Back to skill

Security audit

Engine Miner Wallet

Security checks for vulnerabilities and agentic risk

Overview

This wallet guidance is mostly coherent, but it tells the agent to expose a wallet recovery phrase in chat and suggests a passphrase command pattern that can leak secrets.

Review this carefully before installing. It is not deceptive or broadly malicious, but use manual/local wallet creation where the recovery phrase is displayed only in a trusted local interface, do not put seed phrases or passphrases in chat, and avoid command-line passphrase arguments for real wallet secrets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:21
Finding

Recovery Phrase Exposed Through Agent Chat

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21-22
Vulnerability Type: Plaintext disclosure of wallet recovery credentials
Risk Level: High

Vulnerable Code Snippet

markdown
- remind the user that the mnemonic or seed phrase is sensitive and must be stored safely offline
- if the user asks the agent to create the wallet, warn that the recovery phrase will be shown once in chat and must be backed up immediately

The same unsafe behavior is reinforced elsewhere in SKILL.md, including lines 45 and 76-77.

Technical Analysis

The skill explicitly permits a wallet recovery phrase to be displayed through the agent's chat interface during wallet creation. A mnemonic is a root authentication secret that can be used to reconstruct the wallet and authorize operations without any additional approval from the original user.

Warning that the phrase will be displayed only once does not provide adequate protection. Chat content may be retained in conversation history, application databases, telemetry, debugging records, model-provider logs, browser storage, screenshots, notification previews, or agent context. Consequently, the recovery phrase may persist in multiple systems outside the wallet's intended trust boundary.

This constitutes an insecure secret-handling design rather than a merely informational documentation issue: the skill directs the agent to transmit a high-value secret through a channel that cannot guarantee confidential display, non-retention, or suppression from logs.

Attack Path

  1. A user asks the agent to create an Engine miner wallet.
  2. The agent provides the required warning and invokes the wallet-creation workflow.
  3. The wallet tool returns the generated mnemonic to the agent.
  4. Following the skill instructions, the agent displays the mnemonic in chat.
  5. The mnemonic is retained in chat history, telemetry, logs, screenshots, browser data, or another system access ...[truncated 961 chars]
Remediation
View remediation

Remediation Suggestions

  • Never return or display a mnemonic through the AI agent, chat interface, tool response, or conversational context.
  • Generate and display the recovery phrase only in a trusted local interface designed for secret presentation.
  • Ensure the wallet-creation tool returns only nonsensitive information to the agent, such as a success result, wallet identifier, and public payout address.
  • Mark mnemonic-bearing values as nonserializable and suppress them from application logs, telemetry, exception messages, and debugging output.
  • Require explicit local confirmation that the phrase was backed up before completing wallet initialization.
  • Prefer hardware-backed or operating-system-protected key storage where available.
  • Update all repeated instructions that permit chat disclosure, including the wallet bootstrap, safety rules, and example response sections.
  • Add automated tests verifying that wallet-creation tool responses and agent-visible output never contain mnemonic words or private-key material.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:47
Finding

Wallet Passphrase Passed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 47
Vulnerability Type: Sensitive credential exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code Snippet

markdown
- if the user wants a portable encrypted keystore, tell them to use `node ./admin.js init --passphrase "choose-a-strong-passphrase"`

Technical Analysis

The documented command encourages users to replace the example value with their actual wallet-keystore passphrase directly in a command-line argument. Command-line arguments are not an appropriate secret-input mechanism.

Depending on the operating system and execution environment, the passphrase may be exposed through shell history, process listings, process-monitoring utilities, terminal session recording, command auditing, diagnostic collection, or automation logs. Other local users or monitoring services may be able to inspect process arguments while the command is running. The command may also be copied into chat or support records because it is presented as the recommended initialization procedure.

Encryption of the keystore does not adequately protect it if the encryption passphrase is disclosed through the initialization command.

Attack Path

  1. A user follows the documented initialization procedure.
  2. The user replaces choose-a-strong-passphrase with a real keystore passphrase.
  3. The shell records the complete command in its history, or the operating system exposes it through process inspection or audit logs.
  4. An attacker with access to the same account, host telemetry, terminal records, shell-history file, or process-monitoring data obtains the passphrase.
  5. The attacker separately obtains or accesses the portable encrypted keystore.
  6. The attacker uses the disclosed passphrase to decrypt or unlock the keystore.
  7. The attacker gains access to the wallet keys and can perform operations available to those keys.

Im

...[truncated 626 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the --passphrase command-line argument from the documented workflow.
  • Read the passphrase using a hidden interactive prompt that disables terminal echo.
  • Request the passphrase twice locally to detect input mistakes without exposing it to the agent.
  • For noninteractive execution, use a protected secret manager, dedicated file descriptor, or narrowly permissioned secret file rather than a command-line argument.
  • Ensure the passphrase is never included in environment diagnostics, logs, exception messages, telemetry, shell history, or chat.
  • Clear temporary passphrase buffers as soon as practical after key derivation.
  • Apply restrictive filesystem permissions to the encrypted keystore and keep it outside shared or publicly readable directories.
  • Document that users must enter the passphrase only through the trusted local interface and must never paste it into OpenClaw chat.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
- never ask for or reveal the mnemonic in normal operation
- only reveal the recovery phrase during explicit wallet-creation flow after warning the user that it will appear in chat once
- never ask the user to paste the mnemonic or seed phrase into chat after wallet creation
- never ask the user to paste the wallet passphrase into chat; tell them to set it locally instead
- never describe the wallet as a treasury wallet
- only broadcast claims after explicit user confirmation

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
- never ask for or reveal the mnemonic in normal operation
- only reveal the recovery phrase during explicit wallet-creation flow after warning the user that it will appear in chat once
- never ask the user to paste the mnemonic or seed phrase into chat after wallet creation
- never ask the user to paste the wallet passphrase into chat; tell them to set it locally instead
- never describe the wallet as a treasury wallet
- only broadcast claims after explicit user confirmation

Static analysis

No suspicious patterns detected.