Back to skill

Security audit

Walletconnect Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill openly automates Web3 wallet signing, but its default behavior gives broad transaction authority to WalletConnect dApps without strong user confirmation or transaction validation.

Install only if you are comfortable giving an automated process control over a dedicated, low-value wallet. Use --interactive for any new dApp, avoid funded or primary wallets, verify WalletConnect URIs and dApp origins carefully, and treat typed-data signatures, token approvals, and transactions as irreversible even when eth_sign is blocked.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 ยท Insecure Skill Coding Practices

Error
Location
scripts/wc-connect.js:240
Finding

WalletConnect Requests Are Automatically Approved and Executed Without Security Validation

Content
View full analysis
Remediation
View remediation

T09 ยท Insecure Skill Coding Practices

Error
Location
scripts/register-basename.js:280
Finding

Basename Registration Automation Accepts and Signs Arbitrary Session Requests

Content
View full analysis
{ console.log('โœ… Session proposal from:', proposal.params.proposer.metadata.name); const namespaces = { eip155: { accounts: [`eip155:${BASE_CHAIN_ID}:${address}`], methods: [ 'eth_sendTransaction', 'eth_signTransaction', 'personal_sign', 'eth_signTypedData', 'eth_signTypedData_v4', // Note: eth_sign intentionally excluded (security risk) ], events: ['chainChanged', 'accountsChanged'], chains: [`eip155:${BASE_CHAIN_ID}`], }, }; await web3wallet.approveSession({ id: proposal.id, namespaces }); console.log('โœ… Session approved!'); sessionEstablished = true; }); ``` The request handler executes any supported request delivered through that session: ```js switch (request.method) { case 'personal_sign': { const [message] = request.params; if (ethers.isHexString(message)) { result = await wallet.signMessage(ethers.getBytes(message)); } else { result = await wallet.signMessage(message); } console.log('โœ… Message signed'); break; } case 'eth_signTypedData': case 'eth_signTypedData_v4': { const [, data] = request.params; const typedData = typeof data === 'string' ? JSON.parse(data) : data; const { domain, types, message } = typedData; delete types.EIP712Domain; result = await wallet.signTypedData(domain, types, message); console.log('โœ… Typed data signed'); break; } case 'eth_sendTransaction': { const [tx] = request.params; console.log(` To: ${tx.to}`); console.log(` Value: ${tx.value || '0'} wei`); const txResponse = await wallet.sendTransaction({ to: tx.to, value: tx. ...[truncated 2910 chars]
Remediation
View remediation

T09 ยท Insecure Skill Coding Practices

Error
Location
scripts/register-basename.js:164
Finding

Browser Automation Explicitly Disables the Chromium Sandbox

Content
View full analysis
Remediation
View remediation

T08 ยท Insecure Dependencies

Warning
Location
package.json:7
Finding

Unpinned and Incomplete Dependency Configuration Prevents Reproducible Trusted Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description substantially overstates the skill's scope. The code is not a generic WalletConnect agent for arbitrary dApps; it is a purpose-built automation script for registering a Basename on Base. It hardcodes the target URL, chain, and registration flow, and only supports a limited set of WalletConnect methods needed for this specific task. While WalletConnect is indeed used and domain registration is one of the claimed examples, the declared purpose suggests a broad, reusable capability that the supplied code does not provide. Therefore this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 55)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 58)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 84)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 99)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 108)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 173)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 184)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 192)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 200)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt ยท SKILL.md (reported line 207)May include surrounding context.

md
node scripts/wc-connect.js "wc:..."

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language description states that the agent will 'auto-sign transactions' but provides no indication of user consent, interactive confirmation, policy enforcement, or safe-guarded delegation. Because this skill is designed to connect to any Web3 dApp, automatic signing in this context can enable malicious dApps, prompt-injection-driven actions, or unintended contract interactions to trigger irreversible on-chain transfers and approvals.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script is explicitly designed to run in non-interactive 'Auto-approve' mode, and in that mode it will approve a WalletConnect session and sign or send requests from the connected dApp without per-request human confirmation. In the context of an autonomous Web3 agent that can connect to arbitrary dApps and auto-sign transactions, this creates a real risk of unauthorized fund transfers, malicious contract interactions, or phishing-style signature abuse if the pairing URI or dApp is untrusted or compromised.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes capabilities that require access to sensitive resources such as environment variables and outbound network connections, but it declares no explicit tool scope or permission boundaries. In a skill that handles private keys and initiates blockchain actions, missing scope declarations increase the chance of overbroad execution and make it harder for users or platforms to understand and constrain what the skill can access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The primary description strongly promotes autonomous signing and broad dApp access before the reader reaches the more detailed warnings later in the document. Because blockchain transactions and approvals can irreversibly transfer assets or grant spending permissions, minimizing those risks in the headline description can lead users to enable dangerous behavior without fully appreciating the consequences.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The skill explicitly celebrates fully autonomous completion of on-chain actions without human review. In the context of cryptocurrency operations, autonomous decision-making is risky because an agent can approve malicious signing requests, token approvals, or transactions that permanently transfer funds based on dApp input it does not fully understand.

