T09 ยท Insecure Skill Coding Practices
- Location
scripts/nadmail-register.js:132- Finding
Unvalidated Server-Controlled Message Is Signed by the Wallet
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This wallet skill matches its Nad Wallet purpose, but it needs review because it exposes and persists wallet secrets and signs a NadMail server-provided message without enough local validation.
Review this carefully before installing. Use it only in an isolated environment with wallets that hold no meaningful funds, avoid managed wallet storage and shell startup persistence, do not expose generated keys in shared terminals or logs, and treat NadMail registration as signing a third-party controlled authentication message until the SIWE validation and wallet-name path handling are fixed.
scripts/nadmail-register.js:132Unvalidated Server-Controlled Message Is Signed by the Wallet
scripts/create-wallet.js:91Wallet Names Permit Filesystem Path Traversal
The skill advertises wallet identity operations but also performs or instructs remote account registration, local token storage, and metadata/log updates that are not clearly surfaced as primary behaviors. In a security-sensitive wallet context, undeclared remote registration and credential persistence broaden the trust boundary and can expose users to credential theft, privacy leakage, or unintended account creation.
The skill advertises wallet identity operations but also performs or instructs remote account registration, local token storage, and metadata/log updates that are not clearly surfaced as primary behaviors. In a security-sensitive wallet context, undeclared remote registration and credential persistence broaden the trust boundary and can expose users to credential theft, privacy leakage, or unintended account creation.
Referenced artifact was not completely inspected
node scripts/create-wallet.js --env
Referenced artifact was not completely inspected
node scripts/create-wallet.js --env
Referenced artifact was not completely inspected
node scripts/create-wallet.js --env
Referenced artifact was not completely inspected
node scripts/create-wallet.js --env
Referenced artifact was not completely inspected
node scripts/nadmail-register.js --handle littlelobster
Referenced artifact was not completely inspected
node scripts/nadmail-register.js --handle littlelobster
Referenced artifact was not completely inspected
node scripts/nadmail-register.js --handle littlelobster
Referenced artifact was not completely inspected
node scripts/nadmail-register.js --handle littlelobster
Referenced artifact was not completely inspected
node scripts/nadmail-register.js --handle littlelobster
The skill instructs storing a NadMail access token in a predictable local file under ~/.nad-wallet. Persistent bearer tokens materially increase account-takeover risk if the host is compromised, permissions are misconfigured, backups leak, or other local tooling can read the file.
1. **Start Auth** - Request authentication message from NadMail API
2. **Sign Message** - Use your private key to sign the SIWE message
3. **Agent Register** - Submit signature and handle to complete registration
4. **Save Token** - Store access token in `~/.nad-wallet/nadmail-token.json`
---
Referenced artifact was not completely inspected
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js
Referenced artifact was not completely inspected
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js
Referenced artifact was not completely inspected
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js
Referenced artifact was not completely inspected
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js
Referenced artifact was not completely inspected
NAD_PRIVATE_KEY="0x..." node scripts/check-balance.js
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
nad-private-key*
.env .env.local
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
.env .env.local
---
Although this is not classic malware persistence, appending export NAD_PRIVATE_KEY to ~/.bashrc is still credential persistence in a startup script and is dangerous in a wallet skill. It causes a highly sensitive secret to be automatically loaded into future sessions from plaintext disk storage, magnifying compromise impact if the profile file is exposed or tampered with.
handle is available
chmod 600 ~/.nad-wallet/wallets/*.jsonchmod 700 ~/.nad-wallet/# Check if set
echo $NAD_PRIVATE_KEY
# Set temporarily
export NAD_PRIVATE_KEY="0x..."
# Set permanently (add to ~/.bashrc or ~/.zshrc)
echo 'export NAD_PRIVATE_KEY="0x..."' >> ~/.bashrc
MIT License - Build awesome things with Nad Wallet! ๐
The script deliberately prints the private key and mnemonic to stdout and explicitly recommends copying them into shell environment variables or a .env file. In agent, CI, terminal history, logging, or piped execution contexts, stdout is often captured, persisted, or exposed to other processes, which can directly leak wallet secrets and allow full theft of funds and identity misuse.
// Mode: --env (recommended)
if (isEnv) {
console.log('# ๐ New Nad Wallet Created (Monad Chain)');
console.log('# Copy these lines to your shell or .env file:');
console.log('');
console.log(`export NAD_WALLET_ADDRESS="${wallet.address}"`);
console.log(`export NAD_PRIVATE_KEY="${wallet.privateKey}"`);
The skill documents use of environment variables and network/RPC access, but the manifest declares no explicit tool scope or allowed-tools. In an agent setting, missing capability declarations weaken operator visibility and policy enforcement, increasing the chance the skill is executed with broader privileges than intended.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
| โ
DO | โ DON'T |
|-------|----------|
| Use **NAD_PRIVATE_KEY** environment variable | Store private keys in plain text files |
| Set wallet files to **chmod 600** | Commit wallet files to git |
| Use `--env` mode (recommended) | Use `console.log(privateKey)` |
| Back up mnemonics **offline** | Share private keys or mnemonics |
| Store files in `~/.nad-wallet/` only | Auto-detect wallets outside ~/.nad-wallet/ |
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
| โ
DO | โ DON'T |
|-------|----------|
| Use **NAD_PRIVATE_KEY** environment variable | Store private keys in plain text files |
| Set wallet files to **chmod 600** | Commit wallet files to git |
| Use `--env` mode (recommended) | Use `console.log(privateKey)` |
| Back up mnemonics **offline** | Share private keys or mnemonics |
| Store files in `~/.nad-wallet/` only | Auto-detect wallets outside ~/.nad-wallet/ |
The recommended --env workflow outputs export commands containing the wallet private key. In agent or shared-terminal environments, emitting secrets to stdout increases the chance of leakage through logs, command history capture, terminal scrollback, orchestration traces, or copied transcripts.
# Output as environment variable format (safest)
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal