Back to skill

Security audit

nadfunagent

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed trading bot, but it asks for a wallet private key, stores it in agent memory, and can run unattended financial transactions.

Install only with a disposable, low-balance wallet. Do not paste a valuable private key into chat or allow it to be saved in agent memory. Prefer a dedicated signer or locked-down local secret store, disable cron until you have reviewed every transaction path, and require manual confirmation for buys, sells, approvals, and profit distributions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:10
Finding

Blockchain Private Key Persisted in Agent Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trading/check-pnl.js:146
Finding

Automatic Liquidation Can Be Triggered by Unverified API Market Data

Content
View full analysis
0) { currentValueMON = price * balanceNum; } } catch { // skip } } ``` ```js const shouldSell = pnlPercent >= TAKE_PROFIT_PERCENT || pnlPercent <= STOP_LOSS_PERCENT; const reason = pnlPercent >= TAKE_PROFIT_PERCENT ? 'take profit' : pnlPercent <= STOP_LOSS_PERCENT ? 'stop loss' : null; if (shouldSell && autoSell && !dryRun) { console.log(` 🔄 Executing sell: ${reason}...`); try { const env = { ...process.env, NAD_PRIVATE_KEY: privateKey }; execSync( `node sell-token.js --token ${tokenAddress} --amount all --slippage 300`, { cwd: __dirname, env, stdio: 'inherit' } ); console.log(` ✅ Sold ${symbol}`); await new Promise(r => setTimeout(r, 3000)); } catch (e) { console.error(` ❌ Failed to sell ${symbol}:`, e.message || e); } } ``` ### Technical Analysis The script normally attempts to obtain an on-chain sell quote. If that operation fails, it accepts a price from the Nad.fun Agent API and uses it to calculate P&L. The calculated result can directly trigger an irreversible full-position sale when `--auto-sell` is enabled. The fallback API respo ...[truncated 1695 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trading/sell-token.js:174
Finding

Token Approval Granted to an Unvalidated Router

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
trading/package.json:16
Finding

Unpinned Executable Skills and Package Dependencies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
trading/buy-token.js:203
Finding

Undefined Path Variables Break Entry-Price Tracking and Automated Trading

Content
View full analysis
(p.address || '').toLowerCase() === tokenAddress.toLowerCase()); const position = existingIdx >= 0 ? report.positions[existingIdx] : { address: tokenAddress, symbol: tokenSymbol, name: '', balance: 0, balanceOnChain: 0, currentValueMON: entryValueMON, entryValueMON: entryValueMON, pnlPercent: 0, dataSource: 'buy_record', updatedAt: new Date().toISOString() }; position.entryValueMON = entryValueMON; position.currentValueMON = entryValueMON; position.pnlPercent = 0; position.symbol = tokenSymbol; position.updatedAt = new Date().toISOString(); if (existingIdx >= 0) report.positions[existingIdx] = position; else report.positions.push(position); report.timestamp = new Date().toISOString(); report.wallet = walletAddress; report.positionsCount = report.positions.length; const dir = require('path').dirname(reportPath); await fs.mkdir(dir, { recursive: true }).catch(() => {}); await fs.writeFile(rep ...[truncated 2912 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (78)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .env (reported line 2)May include surrounding context.

text
# Nad.fun Autonomous Trading Agent Configuration
# Copy this file to $HOME/nadfunagent/.env and fill in your values
# DO NOT commit .env to Git!

# MMIND Token Address (for profit distribution)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .env (reported line 3)May include surrounding context.

text
# Nad.fun Autonomous Trading Agent Configuration
# Copy this file to $HOME/nadfunagent/.env and fill in your values
# DO NOT commit .env to Git!

# MMIND Token Address (for profit distribution)

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The document instructs users to create a .env file containing a blockchain private key for a live trading agent. Storing plaintext credentials locally is not inherently malicious, but in this context it is sensitive and dangerous because compromise of the workstation, backups, logs, or adjacent tooling could expose the key and enable theft of funds.

Content

Scanner excerpt · INSTALL.md (reported line 99)May include surrounding context.

Create .env file:

bash
nano .env

Add the following (replace with your values):

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

The guide tells the user to provide sensitive configuration, including a private key, to the agent or to instruct it to use the .env file, and then states that configuration will be saved in OpenClaw memory for future use. Persisting wallet secrets in agent memory broadens the attack surface because other components, logs, memory dumps, or future prompt interactions may expose those credentials.

Content

Scanner excerpt · INSTALL.md (reported line 169)May include surrounding context.

- MONAD_NETWORK

- Telegram user ID (optional)

Provide values or say "use .env file"

text

The agent will save configuration in OpenClaw memory for future use.

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The troubleshooting command prints the contents of the .env file minus lines containing 'PRIVATE_KEY'. That still risks exposing other secrets such as Telegram bot tokens, RPC URLs with embedded credentials, or alternate secret names not matching the grep filter, and encourages users to display secret-bearing files in terminal history or shared sessions.

Content

Scanner excerpt · INSTALL.md (reported line 308)May include surrounding context.

chmod 600 $HOME/nadfunagent/.env

Verify file content (don't expose private key!)

cat $HOME/nadfunagent/.env | grep -v PRIVATE_KEY

text

### Issue: Rate limit errors (HTTP 429)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 217)May include surrounding context.

cd nadfunagent git remote add origin https://github.com/encipher88/nadfunagent.git git branch -M main git push -u origin main

text

If the GitHub repo already exists with a different history, you can force-push: `git push -u origin main --force` (this overwrites the remote history).

