Back to skill

Security audit

doginals

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Dogecoin inscription purpose, but its installer and wallet handling create high-impact risks that should be reviewed before installation.

Install only after reviewing or replacing install.sh with verified package-manager steps. Use a dedicated, minimally funded wallet, protect .wallet.json with strict permissions or encryption, verify Dogecoin Core downloads independently, and avoid running the bulk inscription script with untrusted or copied input.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:9
Finding

Privileged Execution of a Mutable Remote NodeSource Script

Content
View full analysis
/dev/null then echo "Node.js not found. Installing Node.js..." curl -fsSL https://deb.nodesource.com/setup_14.x | sudo -E bash - sudo apt-get install -y nodejs ``` ### Technical Analysis The installer downloads a mutable script from an external URL and pipes it directly into a root shell. The downloaded content is not pinned to a cryptographic digest, verified using a publisher signature, saved for review, or otherwise authenticated beyond HTTPS. Because the effective script can change after the Skill has been reviewed, this creates a remote code-execution channel. The behavior also exceeds minimum privilege requirements: installing Node.js may legitimately require package-manager privileges, but executing an arbitrary remote response as root is not necessary. ### Attack Path 1. A user runs `bash install.sh` on a system where Node.js is absent. 2. The installer requests the NodeSource setup script. 3. An attacker compromises the remote hosting account, delivery infrastructure, DNS/TLS trust chain, or upstream script. 4. The attacker returns a modified shell script. 5. `sudo -E bash -` executes the response immediately with root privileges. 6. The payload can modify the operating system, access local data, install persistence, or replace trusted executables. ### Impact Assessment Successful exploitation provides arbitrary root-level command execution and can result in complete host compromise. The attacker could read or alter wallet files, steal RPC credentials, replace system binaries, install persistent services, or manipulate future blockchain transactions. ]]>
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:18
Finding

Unverified Dogecoin Executables Are Installed System-Wide

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
.doginals-main/auto_inscriber_v4.py:19
Finding

Shell Command Injection in Bulk Inscription Automation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
.doginals-main/doginals.js:129
Finding

Wallet Private Keys Are Stored Unencrypted Without Enforced Owner-Only Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
install.sh:36
Finding

Non-Reproducible Dependency Installation Can Execute Unreviewed Lifecycle Code

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (49)

Tainted flow: 'mint_command' from input (line 22, user input) → subprocess.run (code execution)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

External input (network, user) flows to a code execution sink. This enables remote code execution or command injection.

Content

Scanner excerpt · .doginals-main/auto_inscriber_v4.py (reported line 23)May include surrounding context.

python
# Construct and run the first command
        mint_command = f"node . mint {doge_address} {image_path}"
        result_mint = subprocess.run(mint_command, shell=True, capture_output=True, text=True)
        print("Output from mint command:")
        print(result_mint.stdout)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .doginals-main/DoginalsREADME.md (reported line 242)May include surrounding context.

Make sure port is not set to the same number as rpcport. Also make sure rpcauth is not set.

Your .env file should look like:

text
NODE_RPC_URL=http://127.0.0.1:22555

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .doginals-main/DoginalsREADME.md (reported line 253)May include surrounding context.

Make sure port is not set to the same number as rpcport. Also make sure rpcauth is not set.

Your .env file should look like:

text
NODE_RPC_URL=http://127.0.0.1:22555

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .doginals-main/DunesREADME.md (reported line 185)May include surrounding context.

Make sure port is not set to the same number as rpcport. Also make sure rpcauth is not set.

Your .env file should look like:

text
NODE_RPC_URL=http://127.0.0.1:22555

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .doginals-main/DunesREADME.md (reported line 196)May include surrounding context.

Make sure port is not set to the same number as rpcport. Also make sure rpcauth is not set.

