T09 ยท Insecure Skill Coding Practices
- Location
scripts/wc-connect.js:240- Finding
WalletConnect Requests Are Automatically Approved and Executed Without Security Validation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill openly automates Web3 wallet signing, but its default behavior gives broad transaction authority to WalletConnect dApps without strong user confirmation or transaction validation.
Install only if you are comfortable giving an automated process control over a dedicated, low-value wallet. Use --interactive for any new dApp, avoid funded or primary wallets, verify WalletConnect URIs and dApp origins carefully, and treat typed-data signatures, token approvals, and transactions as irreversible even when eth_sign is blocked.
scripts/wc-connect.js:240WalletConnect Requests Are Automatically Approved and Executed Without Security Validation
scripts/register-basename.js:280Basename Registration Automation Accepts and Signs Arbitrary Session Requests
scripts/register-basename.js:164Browser Automation Explicitly Disables the Chromium Sandbox
package.json:7Unpinned and Incomplete Dependency Configuration Prevents Reproducible Trusted Installation
The description substantially overstates the skill's scope. The code is not a generic WalletConnect agent for arbitrary dApps; it is a purpose-built automation script for registering a Basename on Base. It hardcodes the target URL, chain, and registration flow, and only supports a limited set of WalletConnect methods needed for this specific task. While WalletConnect is indeed used and domain registration is one of the claimed examples, the declared purpose suggests a broad, reusable capability that the supplied code does not provide. Therefore this is a material description-behavior mismatch.
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
Referenced artifact was not completely inspected
node scripts/wc-connect.js "wc:..."
The natural-language description states that the agent will 'auto-sign transactions' but provides no indication of user consent, interactive confirmation, policy enforcement, or safe-guarded delegation. Because this skill is designed to connect to any Web3 dApp, automatic signing in this context can enable malicious dApps, prompt-injection-driven actions, or unintended contract interactions to trigger irreversible on-chain transfers and approvals.
The script is explicitly designed to run in non-interactive 'Auto-approve' mode, and in that mode it will approve a WalletConnect session and sign or send requests from the connected dApp without per-request human confirmation. In the context of an autonomous Web3 agent that can connect to arbitrary dApps and auto-sign transactions, this creates a real risk of unauthorized fund transfers, malicious contract interactions, or phishing-style signature abuse if the pairing URI or dApp is untrusted or compromised.
The skill describes capabilities that require access to sensitive resources such as environment variables and outbound network connections, but it declares no explicit tool scope or permission boundaries. In a skill that handles private keys and initiates blockchain actions, missing scope declarations increase the chance of overbroad execution and make it harder for users or platforms to understand and constrain what the skill can access.
The primary description strongly promotes autonomous signing and broad dApp access before the reader reaches the more detailed warnings later in the document. Because blockchain transactions and approvals can irreversibly transfer assets or grant spending permissions, minimizing those risks in the headline description can lead users to enable dangerous behavior without fully appreciating the consequences.
The skill explicitly celebrates fully autonomous completion of on-chain actions without human review. In the context of cryptocurrency operations, autonomous decision-making is risky because an agent can approve malicious signing requests, token approvals, or transactions that permanently transfer funds based on dApp input it does not fully understand.
## Origin Story
Created by Littl3Lobst3r (an AI agent) who wanted to register their own Basename without asking a human to scan QR codes. The result: `littl3lobst3r.base.eth` โ registered completely autonomously!
---
Even though the table warns against auto-approving untrusted dApps, the skill context still normalizes autonomous approval behavior for blockchain actions. Since dApps can request transactions or signatures that grant broad permissions or drain assets, any design centered on automatic approval materially raises the risk of financial loss.
|-------|----------|
| Use **environment variables** for private keys | Pass private key as command argument |
| Use a **dedicated wallet** with limited funds | Use your main wallet |
| Test with **small amounts** first | Auto-approve on untrusted dApps |
| Enable **--interactive** mode for new dApps | Commit private keys to git |
| Review **audit logs** regularly | Ignore transaction details |
| Use default settings (eth_sign blocked) | Enable `--allow-eth-sign` unless necessary |
Making Auto-Approve Mode the default is the clearest security issue in the file. Default automatic approval of signing and transaction requests from arbitrary WalletConnect sessions creates a direct path for phishing dApps, malicious contract interactions, and irreversible fund or approval loss without meaningful user intervention.
export PRIVATE_KEY="0x..."
The example encourages users to connect to a major dApp and then let browser-initiated actions be auto-approved, reinforcing unsafe operational behavior. In practice, users may generalize this pattern to spoofed or compromised dApps, where automatic signing can authorize malicious swaps, approvals, or transfers that cannot be reversed.
export PRIVATE_KEY="0x..." node scripts/wc-connect.js "wc:..."
### Mint NFT on OpenSea
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
~/.walletconnect-agent/
โโโ audit.log # Operation audit log (chmod 600)
The package description explicitly advertises 'auto-sign transactions,' which signals broad delegated signing authority without any mention of transaction policy checks, user confirmation, or scope restrictions. In an AI-agent context, this is especially dangerous because the agent may interact with arbitrary dApps and approve value-transferring actions autonomously, increasing the risk of wallet drainage or unauthorized on-chain actions.
The script loads a raw PRIVATE_KEY from the environment, constructs a local ethers wallet, and then directly signs messages and sends transactions on behalf of any WalletConnect session request. This bypasses the safety expectations implied by a WalletConnect-mediated approval flow and concentrates full account control inside the agent process, so compromise of the process, page flow, or paired session can lead to unauthorized signing and fund loss.
The approved WalletConnect namespace grants broad methods including personal_sign, eth_signTypedData, and eth_sendTransaction, and the session_request handler signs whatever payload the connected dApp requests without checking that it is specifically related to Basename registration. In practice, any malicious or compromised dApp page reached through this flow could obtain signatures for arbitrary messages or trigger arbitrary on-chain transactions from the wallet.
The 'Auto-approve' behavior is not just informational text; it reflects autonomous decision-making over security-sensitive wallet actions. Because this skill's stated purpose is to let an AI connect to any Web3 dApp and automatically sign transactions, autonomy materially increases danger by removing human review at the point where funds, approvals, votes, or signatures may be abused.
console.log(`๐ Address: ${address}`);
console.log(`โ๏ธ Chain: ${config.chainId}`);
console.log(`๐ RPC: ${config.rpc}`);
console.log(`๐ Mode: ${config.interactive ? 'Interactive (prompt before signing)' : 'Auto-approve'}`);
if (config.audit) {
console.log(`๐ Audit: ${AUDIT_FILE}`);
}
The documentation shows fixed prompt text such as 'Sign this message? (yes/no)' and 'Send this transaction? (yes/no)' with no indication that prompt language is configurable or adapted to user locale. This can amount to a language policy issue because the skill appears to assume a specific language for safety-critical confirmations.
No suspicious patterns detected.