Back to skill

Security audit

Cocod

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Cashu wallet helper, but it documents unsafe handling of wallet secrets and an unpinned global install for a security-critical CLI.

Review before installing. Use a pinned package version from an authoritative source, avoid elevated installs, and do not paste wallet mnemonics, passphrases, or transferable Cashu tokens into agent-visible commands. Prefer an interactive or otherwise protected secret-entry flow before using this skill with real funds.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Global Installation of a Security-Critical Third-Party Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:88
Finding

Wallet Mnemonics and Passphrases Are Accepted Through Process Arguments

Content
View full analysis
] [--mint-url ] # Unlock encrypted wallet (only required when initialised with passphrase) cocod unlock ``` The documented example reinforces this unsafe input method: ```bash **Initialize with encryption:** ```bash cocod init --passphrase "my-secret" ``` ``` ### Technical Analysis The documented interface places wallet mnemonics and encryption passphrases directly in the command-line argument vector. Command-line secrets may be exposed through: - Shell history files. - Process-list and process-inspection interfaces available to authorized local users or monitoring agents. - Terminal session recording. - Audit, telemetry, debugging, or command-execution logs. - Agent tool traces that preserve the exact command. - Error reports or support transcripts containing copied commands. A mnemonic is recovery material that can provide complete control over the associated wallet. A passphrase may permit an attacker who can access encrypted wallet state to unlock it. Quoting the passphrase only affects shell parsing; it does not prevent the value from appearing in process arguments or shell history. The skill's instruction not to expose `~/.cocod` is beneficial but does not address secrets disclosed through command invocation. ### Attack Path 1. A user or agent follows the documented syntax and supplies a mnemonic or passphrase as an argument. 2. The shell, agent framework, process-monitoring facility, or audit system records or exposes the complete command. 3. An attacker with access to the relevant history, logs, monitoring output, or process metadata retrieves the secret. 4. For a mnemonic, the attacker restores or reconstructs the wa ...[truncated 800 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.