Back to skill

Security audit

Nad Wallet

Security checks for vulnerabilities and agentic risk

Overview

This wallet skill matches its Nad Wallet purpose, but it needs review because it exposes and persists wallet secrets and signs a NadMail server-provided message without enough local validation.

Review this carefully before installing. Use it only in an isolated environment with wallets that hold no meaningful funds, avoid managed wallet storage and shell startup persistence, do not expose generated keys in shared terminals or logs, and treat NadMail registration as signing a third-party controlled authentication message until the SIWE validation and wallet-name path handling are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 ยท Insecure Skill Coding Practices

Error
Location
scripts/nadmail-register.js:132
Finding

Unvalidated Server-Controlled Message Is Signed by the Wallet

Content
View full analysis
Remediation
View remediation

T09 ยท Insecure Skill Coding Practices

Warning
Location
scripts/create-wallet.js:91
Finding

Wallet Names Permit Filesystem Path Traversal

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill advertises wallet identity operations but also performs or instructs remote account registration, local token storage, and metadata/log updates that are not clearly surfaced as primary behaviors. In a security-sensitive wallet context, undeclared remote registration and credential persistence broaden the trust boundary and can expose users to credential theft, privacy leakage, or unintended account creation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill advertises wallet identity operations but also performs or instructs remote account registration, local token storage, and metadata/log updates that are not clearly surfaced as primary behaviors. In a security-sensitive wallet context, undeclared remote registration and credential persistence broaden the trust boundary and can expose users to credential theft, privacy leakage, or unintended account creation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 58)May include surrounding context.

md
node scripts/create-wallet.js --env

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 71)May include surrounding context.

md
node scripts/create-wallet.js --env

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 167)May include surrounding context.

md
node scripts/create-wallet.js --env

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 342)May include surrounding context.

md
node scripts/create-wallet.js --env

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 160)May include surrounding context.

md
node scripts/nadmail-register.js --handle littlelobster

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 170)May include surrounding context.

md
node scripts/nadmail-register.js --handle littlelobster

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 239)May include surrounding context.

md
node scripts/nadmail-register.js --handle littlelobster

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 270)May include surrounding context.

md
node scripts/nadmail-register.js --handle littlelobster

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 348)May include surrounding context.

md
node scripts/nadmail-register.js --handle littlelobster

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill instructs storing a NadMail access token in a predictable local file under ~/.nad-wallet. Persistent bearer tokens materially increase account-takeover risk if the host is compromised, permissions are misconfigured, backups leak, or other local tooling can read the file.

Content

Scanner excerpt ยท SKILL.md (reported line 178)May include surrounding context.

md
1. **Start Auth** - Request authentication message from NadMail API
2. **Sign Message** - Use your private key to sign the SIWE message
3. **Agent Register** - Submit signature and handle to complete registration
4. **Save Token** - Store access token in `~/.nad-wallet/nadmail-token.json`

---

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 186)May include surrounding context.

md
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 189)May include surrounding context.

md
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 192)May include surrounding context.

md
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 269)May include surrounding context.

md
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 345)May include surrounding context.

md
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt ยท SKILL.md (reported line 300)May include surrounding context.

nad-private-key*

Environment files

.env .env.local

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt ยท SKILL.md (reported line 301)May include surrounding context.

Environment files

.env .env.local

text

---

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

Although this is not classic malware persistence, appending export NAD_PRIVATE_KEY to ~/.bashrc is still credential persistence in a startup script and is dangerous in a wallet skill. It causes a highly sensitive secret to be automatically loaded into future sessions from plaintext disk storage, magnifying compromise impact if the profile file is exposed or tampered with.

Content

Scanner excerpt ยท SKILL.md (reported line 391)May include surrounding context.

handle is available

  • Ensure wallet has MON for gas fees
  1. "Permission denied"
    • Check file permissions: chmod 600 ~/.nad-wallet/wallets/*.json
    • Verify directory permissions: chmod 700 ~/.nad-wallet/

Environment Variable Not Set

bash
# Check if set
echo $NAD_PRIVATE_KEY

# Set temporarily
export NAD_PRIVATE_KEY="0x..."

# Set permanently (add to ~/.bashrc or ~/.zshrc)
echo 'export NAD_PRIVATE_KEY="0x..."' >> ~/.bashrc

Changelog

v1.0.0 (2026-02-09)

  • ๐ŸŽ‰ Initial release for Monad blockchain
  • ๐Ÿ” Security: Environment variable approach (--env mode default)
  • ๐Ÿ“ง NadMail SIWE integration
  • ๐Ÿ’ฐ MON balance checking
  • ๐Ÿ“ Comprehensive audit logging
  • ๐ŸŒ Nad ecosystem integration (nad.fun, NadMail, NadName)
  • ๐Ÿ“š Complete documentation with security best practices
  • ๐Ÿ”’ File permissions enforcement (600/700)

License

MIT License - Build awesome things with Nad Wallet! ๐Ÿš€

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The script deliberately prints the private key and mnemonic to stdout and explicitly recommends copying them into shell environment variables or a .env file. In agent, CI, terminal history, logging, or piped execution contexts, stdout is often captured, persisted, or exposed to other processes, which can directly leak wallet secrets and allow full theft of funds and identity misuse.

Content

Scanner excerpt ยท scripts/create-wallet.js (reported line 105)May include surrounding context.

js
// Mode: --env (recommended)
  if (isEnv) {
    console.log('# ๐Ÿ” New Nad Wallet Created (Monad Chain)');
    console.log('# Copy these lines to your shell or .env file:');
    console.log('');
    console.log(`export NAD_WALLET_ADDRESS="${wallet.address}"`);
    console.log(`export NAD_PRIVATE_KEY="${wallet.privateKey}"`);

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents use of environment variables and network/RPC access, but the manifest declares no explicit tool scope or allowed-tools. In an agent setting, missing capability declarations weaken operator visibility and policy enforcement, increasing the chance the skill is executed with broader privileges than intended.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt ยท SKILL.md (reported line 30)May include surrounding context.

md
| โœ… DO | โŒ DON'T |
|-------|----------|
| Use **NAD_PRIVATE_KEY** environment variable | Store private keys in plain text files |
| Set wallet files to **chmod 600** | Commit wallet files to git |
| Use `--env` mode (recommended) | Use `console.log(privateKey)` |
| Back up mnemonics **offline** | Share private keys or mnemonics |
| Store files in `~/.nad-wallet/` only | Auto-detect wallets outside ~/.nad-wallet/ |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt ยท SKILL.md (reported line 378)May include surrounding context.

md
| โœ… DO | โŒ DON'T |
|-------|----------|
| Use **NAD_PRIVATE_KEY** environment variable | Store private keys in plain text files |
| Set wallet files to **chmod 600** | Commit wallet files to git |
| Use `--env` mode (recommended) | Use `console.log(privateKey)` |
| Back up mnemonics **offline** | Share private keys or mnemonics |
| Store files in `~/.nad-wallet/` only | Auto-detect wallets outside ~/.nad-wallet/ |

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The recommended --env workflow outputs export commands containing the wallet private key. In agent or shared-terminal environments, emitting secrets to stdout increases the chance of leakage through logs, command history capture, terminal scrollback, orchestration traces, or copied transcripts.

Content

Scanner excerpt ยท SKILL.md (reported line 54)May include surrounding context.

Quick Start

Create a New Wallet (Recommended)

bash
# Output as environment variable format (safest)

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/nadmail-register.js:19

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/create-wallet.js:127

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:283