T09 ยท Insecure Skill Coding Practices
- Location
scripts/wc-connect.js:231- Finding
WalletConnect Sessions and Signing Requests Are Automatically Approved
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is for wallet-based Basename and email registration, but it gives an agent broad automatic wallet-signing and transaction authority with weak scoping and confirmation controls.
Install only if you are comfortable giving this skill control of a dedicated, low-balance wallet. Do not use a main wallet. Treat every registration, email/account binding, signature, and transaction as irreversible or security-sensitive, and prefer interactive/manual review until the skill enforces strict allowlists and SIWE/transaction validation.
scripts/wc-connect.js:231WalletConnect Sessions and Signing Requests Are Automatically Approved
SKILL.md:108Remote Authentication Challenges Are Signed Without SIWE Validation
package.json:8Security-Critical Dependencies Are Not Reproducibly Pinned
This skill context involves automated WalletConnect pairing, message signing, typed-data signing, and transaction submission from a hot wallet, but these capabilities are not clearly bounded in the top-level declaration. In an autonomous agent environment, undocumented signing authority is dangerous because it can be reused for unintended approvals or wallet actions beyond simple name registration.
This skill context involves automated WalletConnect pairing, message signing, typed-data signing, and transaction submission from a hot wallet, but these capabilities are not clearly bounded in the top-level declaration. In an autonomous agent environment, undocumented signing authority is dangerous because it can be reused for unintended approvals or wallet actions beyond simple name registration.
The package description advertises autonomous basename registration over WalletConnect but does not warn that wallet interaction may create onchain transactions, incur fees, or affect user-controlled assets. In the context of an agent skill handling identity registration and wallet connectivity, missing warnings can cause users or host agents to invoke financially sensitive actions without understanding the consequences.
This script is a general-purpose WalletConnect signer that can pair with arbitrary dApps and sign transactions or messages, which materially exceeds the stated basename/email registration purpose. In an agent context, especially with non-interactive mode available, this creates a capability for unintended asset transfers or approvals through any paired dApp.
The approved WalletConnect namespace exposes broad wallet methods including transaction sending, transaction signing, and typed-data signing to any connected dApp. That is unjustified for a basename/email registration skill and enables phishing-style signature requests, malicious approvals, or arbitrary transactions if an attacker controls or spoofs the paired dApp.
The skill demonstrates access to sensitive capabilities such as environment variables for private keys and outbound network calls, but it does not declare any tool scope or permissions. In an agent setting, missing capability declarations reduce transparency and can cause an operator to authorize a skill without realizing it can access wallet secrets and contact third-party services.
The documentation encourages automated name purchases, identity registration, and email/account creation without a clear, prominent warning that these actions can spend funds and permanently associate a wallet with a public identity. In this context, the absence of strong consent language increases the chance of accidental financial loss or unintended doxxing/identity linkage by an agent acting automatically.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://api.basemail.ai/api/donate-buy/quote/yourname
Response:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://api.basemail.ai/api/donate-buy/quote/yourname
Response:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://api.basemail.ai/api/donate-buy/quote/yourname
Response:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://api.basemail.ai/api/donate-buy/quote/yourname
Response:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://api.basemail.ai/api/donate-buy/quote/yourname
Response:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://api.basemail.ai/api/donate-buy/quote/yourname
Response:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://api.basemail.ai/api/donate-buy/quote/yourname
Response:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// 1. Auth
const { message } = await fetch('https://api.basemail.ai/api/auth/start', {
method: 'POST', headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ address: account.address }),
}).then(r => r.json());
This duplicate finding again captures transmission of wallet-authentication signatures to a remote service. In this skill context, automatic handling of signed identity assertions raises risk of unintended account binding or misuse if users are not clearly warned.
// 2. Sign + Register (auto-detects your new Basename)
const signature = await account.signMessage({ message });
const { token, email } = await fetch('https://api.basemail.ai/api/auth/agent-register', {
method: 'POST', headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ address: account.address, signature, message, basename: fullName }),
}).then(r => r.json());
This duplicate finding again captures transmission of wallet-authentication signatures to a remote service. In this skill context, automatic handling of signed identity assertions raises risk of unintended account binding or misuse if users are not clearly warned.
// 2. Sign + Register (auto-detects your new Basename)
const signature = await account.signMessage({ message });
const { token, email } = await fetch('https://api.basemail.ai/api/auth/agent-register', {
method: 'POST', headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ address: account.address, signature, message, basename: fullName }),
}).then(r => r.json());
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 1. Check availability
curl https://api.basemail.ai/api/register/check/yourname
# 2. Get SIWE message
curl -X POST https://api.basemail.ai/api/auth/start \
This request sends signed authentication material to the third-party registration service. Because the signature can authorize account creation or linkage, it is a sensitive external transmission in the context of an agent skill with wallet access.
-d '{"address":"YOUR_WALLET_ADDRESS"}'
# 3. Sign + Register
curl -X POST https://api.basemail.ai/api/auth/agent-register \
-H "Content-Type: application/json" \
-d '{"address":"...","signature":"0x...","message":"..."}'
This authenticated upgrade request instructs a third-party service to auto-register a basename and upgrade email state. It is sensitive because it triggers persistent account and identity changes using a bearer token over the network.
-d '{"address":"...","signature":"0x...","message":"..."}'
# 4. Auto-buy Basename + upgrade email
curl -X PUT https://api.basemail.ai/api/register/upgrade \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_TOKEN" \
-d '{"auto_basename": true, "basename_name": "yourname"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
wallet = Account.from_key(PRIVATE_KEY)
# Auth
resp = requests.post('https://api.basemail.ai/api/auth/start',
json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
wallet = Account.from_key(PRIVATE_KEY)
# Auth
resp = requests.post('https://api.basemail.ai/api/auth/start',
json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',
This duplicate reflects transmission of signature-based authentication data to the service, which is security-sensitive because it binds the wallet identity to a remote account. The risk is amplified in an agent workflow that may perform the action automatically.
resp = requests.post('https://api.basemail.ai/api/auth/start',
json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',
json={'address': wallet.address, 'signature': sig.signature.hex(),
'message': resp['message']}).json()
This duplicate reflects transmission of signature-based authentication data to the service, which is security-sensitive because it binds the wallet identity to a remote account. The risk is amplified in an agent workflow that may perform the action automatically.
resp = requests.post('https://api.basemail.ai/api/auth/start',
json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',
json={'address': wallet.address, 'signature': sig.signature.hex(),
'message': resp['message']}).json()
This duplicate reflects transmission of signature-based authentication data to the service, which is security-sensitive because it binds the wallet identity to a remote account. The risk is amplified in an agent workflow that may perform the action automatically.
resp = requests.post('https://api.basemail.ai/api/auth/start',
json={'address': wallet.address}).json()
sig = wallet.sign_message(encode_defunct(text=resp['message']))
auth = requests.post('https://api.basemail.ai/api/auth/agent-register',
json={'address': wallet.address, 'signature': sig.signature.hex(),
'message': resp['message']}).json()
No suspicious patterns detected.