T09 · Insecure Skill Coding Practices
- Location
scripts/pay_fee.js:21- Finding
Wallet Private Key Exposure Through Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to do what it advertises, but it needs review because its helper scripts can accept a full wallet private key on the command line and broadcast real Base mainnet transactions.
Review this skill before installing. Prefer using the Inflynce web UI or an external wallet for payments and top-ups, and do not pass a real wallet private key with `--private-key`; use a dedicated low-balance wallet if programmatic signing is unavoidable. Also review dependency updates because the lockfile includes a flagged transitive ws version.
scripts/pay_fee.js:21Wallet Private Key Exposure Through Command-Line Arguments
The lockfile pins a known vulnerable version of the ws WebSocket library (8.18.3) with reported issues including uninitialized memory disclosure and memory-exhaustion denial of service. Because this dependency is pulled in by viem, any skill functionality that opens or accepts WebSocket connections could expose sensitive process memory or allow an attacker to degrade availability via crafted fragmented frames.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "module",
"scripts": {
"test": "node --test test/",
"prepare:publish": "rm -rf .clawhub-publish clawhub-publish && rsync -av --exclude=node_modules --exclude=.git --exclude=.env --exclude='*.map' --exclude=LICENSE --exclude=.clawhub-publish --exclude=clawhub-publish ./ .clawhub-publish/"
},
"dependencies": {
"ethereum-cryptography": "^2.0.0",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"type": "module",
"scripts": {
"test": "node --test test/",
"prepare:publish": "rm -rf .clawhub-publish clawhub-publish && rsync -av --exclude=node_modules --exclude=.git --exclude=.env --exclude='*.map' --exclude=LICENSE --exclude=.clawhub-publish --exclude=clawhub-publish ./ .clawhub-publish/"
},
"dependencies": {
"ethereum-cryptography": "^2.0.0",
The description claims the skill can create campaigns for "any URL," which is an overly broad scope for an agent action that can interact with external resources. In agent ecosystems, broad trigger language increases the chance the skill will be invoked on untrusted, malicious, or irrelevant targets, expanding abuse opportunities and making downstream URL validation more critical.
The script allows a private key to be passed via the command line (--private-key), which is commonly exposed through shell history, process listings, audit logs, and CI job output. Because this script performs a blockchain transfer, disclosure of the key could let an attacker fully control the associated wallet, making the issue materially dangerous despite the small stated fee amount.
The script explicitly accepts a raw wallet private key via the command line (--private-key), which is commonly exposed through shell history, process listings, audit logs, and CI/job telemetry. Because this key authorizes on-chain transactions for the user's wallet, accidental disclosure can lead to wallet compromise and unauthorized asset movement well beyond this single approve call.
Using a caret range for ethereum-cryptography allows automatic adoption of future minor and patch releases, which can introduce supply-chain risk if an upstream package is compromised or contains a breaking security regression. While this package is common and the immediate risk in package.json alone is limited, agent skills are part of an execution pipeline where dependency integrity matters.
"prepare:publish": "rm -rf .clawhub-publish clawhub-publish && rsync -av --exclude=node_modules --exclude=.git --exclude=.env --exclude='*.map' --exclude=LICENSE --exclude=.clawhub-publish --exclude=clawhub-publish ./ .clawhub-publish/"
},
"dependencies": {
"ethereum-cryptography": "^2.0.0",
"viem": "^2.0.0"
}
}
Using a caret range for viem permits non-exact dependency resolution, increasing exposure to supply-chain compromise or unexpected behavior changes from upstream releases. In a skill that may handle blockchain-related operations, unreviewed dependency drift can affect transaction logic, signing flows, or data handling.
},
"dependencies": {
"ethereum-cryptography": "^2.0.0",
"viem": "^2.0.0"
}
}
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal