Back to skill

Security audit

Sui Agent Wallet

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Sui wallet integration, but it exposes seed phrase, signing, execution, and wallet administration capabilities through unauthenticated local APIs and a browser-wide extension surface.

Review carefully before installing. Do not use this skill with funded mainnet wallets unless the server is redesigned with strong local authentication, strict CORS/origin controls, explicit per-transaction approval, no HTTP mnemonic export, and scoped extension permissions. Treat any mnemonic exposed through the current /mnemonic endpoint or logs as compromised.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (8)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
server/index.ts:345
Finding

Cross-Origin Unauthenticated Mnemonic Disclosure

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
server/index.ts:306
Finding

Unauthenticated Raw Transaction Signing and Execution

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
server/index.ts:108
Finding

Unauthenticated Wallet Administration and Approval APIs

Content
View full analysis
!r.resolved) .map(r => ({ id: r.id, method: r.method, origin: r.origin, url: r.url, timestamp: r.timestamp, payload: r.payload })); return Response.json({ pending }, { headers: corsHeaders }); } // Approve request if (path.startsWith('/approve/') && req.method === 'POST') { const id = path.slice(9); const request = pendingRequests.get(id); // ... request.resolved = true; request.resolve?.(result); return Response.json({ success: true, result }, { headers: corsHeaders }); } // Switch account if (path === '/accounts/switch' && req.method === 'POST') { const body = await req.json() as { index: number }; const result = wallet.switchAccount(body.index); // ... } // Import from seed phrase if (path === '/import' && req.method === 'POST') { const body = await req.json() as { mnemonic: string }; const result = wallet.importMnemonic(body.mnemonic); return Response.json({ success: true, ...result }, { headers: corsHeaders }); } ``` ### Technical Analysis Wallet administration operations are exposed without authentication. Any client able to reach the service can enumerate pending requests and their complete payloads, approve or reject transactions, create or select accounts, change the active network, and overwrite the wallet mnemonic. The approval endpoint does not establish that the caller is the trusted agent or local user. Consequently, the presence of a nominal pending-request workflow does not create a meaningful security boundary. ### Attack Path **Approval bypass:** 1. A legitimate DApp cre ...[truncated 990 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
server/index.ts:421
Finding

Unauthenticated WebSocket Wallet Interface

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
extension/manifest.json:7
Finding

Extension Injects a Privileged Wallet Bridge into Every Site and Frame

Content
View full analysis
"], "content_scripts": [ { "matches": [""], "js": ["content.js"], "run_at": "document_start", "all_frames": true } ], "web_accessible_resources": [ { "resources": ["inject.js"], "matches": [""] } ] } ``` ### Technical Analysis The extension requests access to all URLs, injects its wallet bridge at document start into every page, and repeats the injection in every frame. This scope exceeds the minimum privileges needed for the documented localhost test DApp. The `storage` and `activeTab` permissions are declared but were not used in the reviewed extension source. Every visited website therefore receives access to the wallet request surface, increasing the likelihood and impact of abuse. ### Attack Path 1. The user installs the extension and visits any website. 2. The extension automatically injects `content.js` and the wallet provider into the page and its frames. 3. A malicious page script sends wallet requests through the injected bridge. 4. The requests are forwarded to the local wallet service. 5. The attacker can create deceptive requests or exploit weaknesses in the local service without the user explicitly enabling the wallet for that site. ### Impact Assessment The extension creates a browser-wide attack surface rather than limiting wallet access to explicitly approved DApps. Any website or embedded frame can initiate interactions with the wallet bridge. This amplifies the server-side authentication issues and violates least-privilege design. ]]>
Remediation
View remediation
` with narrowly scoped, explicitly approved DApp origins. - Prefer optional host permissions granted by the user per site. - Set `all_frames` to `false` unless frame support is demonstrably required. - Remove unused `storage` and `activeTab` permissions. - Require an explicit site-connection approval before exposing account information or signing features. - Restrict web-accessible resources to the same approved origins. - Provide users with a revocable origin allowlist. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
extension/content.js:16
Finding

Page-to-Wallet Bridge Forwards Unvalidated Methods and Payloads

Content
View full analysis
{ if (event.source !== window) return; if (event.data?.type !== 'SUI_AGENT_REQUEST') return; const { requestId, method, payload } = event.data; try { const response = await chrome.runtime.sendMessage({ type: 'SUI_AGENT_REQUEST', method, payload, origin: window.location.origin, url: window.location.href }); // ... } }); ``` ```js chrome.runtime.onMessage.addListener((message, sender, sendResponse) => { if (message.type !== 'SUI_AGENT_REQUEST') return false; const { method, payload, origin, url } = message; sendRequest(method, payload, { origin, url, tabId: sender.tab?.id }) .then(result => sendResponse({ result })) .catch(error => sendResponse({ error: error.message })); return true; }); ``` ### Technical Analysis The content and background scripts only validate the outer message type. They do not enforce an allowed set of wallet methods, validate the payload structure, limit payload size, or verify that the site has an approved wallet connection. Because the content script operates on all sites, any page script can construct a `SUI_AGENT_REQUEST`. The background service worker then forwards the attacker-controlled method and payload to the local privileged service. ### Attack Path 1. A malicious website posts a crafted `SUI_AGENT_REQUEST` to its own window. 2. The content script accepts the message because its source is the same window and its outer type matches. 3. The background script forwards the arbitrary method and payload. 4. The local service creates a pending request or handles a recognized method. 5. The attacker repeats this process with large or numerous payloads, or targets newly in ...[truncated 419 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
server/wallet.ts:98
Finding

Mnemonic Is Written to Standard Output When Keychain Storage Fails

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
server/package.json:8
Finding

Server Dependencies Are Not Reproducibly Locked

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (64)

Missing User Warnings

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The /sign-and-execute endpoint both signs and submits arbitrary transaction bytes without confirmation, making exploitation one-step and immediate. Any attacker able to reach the service can directly trigger asset transfers, contract calls, or other irreversible blockchain actions from the wallet.