Your .env file should look like:

text
NODE_RPC_URL=http://127.0.0.1:22555

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · .doginals-main/auto_inscriber_v4.py (reported line 23)May include surrounding context.

python
# Construct and run the first command
        mint_command = f"node . mint {doge_address} {image_path}"
        result_mint = subprocess.run(mint_command, shell=True, capture_output=True, text=True)
        print("Output from mint command:")
        print(result_mint.stdout)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · .doginals-main/auto_inscriber_v4.py (reported line 48)May include surrounding context.

python
# Loop for the second command
            while True:
                wallet_sync_command = "node . wallet sync"
                result_sync = subprocess.run(wallet_sync_command, shell=True, capture_output=True, text=True)
                print("Output from wallet sync command:")
                print(result_sync.stdout)

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Concealed Executable Artifact

High
Category
Supply Chain
Confidence
100% confidence
Finding

An executable nested in a document or hidden/disguised artifact can evade ordinary extension-based review while still being available to the skill at runtime.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: lodash==4.17.23 — 2 advisory(ies): CVE-2025-13465 (lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and ); CVE-2021-23337 (lodash vulnerable to Code Injection via `_.template` imports key names)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: path-to-regexp==0.1.12 — 1 advisory(ies): CVE-2024-45296 (path-to-regexp vulnerable to Regular Expression Denial of Service via multiple r)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: picomatch==2.3.1 — 2 advisory(ies): CVE-2026-33672 (Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Mat); CVE-2026-33671 (Picomatch has a ReDoS vulnerability via extglob quantifiers)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script downloads a remote installer script with curl and pipes it directly into sudo bash, causing unauthenticated remote content to execute with elevated privileges. If the remote host, network path, or fetched script is compromised, this becomes immediate root-level arbitrary code execution.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The pipeline from curl into sudo creates a dangerous chaining pattern where network-delivered data is immediately treated as executable privileged shell input. This removes opportunities for validation or review and makes compromise of the source or transport path highly impactful.

Content

Scanner excerpt · install.sh (reported line 12)May include surrounding context.

sh
if ! command -v node &> /dev/null
then
    echo "Node.js not found. Installing Node.js..."
    curl -fsSL https://deb.nodesource.com/setup_14.x | sudo -E bash -
    sudo apt-get install -y nodejs
else
    echo "Node.js is already installed."

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · .doginals-main/auto_inscriber_v4.py (reported line 23)May include surrounding context.

python
# Construct and run the first command
        mint_command = f"node . mint {doge_address} {image_path}"
        result_mint = subprocess.run(mint_command, shell=True, capture_output=True, text=True)
        print("Output from mint command:")
        print(result_mint.stdout)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · .doginals-main/auto_inscriber_v4.py (reported line 48)May include surrounding context.

python
# Loop for the second command
            while True:
                wallet_sync_command = "node . wallet sync"
                result_sync = subprocess.run(wallet_sync_command, shell=True, capture_output=True, text=True)
                print("Output from wallet sync command:")
                print(result_sync.stdout)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

The use of sudo -E preserves the caller's environment while executing a remote script as root. Preserving environment variables can expand the attack surface by allowing unintended configuration injection into privileged execution, especially when combined with piped network content.

Content

Scanner excerpt · install.sh (reported line 12)May include surrounding context.

sh
if ! command -v node &> /dev/null
then
    echo "Node.js not found. Installing Node.js..."
    curl -fsSL https://deb.nodesource.com/setup_14.x | sudo -E bash -
    sudo apt-get install -y nodejs
else
    echo "Node.js is already installed."

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

The use of sudo -E preserves the caller's environment while executing a remote script as root. Preserving environment variables can expand the attack surface by allowing unintended configuration injection into privileged execution, especially when combined with piped network content.

Content

Scanner excerpt · install.sh (reported line 12)May include surrounding context.

sh
if ! command -v node &> /dev/null
then
    echo "Node.js not found. Installing Node.js..."
    curl -fsSL https://deb.nodesource.com/setup_14.x | sudo -E bash -
    sudo apt-get install -y nodejs
else
    echo "Node.js is already installed."

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 13)May include surrounding context.

sh
then
    echo "Node.js not found. Installing Node.js..."
    curl -fsSL https://deb.nodesource.com/setup_14.x | sudo -E bash -
    sudo apt-get install -y nodejs
else
    echo "Node.js is already installed."
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 23)May include surrounding context.

sh
then
    echo "Node.js not found. Installing Node.js..."
    curl -fsSL https://deb.nodesource.com/setup_14.x | sudo -E bash -
    sudo apt-get install -y nodejs
else
    echo "Node.js is already installed."
fi