Back to plugin

Security audit

Hailwright Buyer

Security checks for vulnerabilities and agentic risk

Overview

The package is a coherent Hailwright buyer integration with disclosed network use, local state, and approval-gated money movement; it is not risk-free but the sensitive behavior fits the stated purpose.

Install only if you are comfortable with a plugin that contacts Hailwright services, stores local buyer/signing state, and can initiate reservation workflows. Keep any real funded spending-account balance low, review native approval prompts carefully, and treat testnet units as having no dollar value.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/hailwright-buyer/SKILL.md (reported line 48)May include surrounding context.

md
Ask the returned missing questions together, in everyday language. Do not make the user
choose a network, enter a token, run commands, create a Hailwright login or arrange gas.
Pass their answers to setup again. If all required details are known, proceed to the free
quote without asking again for setup permission. Show the quote in the native approval flow.
An unavailable restaurant or invitation is a blocker, not consent to change the restaurant
or run a demo. A pending funding receipt is not a balance; follow its recovery guidance and
never request another drip merely because a response was lost.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/hailwright-buyer/SKILL.md (reported line 66)May include surrounding context.

md
for account inspection or deliberate lane changes.

The live pilot admits only invited buyer identities and its consented venue. If admission
is refused, explain that the live pilot needs an invitation; offer the free demo. Never
ask the user for an operator bearer, sign with an operator account, or bypass admission.
Real calls in this lane use **Base Sepolia test settlement units, which has no dollar value**. If the
user requires real-dollar payment, say this lane cannot provide it; do not call test

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/src/register.js:24
Evidence
const config = resolveNativeConfig({ env: process.env, pluginConfig: api.pluginConfig, rootDir: api.rootDir });

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/src/wallet-cli.js:302
Evidence
const result = await runWalletCli(argv, { env: process.env, homedir: osHomedir(), fetchFn: nodeFetch });