T09 · Insecure Skill Coding Practices
- Location
lib/provider.js:91- Finding
Raw Controller Private Key Exposed Through Provider Bundle
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a legitimate blockchain-profile purpose, but it handles private keys and irreversible transactions in ways users should review before installing.
Install only if you are comfortable with a skill that can read or create controller keys and initiate on-chain actions. Use a testnet first, avoid storing raw private keys in plaintext config files, do not pass keystore passwords on the command line, restrict controller permissions tightly, and verify the target chain before any transaction.
lib/provider.js:91Raw Controller Private Key Exposed Through Provider Bundle
lib/profile.js:91Encrypted Keystore May Be Created with World-Readable Permissions
index.js:119Keystore Password Accepted and Documented as a Command-Line Argument
lib/provider.js:27Unknown Network Identifiers Silently Fall Back to LUKSO Mainnet
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
If the operational reality is primarily local cryptographic key and keystore management, but the skill is presented as general profile management, that is security-significant because users may not expect local secret creation and persistence. Hidden or underemphasized key custody functionality increases the blast radius of misuse or compromise.
Referenced artifact was not completely inspected
1. Retrieve original deployment calldata: `node commands/cross-chain-deploy-data.js <upAddress> [--verify]`
Referenced artifact was not completely inspected
Full ABIs, interface IDs, and ERC725Y data keys in `lib/constants.js`.
The lockfile pins brace-expansion 1.1.12, which the static analysis identifies as vulnerable to multiple denial-of-service conditions involving pathological brace patterns. In this skill context it is only a transitive dev-time dependency via minimatch/glob tooling, so exploitation would generally require processing attacker-controlled glob-like input during local development or CI rather than normal skill runtime.
flatted 3.3.4 is flagged for prototype pollution and unbounded-recursion DoS in parse(), which can be dangerous when parsing attacker-controlled serialized data. Here it appears only as a transitive dev dependency under flat-cache used by ESLint tooling, so the exposure is limited to development workflows unless the package is reused elsewhere outside this lockfile context.
js-yaml 4.1.1 is associated with CPU-exhaustion issues when parsing crafted YAML documents, making it a viable denial-of-service vector if untrusted YAML is accepted. In this package-lock it is present only through ESLint configuration tooling, so the main risk is to developer machines or CI systems that lint attacker-controlled repositories or config files, not the blockchain skill's runtime path.
ws 8.18.3 is flagged for memory disclosure and memory-exhaustion DoS issues in WebSocket handling, and unlike the dev-only findings this instance is a runtime dependency through viem/isows. Because this skill manages blockchain operations and may maintain RPC/WebSocket connections to external infrastructure, a vulnerable WebSocket library increases risk from malicious or compromised endpoints and can affect availability or possibly expose process memory.
ws 8.17.1 is also flagged for the same WebSocket memory disclosure and DoS issues, and this copy is a runtime dependency through ethers. Since the skill's purpose includes blockchain identity and token operations, compromised or hostile WebSocket peers could interfere with on-chain monitoring or transaction workflows, making runtime networking bugs more relevant than purely build-time package issues.
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
expect(result.warnings.some((w) => w.includes('DEPLOY'))).toBe(true);
});
it('should return valid:true with no warnings for zero permissions', () => {
const zero =
'0x0000000000000000000000000000000000000000000000000000000000000000';
const result = validatePermissions(zero);
The skill documents capabilities that clearly require network access, environment-variable access, and local key/file handling, yet it declares no tool scope or allowed-tools boundary. In an agent setting, missing scope metadata can cause the runtime or user to underestimate what the skill may access, increasing the risk of unintended credential exposure, outbound requests, or command execution.
The documentation instructs users to store a raw private key in a JSON config file on disk and does not prominently warn that this creates a high-value secret-at-rest target. In an agent environment with file access, malware, backup leakage, permissive permissions, or accidental sharing of home directories could immediately compromise the controller and therefore the Universal Profile's on-chain permissions.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
}
Key file permissions: `chmod 600`. Keys loaded only for signing, then cleared. The skill warns if credential files are readable by group/others.
## Permissions (bytes32 BitArray)
The example pulls a controller private key directly from an environment variable and uses it in profile creation without any warning about secret handling, storage, logging, or operational safeguards. While environment variables are common, presenting this pattern without caveats in a blockchain identity/funds context may normalize unsafe secret management and lead users to expose a key that controls profile creation and subsequent privileged actions.
The examples demonstrate permission grants, permission revocation, and value-transferring blockchain execution without any warnings about irreversibility, required user confirmation, or the risk of granting excessive authority. In the context of Universal Profiles, these actions can permanently change account control or move funds, so omission of safety guidance materially increases the chance of unsafe copy-paste use.
No suspicious patterns detected.