Back to skill

Security audit

Inflynce Campaign

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it advertises, but it needs review because its helper scripts can accept a full wallet private key on the command line and broadcast real Base mainnet transactions.

Review this skill before installing. Prefer using the Inflynce web UI or an external wallet for payments and top-ups, and do not pass a real wallet private key with `--private-key`; use a dedicated low-balance wallet if programmatic signing is unavoidable. Also review dependency updates because the lockfile includes a flagged transitive ws version.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/pay_fee.js:21
Finding

Wallet Private Key Exposure Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Known Vulnerable Dependency: ws==8.18.3 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
98% confidence
Finding

The lockfile pins a known vulnerable version of the ws WebSocket library (8.18.3) with reported issues including uninitialized memory disclosure and memory-exhaustion denial of service. Because this dependency is pulled in by viem, any skill functionality that opens or accepts WebSocket connections could expose sensitive process memory or allow an attacker to degrade availability via crafted fragmented frames.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"type": "module",
  "scripts": {
    "test": "node --test test/",
    "prepare:publish": "rm -rf .clawhub-publish clawhub-publish && rsync -av --exclude=node_modules --exclude=.git --exclude=.env --exclude='*.map' --exclude=LICENSE --exclude=.clawhub-publish --exclude=clawhub-publish ./ .clawhub-publish/"
  },
  "dependencies": {
    "ethereum-cryptography": "^2.0.0",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test/create_campaign.test.js (reported line 36)May include surrounding context.

js
"type": "module",
  "scripts": {
    "test": "node --test test/",
    "prepare:publish": "rm -rf .clawhub-publish clawhub-publish && rsync -av --exclude=node_modules --exclude=.git --exclude=.env --exclude='*.map' --exclude=LICENSE --exclude=.clawhub-publish --exclude=clawhub-publish ./ .clawhub-publish/"
  },
  "dependencies": {
    "ethereum-cryptography": "^2.0.0",

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description claims the skill can create campaigns for "any URL," which is an overly broad scope for an agent action that can interact with external resources. In agent ecosystems, broad trigger language increases the chance the skill will be invoked on untrusted, malicious, or irrelevant targets, expanding abuse opportunities and making downstream URL validation more critical.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script allows a private key to be passed via the command line (--private-key), which is commonly exposed through shell history, process listings, audit logs, and CI job output. Because this script performs a blockchain transfer, disclosure of the key could let an attacker fully control the associated wallet, making the issue materially dangerous despite the small stated fee amount.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script explicitly accepts a raw wallet private key via the command line (--private-key), which is commonly exposed through shell history, process listings, audit logs, and CI/job telemetry. Because this key authorizes on-chain transactions for the user's wallet, accidental disclosure can lead to wallet compromise and unauthorized asset movement well beyond this single approve call.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
83% confidence
Finding

Using a caret range for ethereum-cryptography allows automatic adoption of future minor and patch releases, which can introduce supply-chain risk if an upstream package is compromised or contains a breaking security regression. While this package is common and the immediate risk in package.json alone is limited, agent skills are part of an execution pipeline where dependency integrity matters.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"prepare:publish": "rm -rf .clawhub-publish clawhub-publish && rsync -av --exclude=node_modules --exclude=.git --exclude=.env --exclude='*.map' --exclude=LICENSE --exclude=.clawhub-publish --exclude=clawhub-publish ./ .clawhub-publish/"
  },
  "dependencies": {
    "ethereum-cryptography": "^2.0.0",
    "viem": "^2.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
83% confidence
Finding

Using a caret range for viem permits non-exact dependency resolution, increasing exposure to supply-chain compromise or unexpected behavior changes from upstream releases. In a skill that may handle blockchain-related operations, unreviewed dependency drift can affect transaction logic, signing flows, or data handling.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
},
  "dependencies": {
    "ethereum-cryptography": "^2.0.0",
    "viem": "^2.0.0"
  }
}

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/create_campaign.test.js:16

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/create_campaign.js:73

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/pay_fee.js:36

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/top_up.js:36