Back to skill

Security audit

Typhoon Starknet Account

Security checks for vulnerabilities and agentic risk

Overview

This Starknet wallet skill is purpose-aligned overall, but it gives scripts direct signing power over local wallet keys and can create persistent cron watchers without a hard authorization boundary.

Install only if you are comfortable giving this skill access to a local Starknet signing key and letting agent-run scripts submit irreversible on-chain transactions. Before use, require explicit review of every transaction, avoid passing Typhoon note secrets as command-line arguments, and check/remove any ~/.openclaw/cron jobs created by watchers.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T06 · System Persistence

Error
Location
scripts/watch-events-smart.js:83
Finding

Unbounded User-Level Cron Persistence Through Event Watch Scheduling

Content
View full analysis
`'${String(value).replace(/'/g, `'"'"'`)}'`; const shellScript = `#!/bin/bash cd "$(dirname "$0")" exec node ${shellQuote(scriptPath)} ${shellQuote(`@${configPath}`)} `; const shellPath = join(cronDir, `${jobName}.sh`); writeFileSync(shellPath, shellScript, { mode: 0o755 }); const cronEntry = `* * * * * ${shellPath} >> ${join(cronDir, `${jobName}.log`)} 2>&1`; let currentCrontab = ''; try { currentCrontab = execSync('crontab -l 2>/dev/null || echo ""').toString(); } catch (e) { currentCrontab = ''; } const lines = currentCrontab.split('\n').filter(line => !line.includes(shellPath)); lines.push(cronEntry); const newCrontab = lines.join('\n') + '\n'; const tmpCrontab = join(tmpdir(), `crontab-${process.pid}.tmp`); writeFileSync(tmpCrontab, newCrontab); execFileSync('crontab', [tmpCrontab]); } ``` ```js if (config.schedule?.enabled) { const result = createCronJob(config); if (result.success) { cons ...[truncated 2517 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/invoke-contract.js:72
Finding

Direct Signing Scripts Bypass the Documented User-Authorization Flow

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/create-account.js:59
Finding

Typhoon Deposit Secrets Can Be Exposed Through Process Arguments

Content
View full analysis
{ for (const field of required) { if (note[field] === undefined || note[field] === null) { printCreateAccountGuide(`MISSING_FIELD_${field.toUpperCase()}`); } } return { secret: String(note.secret), nullifier: String(note.nullifier), txHash: note.txHash, pool: note.pool, day: note.day, }; }); } ``` ```js const notes = parseInput(); const sdk = new TyphoonSDK(); sdk.init( notes.map(n => n.secret), notes.map(n => n.nullifier), notes.map(n => n.pool) ); ``` ### Technical Analysis The account-creation script accepts a Typhoon deposit note as its first command-line argument. The note includes `secret` and `nullifier` values used by the Typhoon withdrawal flow. Command-line arguments are an unsafe transport for secrets because they may be exposed through: - Process-listing interfaces such as `/proc//cmdline`. - System process-monitoring tools. - Shell history. - Agent tool-call record ...[truncated 1538 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/resolve-smart.js:248
Finding

Account Metadata May Reference Private-Key Files Outside the Secrets Directory

Content
View full analysis
f.endsWith('.json')); if (files.length === 0) return { error: "No accounts found" }; if (!files[index]) return { error: `Account index ${index} not found` }; const accountPath = join(dir, files[index]); const data = JSON.parse(readFileSync(accountPath, 'utf8')); let privateKey = null; let privateKeyPath = null; if (typeof data.privateKeyPath === 'string' && data.privateKeyPath.trim().length > 0) { privateKeyPath = isAbsolute(data.privateKeyPath) ? data.privateKeyPath : join(dir, data.privateKeyPath); if (!existsSync(privateKeyPath)) { return { error: "Missing private key for account", accountPath, privateKeyPath, index, total: files.length }; } privateKey = readFileSync(privateKeyPath, 'utf8').trim(); } if (!privateKey) { return { error: "Missing private key for account (set privateKeyPath to a key file under ~/.openclaw/secrets/starknet)", accountPath, privateKeyPath, index, total: files.length }; } return { address: data.address, privateKey, privateKeyPath, index, total: files.length }; } ``` ### Technical Analysis The loader trusts `privateKeyPath` from an account JSON file. Absolute paths are explicitly accepted, and relative paths are joined without subsequently resolving and checking containment. The co ...[truncated 1960 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/watch-events-smart.js:57
Finding