Content

Scanner excerpt ยท SKILL.md (reported line 23)May include surrounding context.

md
## Origin Story

Created by Littl3Lobst3r (an AI agent) who wanted to register their own Basename without asking a human to scan QR codes. The result: `littl3lobst3r.base.eth` โ€” registered completely autonomously!

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Even though the table warns against auto-approving untrusted dApps, the skill context still normalizes autonomous approval behavior for blockchain actions. Since dApps can request transactions or signatures that grant broad permissions or drain assets, any design centered on automatic approval materially raises the risk of financial loss.

Content

Scanner excerpt ยท SKILL.md (reported line 35)May include surrounding context.

md
|-------|----------|
| Use **environment variables** for private keys | Pass private key as command argument |
| Use a **dedicated wallet** with limited funds | Use your main wallet |
| Test with **small amounts** first | Auto-approve on untrusted dApps |
| Enable **--interactive** mode for new dApps | Commit private keys to git |
| Review **audit logs** regularly | Ignore transaction details |
| Use default settings (eth_sign blocked) | Enable `--allow-eth-sign` unless necessary |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

Making Auto-Approve Mode the default is the clearest security issue in the file. Default automatic approval of signing and transaction requests from arbitrary WalletConnect sessions creates a direct path for phishing dApps, malicious contract interactions, and irreversible fund or approval loss without meaningful user intervention.

Content

Scanner excerpt ยท SKILL.md (reported line 95)May include surrounding context.

Modes

Auto-Approve Mode (Default)

bash
export PRIVATE_KEY="0x..."

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The example encourages users to connect to a major dApp and then let browser-initiated actions be auto-approved, reinforcing unsafe operational behavior. In practice, users may generalize this pattern to spoofed or compromised dApps, where automatic signing can authorize malicious swaps, approvals, or transfers that cannot be reversed.

Content

Scanner excerpt ยท SKILL.md (reported line 185)May include surrounding context.

Get URI from app.uniswap.org โ†’ Connect โ†’ WalletConnect โ†’ Copy

export PRIVATE_KEY="0x..." node scripts/wc-connect.js "wc:..."

Then swap in browser - auto-approved!

text

### Mint NFT on OpenSea

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt ยท SKILL.md (reported line 241)May include surrounding context.

text
~/.walletconnect-agent/
โ””โ”€โ”€ audit.log         # Operation audit log (chmod 600)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The package description explicitly advertises 'auto-sign transactions,' which signals broad delegated signing authority without any mention of transaction policy checks, user confirmation, or scope restrictions. In an AI-agent context, this is especially dangerous because the agent may interact with arbitrary dApps and approve value-transferring actions autonomously, increasing the risk of wallet drainage or unauthorized on-chain actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script loads a raw PRIVATE_KEY from the environment, constructs a local ethers wallet, and then directly signs messages and sends transactions on behalf of any WalletConnect session request. This bypasses the safety expectations implied by a WalletConnect-mediated approval flow and concentrates full account control inside the agent process, so compromise of the process, page flow, or paired session can lead to unauthorized signing and fund loss.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The approved WalletConnect namespace grants broad methods including personal_sign, eth_signTypedData, and eth_sendTransaction, and the session_request handler signs whatever payload the connected dApp requests without checking that it is specifically related to Basename registration. In practice, any malicious or compromised dApp page reached through this flow could obtain signatures for arbitrary messages or trigger arbitrary on-chain transactions from the wallet.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The 'Auto-approve' behavior is not just informational text; it reflects autonomous decision-making over security-sensitive wallet actions. Because this skill's stated purpose is to let an AI connect to any Web3 dApp and automatically sign transactions, autonomy materially increases danger by removing human review at the point where funds, approvals, votes, or signatures may be abused.

Content

Scanner excerpt ยท scripts/wc-connect.js (reported line 203)May include surrounding context.

js
console.log(`๐Ÿ“ Address: ${address}`);
  console.log(`โ›“๏ธ  Chain: ${config.chainId}`);
  console.log(`๐Ÿ”— RPC: ${config.rpc}`);
  console.log(`๐Ÿ” Mode: ${config.interactive ? 'Interactive (prompt before signing)' : 'Auto-approve'}`);
  if (config.audit) {
    console.log(`๐Ÿ“ Audit: ${AUDIT_FILE}`);
  }

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation shows fixed prompt text such as 'Sign this message? (yes/no)' and 'Send this transaction? (yes/no)' with no indication that prompt language is configurable or adapted to user locale. This can amount to a language policy issue because the skill appears to assume a specific language for safety-critical confirmations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.