T09 · Insecure Skill Coding Practices
- Location
SKILL.md:21- Finding
Recovery Phrase Exposed Through Agent Chat
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 21-22
Vulnerability Type: Plaintext disclosure of wallet recovery credentials
Risk Level: HighVulnerable Code Snippet
markdown - remind the user that the mnemonic or seed phrase is sensitive and must be stored safely offline - if the user asks the agent to create the wallet, warn that the recovery phrase will be shown once in chat and must be backed up immediatelyThe same unsafe behavior is reinforced elsewhere in
SKILL.md, including lines 45 and 76-77.Technical Analysis
The skill explicitly permits a wallet recovery phrase to be displayed through the agent's chat interface during wallet creation. A mnemonic is a root authentication secret that can be used to reconstruct the wallet and authorize operations without any additional approval from the original user.
Warning that the phrase will be displayed only once does not provide adequate protection. Chat content may be retained in conversation history, application databases, telemetry, debugging records, model-provider logs, browser storage, screenshots, notification previews, or agent context. Consequently, the recovery phrase may persist in multiple systems outside the wallet's intended trust boundary.
This constitutes an insecure secret-handling design rather than a merely informational documentation issue: the skill directs the agent to transmit a high-value secret through a channel that cannot guarantee confidential display, non-retention, or suppression from logs.
Attack Path
- A user asks the agent to create an Engine miner wallet.
- The agent provides the required warning and invokes the wallet-creation workflow.
- The wallet tool returns the generated mnemonic to the agent.
- Following the skill instructions, the agent displays the mnemonic in chat.
- The mnemonic is retained in chat history, telemetry, logs, screenshots, browser data, or another system access ...[truncated 961 chars]
- Remediation
View remediation
Remediation Suggestions
- Never return or display a mnemonic through the AI agent, chat interface, tool response, or conversational context.
- Generate and display the recovery phrase only in a trusted local interface designed for secret presentation.
- Ensure the wallet-creation tool returns only nonsensitive information to the agent, such as a success result, wallet identifier, and public payout address.
- Mark mnemonic-bearing values as nonserializable and suppress them from application logs, telemetry, exception messages, and debugging output.
- Require explicit local confirmation that the phrase was backed up before completing wallet initialization.
- Prefer hardware-backed or operating-system-protected key storage where available.
- Update all repeated instructions that permit chat disclosure, including the wallet bootstrap, safety rules, and example response sections.
- Add automated tests verifying that wallet-creation tool responses and agent-visible output never contain mnemonic words or private-key material.
