T09 · Insecure Skill Coding Practices
- Location
scripts/api3-feed-manager.js:135- Finding
Private Key Exposed Through Command-Line Arguments
- Content
View full analysis
api3-feed-manager execute-buy-subscription \ --dapi-name ETH/USD \ --rpc-url https://arb1.arbitrum.io/rpc \ --chain arbitrum \ --execution-mode wrapper \ --private-key api3-feed-manager deploy-communal-proxy \ --dapi-name ETH/USD \ --rpc-url https://arb1.arbitrum.io/rpc \ --chain arbitrum \ --private-key ``` The value is parsed from the process argument list and used directly to construct a wallet: ```js async function executePreparedContractCall({ preparedContractCall, rpcUrl, privateKey, submit, acknowledgement, simulationFromAddress }) { // ... if (!rpcUrl || !privateKey) { executionSummary.failureReason = 'Execution requires rpcUrl and privateKey.'; return { executionSummary, transactionRequest: null, callResult: null }; } if (submit && acknowledgement !== SEND_ACKNOWLEDGEMENT) { executionSummary.failureReason = `Submitting requires acknowledgement=${SEND_ACKNOWLEDGEMENT}.`; return { executionSummary, transactionRequest: null, callResult: null }; } const provider = new JsonRpcProvider(rpcUrl); const wallet = new Wallet(privateKey, provider); const signerAddress = await wallet.getAddress(); executionSummary.signerAddress = signerAddress; ``` The proxy deployment path uses the same pattern: ```js if (!options.privateKey) { executionSummary.failureReason = 'Execution requires ...[truncated 2685 chars]- Remediation
View remediation
