T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Blockchain Private Key Persisted in Agent Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed trading bot, but it asks for a wallet private key, stores it in agent memory, and can run unattended financial transactions.
Install only with a disposable, low-balance wallet. Do not paste a valuable private key into chat or allow it to be saved in agent memory. Prefer a dedicated signer or locked-down local secret store, disable cron until you have reviewed every transaction path, and require manual confirmation for buys, sells, approvals, and profit distributions.
SKILL.md:10Blockchain Private Key Persisted in Agent Memory
trading/check-pnl.js:146Automatic Liquidation Can Be Triggered by Unverified API Market Data
trading/sell-token.js:174Token Approval Granted to an Unvalidated Router
trading/package.json:16Unpinned Executable Skills and Package Dependencies
trading/buy-token.js:203Undefined Path Variables Break Entry-Price Tracking and Automated Trading
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Nad.fun Autonomous Trading Agent Configuration
# Copy this file to $HOME/nadfunagent/.env and fill in your values
# DO NOT commit .env to Git!
# MMIND Token Address (for profit distribution)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Nad.fun Autonomous Trading Agent Configuration
# Copy this file to $HOME/nadfunagent/.env and fill in your values
# DO NOT commit .env to Git!
# MMIND Token Address (for profit distribution)
The document instructs users to create a .env file containing a blockchain private key for a live trading agent. Storing plaintext credentials locally is not inherently malicious, but in this context it is sensitive and dangerous because compromise of the workstation, backups, logs, or adjacent tooling could expose the key and enable theft of funds.
Create .env file:
nano .env
Add the following (replace with your values):
The guide tells the user to provide sensitive configuration, including a private key, to the agent or to instruct it to use the .env file, and then states that configuration will be saved in OpenClaw memory for future use. Persisting wallet secrets in agent memory broadens the attack surface because other components, logs, memory dumps, or future prompt interactions may expose those credentials.
The agent will save configuration in OpenClaw memory for future use.
The troubleshooting command prints the contents of the .env file minus lines containing 'PRIVATE_KEY'. That still risks exposing other secrets such as Telegram bot tokens, RPC URLs with embedded credentials, or alternate secret names not matching the grep filter, and encourages users to display secret-bearing files in terminal history or shared sessions.
chmod 600 $HOME/nadfunagent/.env
cat $HOME/nadfunagent/.env | grep -v PRIVATE_KEY
### Issue: Rate limit errors (HTTP 429)
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
cd nadfunagent git remote add origin https://github.com/encipher88/nadfunagent.git git branch -M main git push -u origin main
If the GitHub repo already exists with a different history, you can force-push: `git push -u origin main --force` (this overwrites the remote history).
The skill advertises autonomous trading and profit distribution without an explicit warning that it can perform irreversible financial transactions. In this context, omission of clear risk disclosure makes unsafe use more likely and increases the chance users provide wallet credentials without understanding the consequences.
Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.
---
**CRITICAL COMMUNICATION RULES:**
1. **Language**: Always respond in the SAME language as the user's question. If in English, respond in English.
2. **Data Loading**: BEFORE executing any operations, FIRST request and load ALL required data from user or configuration files. Use OpenClaw's memory/session storage to save loaded data so you don't need to ask again.
3. **Telegram Integration**:
- Send detailed reports to Telegram after each trading cycle
The skill explicitly instructs the agent to persist highly sensitive secrets, including a private key, in memory/session storage for reuse. Persisting signing material in conversational or agent memory greatly expands the attack surface: other prompts, logs, memory leaks, or downstream integrations could expose credentials that control real funds.
The instructions tell the agent to collect a blockchain private key and related configuration from the user without a clear user-facing warning about credential sensitivity and theft risk. Because the same skill can execute trades and move funds, normalizing secret collection in chat significantly increases the likelihood of account compromise or misuse.
The skill repeatedly directs the agent to ask the user for a missing private key before proceeding. Soliciting wallet secrets in chat creates a direct path for unsafe credential handling, especially in a high-risk financial automation context where the key can immediately authorize trades and transfers.
This workflow explicitly tells the agent to obtain and use a private key from chat when the environment file is missing or incomplete. In context, that is dangerous because the same workflow proceeds toward automated market scanning, trading, selling, and profit distribution using the supplied key.
Referenced artifact was not completely inspected
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:
Referenced artifact was not completely inspected
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:
Referenced artifact was not completely inspected
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:
Referenced artifact was not completely inspected
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:
Referenced artifact was not completely inspected
**CRITICAL**: Always use the `check-pnl.js` script from `nadfun-trading` skill for proper P&L calculation. This script:
The cron example operationalizes unattended execution that depends on secrets loaded from .env and then performs trading actions on a schedule. In this financial context, automating credential-backed fund-moving actions without explicit approval gates or safer secret isolation increases the blast radius of misconfiguration, prompt mistakes, or system compromise.
# Via OpenClaw chat
"Start autonomous trading agent"
# Or via cron job (runs every minute). Paths: use NADFUN_ENV_PATH / NADFUNAGENT_DATA_DIR for .env and data; run scripts from nadfun-trading skill directory (clawhub install).
openclaw cron add \
--name "Nad.fun Trading Agent" \
--cron "* * * * *" \
This cron message embeds instructions to load wallet secrets and run automated trading and profit distribution. That makes credential use part of an unattended workflow capable of executing irreversible transactions, which is particularly dangerous if logs, job history, or misrouted prompts expose operational details or trigger unintended execution.
--name "Nad.fun Trading Agent"
--cron "* * * * *"
--session isolated
--message "Run autonomous trading cycle: 1) Load config from .env (path: NADFUN_ENV_PATH or NADFUNAGENT_DATA_DIR/.env; need MMIND_TOKEN_ADDRESS, MONAD_PRIVATE_KEY, MONAD_RPC_URL, MONAD_NETWORK). 2) From nadfun-trading skill directory run: node execute-bonding-v2.js (uses check-pnl.js for P&L from positions_report.json at POSITIONS_REPORT_PATH or NADFUNAGENT_DATA_DIR, auto-sells at +5% or -10%). 3) If there is positive PnL (profit >= 0.1 MON), distribute profits to MMIND token holders: use MMIND_TOKEN_ADDRESS from .env, get holders via indexer/Transfer events, distribute proportionally (e.g. 30%) in MON. Report output in English."
**Check agent status:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const os = require('os');
const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');
function loadEnv() {
const env = {};
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const os = require('os');
const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');
function loadEnv() {
const env = {};
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const os = require('os');
const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');
function loadEnv() {
const env = {};
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const os = require('os');
const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');
function loadEnv() {
const env = {};
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const os = require('os');
const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');
function loadEnv() {
const env = {};
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const os = require('os');
const DATA_DIR = process.env.NADFUNAGENT_DATA_DIR || path.join(os.homedir(), 'nadfunagent');
const ENV_PATH = process.env.NADFUN_ENV_PATH || path.join(DATA_DIR, '.env');
function loadEnv() {
const env = {};
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)