Content

No source excerpt is available for this finding.

Missing User Warnings

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

Exposing the mnemonic through /mnemonic without confirmation or access control is a complete wallet compromise primitive. An attacker who retrieves the seed phrase can recreate the wallet independently, drain funds, and retain persistent access even after the local server is shut down.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This documentation explicitly tells users how to retrieve the wallet seed phrase from a local endpoint immediately after creation. Since the mnemonic is the root credential for the wallet, exposing it enables total compromise of all funds and accounts derived from it.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
🔐 NEW WALLET CREATED
═══════════════════════════════════════════════════════════

  Seed phrase stored securely in macOS Keychain.

  To view your seed phrase for backup:
    curl http://localhost:3847/mnemonic

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation advertises the mnemonic endpoint as a routine backup step without a prominent warning that this reveals the wallet's master secret in plaintext. That makes dangerous behavior appear safe and can lead users or agents to expose the phrase through shell history, logs, screenshots, or automation tooling.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Documenting direct plaintext access to the Keychain entry lowers the barrier to credential theft and encourages users to handle the seed phrase as ordinary retrievable data. While local keychain access may require OS permissions, normalizing extraction of the root secret still materially increases exposure risk.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
To view your seed phrase for backup:
    curl http://localhost:3847/mnemonic

  Or use macOS Keychain Access app:
    Service: sui-agent-wallet
    Account: mnemonic
═══════════════════════════════════════════════════════════

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The command shown retrieves the mnemonic directly from macOS Keychain in plaintext, providing a simple credential-access recipe for anyone with sufficient local access. In a wallet context, that means compromise of the single secret that controls all wallet accounts, making this especially dangerous.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Command line

security find-generic-password -s "sui-agent-wallet" -a "mnemonic" -w

Or open Keychain Access app

Search for "sui-agent-wallet"

text

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented API exposes the wallet mnemonic over an unauthenticated local HTTP endpoint, which is equivalent to handing out the private root credential for all derived accounts. Any local process, malicious browser extension, or webpage able to reach localhost could recover the seed phrase and permanently steal all current and future funds from this wallet.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file presents itself as a local control server, but it exposes highly sensitive wallet capabilities over unauthenticated HTTP with permissive CORS set to '*'. Any local webpage, browser extension, or process that can reach localhost can query wallet state, initiate signing flows, switch accounts/networks, import mnemonics, and in some cases directly obtain secrets or signatures, making the 'local only' framing materially misleading and dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The /sign-raw endpoint signs attacker-supplied transaction bytes immediately, with no user approval workflow, authentication, or trusted-origin check. This allows any local or cross-origin caller to obtain valid signatures from the wallet, which can then be broadcast elsewhere to move assets or authorize on-chain actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The comment claims mnemonic export is only for backup, but the GET /mnemonic endpoint returns the wallet seed phrase to any caller without authentication, approval, or origin restriction. Exposure of the mnemonic gives full irreversible control over all derived accounts and funds, far beyond ordinary transaction-signing risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The /import endpoint lets any caller replace wallet state by importing an arbitrary mnemonic, with no approval or authentication. This can redirect the agent to an attacker-controlled wallet, disrupt operations, or set up subsequent signing/exfiltration flows under attacker-chosen keys.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The code interpolates the raw mnemonic directly into a shell command passed to execSync. Because mnemonic text is attacker-controlled input in many threat models, shell metacharacters such as quotes, backticks, or command substitutions could break out of the intended argument and trigger arbitrary command execution, while also exposing the seed phrase via process arguments.

Content

Scanner excerpt · server/keychain.ts (reported line 25)May include surrounding context.

ts
`security add-generic-password -s "${SERVICE_NAME}" -a "${ACCOUNT_NAME}" -w "${mnemonic}"`,
      { stdio: 'pipe' }
    );
    console.log('✅ Seed phrase stored in macOS Keychain');
    return true;
  } catch (e: any) {
    console.error('Failed to store in Keychain:', e.message);

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/keychain.ts (reported line 2)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/keychain.ts (reported line 11)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/keychain.ts (reported line 28)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/keychain.ts (reported line 34)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/keychain.ts (reported line 49)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/keychain.ts (reported line 61)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/wallet.ts (reported line 2)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/wallet.ts (reported line 4)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/wallet.ts (reported line 70)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/wallet.ts (reported line 73)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/wallet.ts (reported line 80)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/wallet.ts (reported line 92)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · server/wallet.ts (reported line 289)May include surrounding context.

ts
/**
 * Sui Agent Wallet - Key Management with Keychain Support
 * 
 * Seed phrase is stored securely in macOS Keychain.
 * Only non-sensitive data (accounts, network) stored in wallet.json.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
server/keychain.ts:17