicate reflects transmission of signature-based authentication data to the service, which is security-sensitive because it binds the wallet identity to a remote account. The risk is amplified in an agent workflow that may perform the action automatically.

Content

Scanner excerpt ยท SKILL.md (reported line 181)May include surrounding context.

md
resp = requests.post('https://api.basemail.ai/api/auth/start',
    json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',
    json={'address': wallet.address, 'signature': sig.signature.hex(),
          'message': resp['message']}).json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This duplicate reflects transmission of signature-based authentication data to the service, which is security-sensitive because it binds the wallet identity to a remote account. The risk is amplified in an agent workflow that may perform the action automatically.

Content

Scanner excerpt ยท SKILL.md (reported line 181)May include surrounding context.

md
resp = requests.post('https://api.basemail.ai/api/auth/start',
    json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',
    json={'address': wallet.address, 'signature': sig.signature.hex(),
          'message': resp['message']}).json()

Static analysis

No suspicious patterns detected.