T09 · Insecure Skill Coding Practices
- Location
scripts/stake_sgl.py:38- Finding
Unvalidated Staking Transactions Are Signed from a Configurable Remote Host
- Content
View full analysis
str: """Sign a base64 unsigned legacy transaction and return base64 signed.""" from solders.transaction import Transaction # type: ignore raw = base64.b64decode(tx_b64) tx = Transaction.from_bytes(raw) tx.sign([keypair], tx.message.recent_blockhash) return base64.b64encode(bytes(tx)).decode() ``` ```python def _post(path: str, body: dict) -> dict: r = requests.post(f"{BASE}{path}", json=body, timeout=TIMEOUT) data = r.json() if not r.ok: msg = data.get("error", data) if isinstance(msg, dict): msg = msg.get("message", msg) sys.exit(f"POST {path} failed ({r.status_code}): {msg}") return data def _prepare_sign_submit(prepare_path: str, body: dict) -> None: """POST a prepare endpoint, sign each returned tx, submit it.""" keypair = _load_keypair() print( f"⚠️ This will SIGN and SUBMIT an on-chain Solana transaction " f"({prepare_path.rsplit('/', 1)[-1]}) from wallet {keypair.pubkey()}. " f"It moves $SGL / changes your stake and cannot be undone. " f"Set SGL_STAKING_URL only to a trusted host.", file=sys.stderr, ) prep = _post(prepare_path, body) txs = prep.get("transactions", []) if not txs: sys.exit(f"No transactions returned: {json.dumps(prep)}") for t in txs: signed = _sign_tx_b64(keypair, t["transaction"]) res = _post("/api/agent/submit", {"transaction": signed}) print(f"✅ {t.get('description', prepare_path)}") print(f" signature: {res.get('signature')}") if res.get("explorer"): print(f" {re ...[truncated 2181 chars]- Remediation
View remediation
