T05 · Unauthorized Access and Privilege Escalation
- Location
server/index.ts:345- Finding
Cross-Origin Unauthenticated Mnemonic Disclosure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real Sui wallet integration, but it exposes seed phrase, signing, execution, and wallet administration capabilities through unauthenticated local APIs and a browser-wide extension surface.
Review carefully before installing. Do not use this skill with funded mainnet wallets unless the server is redesigned with strong local authentication, strict CORS/origin controls, explicit per-transaction approval, no HTTP mnemonic export, and scoped extension permissions. Treat any mnemonic exposed through the current /mnemonic endpoint or logs as compromised.
server/index.ts:345Cross-Origin Unauthenticated Mnemonic Disclosure
server/index.ts:306Unauthenticated Raw Transaction Signing and Execution
server/index.ts:108Unauthenticated Wallet Administration and Approval APIs
server/index.ts:421Unauthenticated WebSocket Wallet Interface
extension/manifest.json:7Extension Injects a Privileged Wallet Bridge into Every Site and Frame
extension/content.js:16Page-to-Wallet Bridge Forwards Unvalidated Methods and Payloads
server/wallet.ts:98Mnemonic Is Written to Standard Output When Keychain Storage Fails
server/package.json:8Server Dependencies Are Not Reproducibly Locked
The /sign-and-execute endpoint both signs and submits arbitrary transaction bytes without confirmation, making exploitation one-step and immediate. Any attacker able to reach the service can directly trigger asset transfers, contract calls, or other irreversible blockchain actions from the wallet.
Exposing the mnemonic through /mnemonic without confirmation or access control is a complete wallet compromise primitive. An attacker who retrieves the seed phrase can recreate the wallet independently, drain funds, and retain persistent access even after the local server is shut down.
This documentation explicitly tells users how to retrieve the wallet seed phrase from a local endpoint immediately after creation. Since the mnemonic is the root credential for the wallet, exposing it enables total compromise of all funds and accounts derived from it.
🔐 NEW WALLET CREATED
═══════════════════════════════════════════════════════════
Seed phrase stored securely in macOS Keychain.
To view your seed phrase for backup:
curl http://localhost:3847/mnemonic
The documentation advertises the mnemonic endpoint as a routine backup step without a prominent warning that this reveals the wallet's master secret in plaintext. That makes dangerous behavior appear safe and can lead users or agents to expose the phrase through shell history, logs, screenshots, or automation tooling.
Documenting direct plaintext access to the Keychain entry lowers the barrier to credential theft and encourages users to handle the seed phrase as ordinary retrievable data. While local keychain access may require OS permissions, normalizing extraction of the root secret still materially increases exposure risk.
To view your seed phrase for backup:
curl http://localhost:3847/mnemonic
Or use macOS Keychain Access app:
Service: sui-agent-wallet
Account: mnemonic
═══════════════════════════════════════════════════════════
The command shown retrieves the mnemonic directly from macOS Keychain in plaintext, providing a simple credential-access recipe for anyone with sufficient local access. In a wallet context, that means compromise of the single secret that controls all wallet accounts, making this especially dangerous.
security find-generic-password -s "sui-agent-wallet" -a "mnemonic" -w
The documented API exposes the wallet mnemonic over an unauthenticated local HTTP endpoint, which is equivalent to handing out the private root credential for all derived accounts. Any local process, malicious browser extension, or webpage able to reach localhost could recover the seed phrase and permanently steal all current and future funds from this wallet.
The file presents itself as a local control server, but it exposes highly sensitive wallet capabilities over unauthenticated HTTP with permissive CORS set to '*'. Any local webpage, browser extension, or process that can reach localhost can query wallet state, initiate signing flows, switch accounts/networks, import mnemonics, and in some cases directly obtain secrets or signatures, making the 'local only' framing materially misleading and dangerous.
The /sign-raw endpoint signs attacker-supplied transaction bytes immediately, with no user approval workflow, authentication, or trusted-origin check. This allows any local or cross-origin caller to obtain valid signatures from the wallet, which can then be broadcast elsewhere to move assets or authorize on-chain actions.
The comment claims mnemonic export is only for backup, but the GET /mnemonic endpoint returns the wallet seed phrase to any caller without authentication, approval, or origin restriction. Exposure of the mnemonic gives full irreversible control over all derived accounts and funds, far beyond ordinary transaction-signing risk.
The /import endpoint lets any caller replace wallet state by importing an arbitrary mnemonic, with no approval or authentication. This can redirect the agent to an attacker-controlled wallet, disrupt operations, or set up subsequent signing/exfiltration flows under attacker-chosen keys.
The code interpolates the raw mnemonic directly into a shell command passed to execSync. Because mnemonic text is attacker-controlled input in many threat models, shell metacharacters such as quotes, backticks, or command substitutions could break out of the intended argument and trigger arbitrary command execution, while also exposing the seed phrase via process arguments.
`security add-generic-password -s "${SERVICE_NAME}" -a "${ACCOUNT_NAME}" -w "${mnemonic}"`,
{ stdio: 'pipe' }
);
console.log('✅ Seed phrase stored in macOS Keychain');
return true;
} catch (e: any) {
console.error('Failed to store in Keychain:', e.message);
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* Sui Agent Wallet - Key Management with Keychain Support
*
* Seed phrase is stored securely in macOS Keychain.
* Only non-sensitive data (accounts, network) stored in wallet.json.
Detected: suspicious.dangerous_exec