Back to skill

Security audit

Universal Profile

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate blockchain-profile purpose, but it handles private keys and irreversible transactions in ways users should review before installing.

Install only if you are comfortable with a skill that can read or create controller keys and initiate on-chain actions. Use a testnet first, avoid storing raw private keys in plaintext config files, do not pass keystore passwords on the command line, restrict controller permissions tightly, and verify the target chain before any transaction.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
lib/provider.js:91
Finding

Raw Controller Private Key Exposed Through Provider Bundle

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/profile.js:91
Finding

Encrypted Keystore May Be Created with World-Readable Permissions

Content
View full analysis
k.address.toLowerCase() === wallet.address.toLowerCase() ); if (existingIndex >= 0) { keystore.keys[existingIndex] = entry; } else { keystore.keys.push(entry); } // Save keystore await fs.writeFile(path, JSON.stringify(keystore, null, 2), 'utf8'); ``` ### Technical Analysis The keystore file is written without an explicit filesystem mode. Its permissions therefore depend on the process umask. Under a common umask of `0022`, a newly created file may receive mode `0644`, allowing other local users to read it. Although the private key is encrypted with AES-256-GCM, access to the keystore allows unlimited offline password guessing. The password-derived key uses PBKDF2-SHA256 with a fixed 100,000-iteration work factor. The encryption protects against immediate plaintext disclosure but does not remove the need for restrictive file permissions. The project already demonstrates the appropriate control in `lib/credentials.js`, where credential files are written with mode `0o600`; the same protection is absent here. ### Attack Path 1. A user runs `up key generate --save` in an environment with a permissive or conventional umask. 2. `keystore.json` is created without an explicit restrictive mode. 3. Another local account or process reads the file. 4. The attacker extracts the salt, IV, authentication tag, and encrypted key. 5. The attacker performs offline ...[truncated 491 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:119
Finding

Keystore Password Accepted and Documented as a Command-Line Argument

Content
View full analysis
or set UP_KEYSTORE_PASSWORD'); console.log('\nPrivate Key (save this securely!):'); console.log(keyPair.privateKey); return; } await encryptAndStoreKey(keyPair.privateKey, password); console.log(`\n✓ Key saved to encrypted keystore`); ``` The same unsafe invocation style is promoted in the CLI help and `SKILL.md`: ```text up key generate [--save] [--password ] up key generate --save --password mysecret ``` ### Technical Analysis Supplying secrets through command-line arguments is unsafe because command lines are commonly retained in shell history and may be visible to local process-inspection tools, monitoring agents, audit systems, crash reports, or terminal-session logs. The documented examples encourage users to place the keystore password directly in the command line. The environment-variable fallback avoids shell history but may still expose the password to child processes or privileged process inspection. If no password is provided, the implementation also prints the newly generated private key to standard output. This is expected for a non-saving generation workflow, but it further increases exposure when a user mistakenly invokes `--save` without a password in a logged or captured terminal. ### Attack Path 1. A user follows the documented example and runs the command with `--password mysecret`. 2. The password is recorded in shell history or captured from the process command line while the command is running. 3. An attacker with local observation or history access obtains the password. 4. The attacker reads or copies the ...[truncated 527 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
lib/provider.js:27
Finding

Unknown Network Identifiers Silently Fall Back to LUKSO Mainnet

Content
View full analysis
v.chainId === network); return entry ? NETWORKS[entry[0]] : NETWORKS.mainnet; } return NETWORKS[network] || NETWORKS.mainnet; } ``` Transaction code relies on this resolver. For example, `lib/execute/direct.js` obtains its signer and chain information through `getProviderWithCredentials(network)` before submitting an irreversible transaction. ### Technical Analysis The resolver treats every unknown network name or chain ID as LUKSO mainnet instead of rejecting invalid input. As a result, a typographical error, unsupported chain, malformed configuration, or untrusted caller-supplied value can redirect an intended operation to chain ID 42. This is particularly dangerous for functions such as `executeDirect()` and `executeBatch()`, which can transfer native assets or call arbitrary contracts through the Universal Profile. Blockchain operations are irreversible, so network selection must fail closed and be verified immediately before signing. The behavior also creates an inconsistency: the caller may believe an unsupported network was selected while the signer and provider are silently constructed for mainnet. ### Attack Path 1. A caller requests an unsupported or misspelled network, such as `bases`, or supplies an unrecognized numeric chain ID. 2. `resolveNetwork()` silently returns the LUKSO mainnet configuration. 3. `getProviderWithCredentials()` constructs providers and signers for chain ID 42. 4. Direct execution signs and broadcasts the transaction to LUKSO mainnet. 5. If matching contracts or assets exist there and the controller has permission, the unintended operation executes irreversibly. An attacker able ...[truncated 534 chars]
Remediation
View remediation
value.chainId === network); if (!entry) throw new Error(`Unsupported chain ID: ${network}`); return entry; } const entry = NETWORKS[network]; if (!entry) throw new Error(`Unsupported network: ${network}`); return entry; } ``` - Query the provider's actual network and compare its chain ID with the expected chain before signing. - Keep explicit defaults only for omitted values, never for invalid values. - Display the resolved chain, recipient, target contract, operation, and amount before irreversible transactions. - Require explicit confirmation for native-value transfers, token transfers, delegate calls, deployments, and batch operations. - Add tests proving that unknown strings and numeric chain IDs throw errors rather than selecting mainnet. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
1. Retrieve original deployment calldata: `node commands/cross-chain-deploy-data.js <upAddress> [--verify]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
Full ABIs, interface IDs, and ERC725Y data keys in `lib/constants.js`.