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises autonomous trading and profit distribution without an explicit warning that it can perform irreversible financial transactions. In this context, omission of clear risk disclosure makes unsafe use more likely and increases the chance users provide wallet credentials without understanding the consequences.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
---

**CRITICAL COMMUNICATION RULES:**
1. **Language**: Always respond in the SAME language as the user's question.  If in English, respond in English.
2. **Data Loading**: BEFORE executing any operations, FIRST request and load ALL required data from user or configuration files. Use OpenClaw's memory/session storage to save loaded data so you don't need to ask again.
3. **Telegram Integration**: 
   - Send detailed reports to Telegram after each trading cycle

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The skill explicitly instructs the agent to persist highly sensitive secrets, including a private key, in memory/session storage for reuse. Persisting signing material in conversational or agent memory greatly expands the attack surface: other prompts, logs, memory leaks, or downstream integrations could expose credentials that control real funds.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions tell the agent to collect a blockchain private key and related configuration from the user without a clear user-facing warning about credential sensitivity and theft risk. Because the same skill can execute trades and move funds, normalizing secret collection in chat significantly increases the likelihood of account compromise or misuse.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill repeatedly directs the agent to ask the user for a missing private key before proceeding. Soliciting wallet secrets in chat creates a direct path for unsafe credential handling, especially in a high-risk financial automation context where the key can immediately authorize trades and transfers.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This workflow explicitly tells the agent to obtain and use a private key from chat when the environment file is missing or incomplete. In context, that is dangerous because the same workflow proceeds toward automated market scanning, trading, selling, and profit distribution using the supplied key.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 732)May include surrounding context.

md
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 738)May include surrounding context.

md
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 797)May include surrounding context.

md
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 945)May include surrounding context.

md
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1051)May include surrounding context.

md
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

The cron example operationalizes unattended execution that depends on secrets loaded from .env and then performs trading actions on a schedule. In this financial context, automating credential-backed fund-moving actions without explicit approval gates or safer secret isolation increases the blast radius of misconfiguration, prompt mistakes, or system compromise.

Content

Scanner excerpt · SKILL.md (reported line 1097)May include surrounding context.

md
# Via OpenClaw chat
"Start autonomous trading agent"

# Or via cron job (runs every minute). Paths: use NADFUN_ENV_PATH / NADFUNAGENT_DATA_DIR for .env and data; run scripts from nadfun-trading skill directory (clawhub install).
openclaw cron add \
  --name "Nad.fun Trading Agent" \
  --cron "* * * * *" \

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

This cron message embeds instructions to load wallet secrets and run automated trading and profit distribution. That makes credential use part of an unattended workflow capable of executing irreversible transactions, which is particularly dangerous if logs, job history, or misrouted prompts expose operational details or trigger unintended execution.

Content

Scanner excerpt · SKILL.md (reported line 1102)May include surrounding context.

--name "Nad.fun Trading Agent"
--cron "* * * * *"
--session isolated
--message "Run autonomous trading cycle: 1) Load config from .env (path: NADFUN_ENV_PATH or NADFUNAGENT_DATA_DIR/.env; need MMIND_TOKEN_ADDRESS, MONAD_PRIVATE_KEY, MONAD_RPC_URL, MONAD_NETWORK). 2) From nadfun-trading skill directory run: node execute-bonding-v2.js (uses check-pnl.js for P&L from positions_report.json at POSITIONS_REPORT_PATH or NADFUNAGENT_DATA_DIR, auto-sells at +5% or -10%). 3) If there is positive PnL (profit >= 0.1 MON), distribute profits to MMIND token holders: use MMIND_TOKEN_ADDRESS from .env, get holders via indexer/Transfer events, distribute proportionally (e.g. 30%) in MON. Report output in English."

text

**Check agent status:**

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 964)May include surrounding context.

md
const os = require('os');

const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');

function loadEnv() {
  const env = {};

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check_positions.js (reported line 14)May include surrounding context.

js
const os = require('os');

const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');

function loadEnv() {
  const env = {};

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check_positions.js (reported line 41)May include surrounding context.

js
const os = require('os');

const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');

function loadEnv() {
  const env = {};

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · trading/check-pnl.js (reported line 66)May include surrounding context.

js
const os = require('os');

const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');

function loadEnv() {
  const env = {};

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · trading/execute-bonding-v2.js (reported line 15)May include surrounding context.

js
const os = require('os');

const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');

function loadEnv() {
  const env = {};

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · trading/fix-entry-prices.js (reported line 17)May include surrounding context.

js
const os = require('os');

const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');

function loadEnv() {
  const env = {};

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
trading/check-pnl.js:192

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
trading/sell-all.js:102

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/check_positions.js:13

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
trading/check-pnl.js:43

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
trading/execute-bonding-v2.js:15

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
trading/fix-entry-prices.js:17

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
trading/sell-all.js:20

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
trading/check-pnl.js:62

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
trading/execute-bonding-v2.js:71

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
trading/fix-entry-prices.js:33

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
trading/sell-all.js:42

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
trading/ENTRY_PRICE_TRACKING.md:69

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
trading/README.md:36