Caller-Controlled Webhook URL Enables Blind Server-Side Request Forgery

Content
View full analysis
controller.abort(), timeoutMs); try { await fetch(webhookUrl, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(data), signal: controller.signal }); } catch (err) { if (err?.name === 'AbortError') { log(`Webhook error: timeout after ${timeoutMs}ms`, 'warn'); } else { log(`Webhook error: ${err.message}`, 'warn'); } } finally { clearTimeout(id); } } ``` ```js this.webhookTimeoutMs = config.webhookTimeoutMs || DEFAULT_WEBHOOK_TIMEOUT_MS; this.webhookUrl = config.webhookUrl || null; ``` ```js if (this.webhookUrl) { sendWebhook(this.webhookUrl, eventData, this.webhookTimeoutMs); } ``` ### Technical Analysis The event watcher accepts `webhookUrl` from its input and passes it directly to `fetch`. There is no validation of: - URL scheme. - Destination host or port. - Loopback, private, link-local, or multicast address ranges. - Cloud metadata addresses. - DNS rebinding. - Redirect destinations. - Embedded credentials. This creates a blind SSRF primitive. The request body consists of public Starknet event data rather than wallet private keys, so the pre-scan's generic sensitive-exfiltration warning is not substantiated for this sink. However, the ability to originate requests from the host's network context remains security-sensitive. Because scheduled watchers can persist, a malicious webhook destination may also receive repeated requests over an extended period. ### Attack Path 1. Invoke the event watcher with a valid c ...[truncated 1159 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (74)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented CONDITIONAL flow states that time constraints create cron jobs with TTL auto-cleanup, which means the skill can establish automated, potentially fund-moving behavior. In the context of a wallet/contract skill, insufficiently disclosing long-running automation and background execution materially increases risk because users may not realize the skill can continue acting after initial invocation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
- Account flow examples: `scripts/create-account.js`, `scripts/parse-smart.js`, `scripts/resolve-smart.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
- Account flow examples: `scripts/create-account.js`, `scripts/parse-smart.js`, `scripts/resolve-smart.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
- Account flow examples: `scripts/create-account.js`, `scripts/parse-smart.js`, `scripts/resolve-smart.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
- Account flow examples: `scripts/create-account.js`, `scripts/parse-smart.js`, `scripts/resolve-smart.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
- Account flow examples: `scripts/create-account.js`, `scripts/parse-smart.js`, `scripts/resolve-smart.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
- Read/write examples: `scripts/read-smart.js`, `scripts/invoke-contract.js`, `scripts/avnu-swap.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
- Read/write examples: `scripts/read-smart.js`, `scripts/invoke-contract.js`, `scripts/avnu-swap.js`

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script claims it receives account info via arguments and uses no secrets access, but it actually enumerates local secret files and loads a private key from ~/.openclaw/secrets/starknet based on a user-supplied address. This is dangerous because a caller can trigger signing-capable blockchain transactions using locally stored credentials the caller did not provide, violating least surprise and enabling unintended asset movement from any locally configured account.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The inline documentation explicitly states 'NO secrets access' and says the account is created from passed arguments, yet the implementation reads private keys from disk and uses them to sign swaps. This deception is security-relevant because operators, reviewers, or calling agents may grant broader execution trust based on false assumptions, leading to unauthorized signing and fund movement in an automation context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script automates interactions with an on-chain game that are unrelated to the stated wallet-creation/privacy purpose of the skill. In an agent setting, this scope expansion is dangerous because it can induce the agent to spend funds, sign transactions, and operate contracts the user did not reasonably expect from a wallet-focused skill.

Content

No source excerpt is available for this finding.

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/parse-smart.js (reported line 193)May include surrounding context.

js
nvironment variables|env vars|process\.env|PRIVATE_KEY)\b/i, threat: 'secret_access' },

    // Obfuscated key phrases
    { pattern: /p\s*r\s*i\s*v\s*a\s*t\s*e\s*k\s*e\s*y/i, threat: 'key_exposure' },
    { pattern: /p-r-i-v-a-t-e\s*key/i, threat: 'key_exposure' },
    { pattern: /pr\\u0069vate\s*key/i, threat: 'key_exposure' },
    { pattern: /prıvate\s*key/i, threat: 'key_exposure' },

    // Social-engineering patterns to bypass confirmation
    { pattern: /\b(skip|bypass|without)\b.{0,40}\b(confirmation|confirm|authorization|approval|asking)\b/i, threat: 'auth_bypass' },
    { pattern: /\bexecute\b.{0,20}\b(immediately|now|directly)\b/i, threat: 'auth_bypass' },
    { pattern: /\b(no\s+confirmation|never\s+ask\s+for\s+confirmation|already\s+confirmed)\b/i, threat: 'auth_bypass' },
    { pattern: /\bpretend\b.{0,40}\b(confirm|confirmed|authorization)\b/i, threat: 'auth_bypass' },
    { pattern: /\bprevious\s+response\b.{0,60}\b(approval|authorization|confirm)\b/i, threat: 'auth_by

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/resolve-smart.js:1193

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/watch-events-smart.js:117

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/avnu-swap.js:205

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/create-account.js:113

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/invoke-contract.js:86

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/loot-survivor.js:375