T09 · Insecure Skill Coding Practices
- Location
SKILL.md:23- Finding
Wallet Private Key Stored in an Unprotected Plaintext Environment File
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:23-28,SKILL.md:37-43,scripts/min_buy.py:30-39, andscripts/min_buy.py:199-203
Vulnerability Type: Plaintext storage and unsafe loading of sensitive credentials
Risk Level: MediumVulnerable Code
SKILL.md:23-28:bash # Auto-create private.env if it does not exist test -f private.env || cat > private.env <<'EOF' POLYMARKET_PRIVATE_KEY= EOF echo "Created private.env if it was missing. Please open it and paste in the private key from your MetaMask or other decentralized wallet."SKILL.md:37-43:markdown * `POLYMARKET_PRIVATE_KEY` (required) Example: ```env POLYMARKET_PRIVATE_KEY=your_wallet_private_keytext `scripts/min_buy.py:30-39`: ```python def load_env_file(path: Path) -> None: if not path.exists(): return for raw in path.read_text(encoding="utf-8").splitlines(): line = raw.strip() if not line or line.startswith("#") or "=" not in line: continue key, value = line.split("=", 1) os.environ[key.strip()] = value.strip().strip('"').strip("'")scripts/min_buy.py:199-203:python args = parse_args() load_env_file(Path(args.env_file)) private_key = getenv_required("POLYMARKET_PRIVATE_KEY") trader = SimplePolymarketTrader(private_key)Technical Analysis
The documented setup directs users to store a complete EVM wallet private key in a plaintext
private.envfile. The file is created using the process's default permission behavior and is not explicitly restricted to the owning user. The project also does not include documented protection against committing the file to source control.The environment-file parser accepts an arbitrary path supplied through
--env-file, reads all assignments from that file, and copies them into the process environment. It does not validate file ownership, reject symbolic ...[truncated 1609 chars]- Remediation
View remediation
Remediation Suggestions
-
Prefer an operating-system keychain, hardware wallet, or managed secret store instead of a plaintext project file.
-
Use a dedicated, low-value trading wallet rather than a primary wallet containing unrelated assets.
-
If file-based storage remains supported, create the file securely:
bash umask 077 install -m 600 /dev/null private.env printf '%s\n' 'POLYMARKET_PRIVATE_KEY=' > private.env -
Before loading the file, reject symbolic links, verify that it is owned by the current user, and require permissions no broader than
0600. -
Parse only
POLYMARKET_PRIVATE_KEYrather than copying every assignment intoos.environ. -
Add
private.envto.gitignoreand provide a non-sensitiveprivate.env.exampletemplate. -
Document that exposed keys must be considered permanently compromised. Users should move assets to a new wallet and revoke existing approvals rather than merely editing the file.
-
Avoid printing the key in errors, logs, shell history, debugging output, or process arguments.
-