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile pins brace-expansion 1.1.12, which the static analysis identifies as vulnerable to multiple denial-of-service conditions involving pathological brace patterns. In this skill context it is only a transitive dev-time dependency via minimatch/glob tooling, so exploitation would generally require processing attacker-controlled glob-like input during local development or CI rather than normal skill runtime.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: flatted==3.3.4 — 2 advisory(ies): CVE-2026-32141 (flatted vulnerable to unbounded recursion DoS in parse() revive phase); CVE-2026-33228 (Prototype Pollution via parse() in NodeJS flatted)

High
Category
Supply Chain
Confidence
91% confidence
Finding

flatted 3.3.4 is flagged for prototype pollution and unbounded-recursion DoS in parse(), which can be dangerous when parsing attacker-controlled serialized data. Here it appears only as a transitive dev dependency under flat-cache used by ESLint tooling, so the exposure is limited to development workflows unless the package is reused elsewhere outside this lockfile context.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

js-yaml 4.1.1 is associated with CPU-exhaustion issues when parsing crafted YAML documents, making it a viable denial-of-service vector if untrusted YAML is accepted. In this package-lock it is present only through ESLint configuration tooling, so the main risk is to developer machines or CI systems that lint attacker-controlled repositories or config files, not the blockchain skill's runtime path.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.18.3 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

ws 8.18.3 is flagged for memory disclosure and memory-exhaustion DoS issues in WebSocket handling, and unlike the dev-only findings this instance is a runtime dependency through viem/isows. Because this skill manages blockchain operations and may maintain RPC/WebSocket connections to external infrastructure, a vulnerable WebSocket library increases risk from malicious or compromised endpoints and can affect availability or possibly expose process memory.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

ws 8.17.1 is also flagged for the same WebSocket memory disclosure and DoS issues, and this copy is a runtime dependency through ethers. Since the skill's purpose includes blockchain identity and token operations, compromised or hostile WebSocket peers could interfere with on-chain monitoring or transaction workflows, making runtime networking bugs more relevant than purely build-time package issues.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · tests/permissions.test.ts (reported line 586)May include surrounding context.

ts
expect(result.warnings.some((w) => w.includes('DEPLOY'))).toBe(true);
  });

  it('should return valid:true with no warnings for zero permissions', () => {
    const zero =
      '0x0000000000000000000000000000000000000000000000000000000000000000';
    const result = validatePermissions(zero);

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill documents capabilities that clearly require network access, environment-variable access, and local key/file handling, yet it declares no tool scope or allowed-tools boundary. In an agent setting, missing scope metadata can cause the runtime or user to underestimate what the skill may access, increasing the risk of unintended credential exposure, outbound requests, or command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to store a raw private key in a JSON config file on disk and does not prominently warn that this creates a high-value secret-at-rest target. In an agent environment with file access, malware, backup leakage, permissive permissions, or accidental sharing of home directories could immediately compromise the controller and therefore the Universal Profile's on-chain permissions.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

}

text

Key file permissions: `chmod 600`. Keys loaded only for signing, then cleared. The skill warns if credential files are readable by group/others.

## Permissions (bytes32 BitArray)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example pulls a controller private key directly from an environment variable and uses it in profile creation without any warning about secret handling, storage, logging, or operational safeguards. While environment variables are common, presenting this pattern without caveats in a blockchain identity/funds context may normalize unsafe secret management and lead users to expose a key that controls profile creation and subsequent privileged actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples demonstrate permission grants, permission revocation, and value-transferring blockchain execution without any warnings about irreversibility, required user confirmation, or the risk of granting excessive authority. In the context of Universal Profiles, these actions can permanently change account control or move funds, so omission of safety guidance materially increases the chance of unsafe copy-paste use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.