T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned External Package Executes with Access to an Operator Private Key
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed AI DeFi execution skill, but it runs unpinned npm code with a private key and has conflicting/high-risk transaction guidance that users should review before installing.
Review this as a financial signing tool, not a normal chat helper. Use only a fresh operator wallet with minimal gas, do not reuse any main wallet key, pin and verify the npm package before execution, avoid unpinned npx MCP setup, and require explicit confirmation for raw calldata, transfers, and any config change.
SKILL.md:9Unpinned External Package Executes with Access to an Operator Private Key
SKILL.md:225Contradictory Config Classification Can Bypass Write Confirmation
The documentation states that a compromised operator key cannot withdraw vault funds, yet the documented transfer command allows sending BNB or ERC20 from the vault. That contradiction can mislead users into underestimating key compromise risk; if transfers are policy-permitted, an attacker controlling the operator could move assets to approved recipients or otherwise drain value within configured limits.
Allowing raw calldata execution gives the agent a near-generic transaction primitive, which undermines the safety benefits of constrained DeFi tools. Even if PolicyGuard exists, exposing arbitrary calldata from "any source" creates a powerful path for prompt-injection-driven transactions, unsafe contract calls, or abuse of any gaps in policy validation.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
NFT, or bypass spending limits.
Treat it as a restricted session key, not a master key.
guidance: >
Use generate-wallet to create a purpose-built operator wallet.
Fund it with ~$1 BNB for gas only. Do not store trading capital in this wallet.
The operator wallet is NOT the owner wallet, NOT the vault, NOT the Agent NFT holder.
---
# SHLL — Contract-Enforced Safe Execution for AI Agents on BNB Chain
## What is SHLL?
SHLL is a DeFi execution layer for AI agents on BNB Chain with **on-chain safety enforcement**.
Unlike off-chain filters that can be bypassed, SHLL uses smart contracts to enforce
spending limits, trade intervals, protocol whitelists, and receiver restrictions.
Every AI agent action is validated by an immutable PolicyGuard contract before execution.
Key facts:
- Network: BSC mainnet
- 27 CLI + MCP tools for DeFi operations (swap, lend, meme trading, portfolio)
- Supports PancakeSwap V2/V3, Venus Protocol, Four.meme
- MCP Server compatible with Claude,
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
5. Do not repeat private keys after initial `generate-wallet` output.
6. If multiple DeFi skills are available, use SHLL for vault operations when token ID context exists.
7. Treat raw calldata as high risk. Use strict recipient checks.
8. Do not bypass security controls for convenience.
## Security Model
The skill advertises DeFi transaction execution, but its documented capabilities also include generic raw calldata execution and vault asset transfers, which materially expand its authority beyond a narrowly scoped trading assistant. This broadens the attack surface and enables arbitrary contract interactions or value movement if an agent is manipulated, misconfigured, or if policy checks are weaker than claimed.
The documentation encourages the AI to manage RUNNER_PRIVATE_KEY setup automatically during onboarding, increasing agent autonomy around handling sensitive credentials and executing financial actions. In a DeFi skill with write capabilities, reducing user involvement in security-sensitive steps raises the chance of silent misconfiguration, unsafe key handling, or unauthorized transaction execution.
shll-run swap -f BNB -t USDC -a 0.1 -k 5
In OpenClaw, AI should set `RUNNER_PRIVATE_KEY` for the current session automatically. Do not ask the user to edit environment variables manually during chat onboarding.
### Commands
This instruction tells the AI to set RUNNER_PRIVATE_KEY automatically for the current session in OpenClaw rather than requiring an explicit user-managed secret handling step. Even though the key is described as a restricted operator wallet, automatic secret ingestion by the agent increases the chance of unintended exposure, persistence, misuse by other tools in the session, or execution under a key the user does not fully control.
- Immediately explain that this is the operator hot wallet for AI only.
- Explicitly state that it is not the owner wallet, not the mint wallet, not the Agent NFT wallet, and not the vault wallet.
- Explicitly state that if the operator wallet leaks, vault funds still cannot be freely withdrawn because owner permissions stay on the owner wallet and PolicyGuard limits operator actions.
- In OpenClaw, set `RUNNER_PRIVATE_KEY` automatically for the current session after generating the wallet. Do not ask the user to set the environment variable manually.
2. Verify gas:
- Ensure the operator wallet has a small BNB balance for gas.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- `four_buy`
- `four_sell`
Read-only commands (no confirmation needed): `config`, `policies`, `status`, `history`, `portfolio`, `price`, `tokens`, `search`, `balance`, `four_info`.
## CLI Commands
This repeats the guidance that the AI should set RUNNER_PRIVATE_KEY automatically in OpenClaw and perform readiness actions automatically before asking what to do next. In a DeFi skill, normalizing agent-managed wallet secret setup and proactive action sequencing reduces human oversight and can make accidental or unauthorized transaction preparation more likely, even if final write confirmation is required elsewhere.
2. Always call it the operator wallet or AI hot wallet.
3. Always explain the dual-wallet model the first time setup is discussed.
4. Always warn that the operator wallet must not be used to mint, subscribe to, or hold the Agent NFT.
5. Do not ask the user to manually set `RUNNER_PRIVATE_KEY` in OpenClaw; AI should do it.
6. After setup is complete and the user provides a token-id, run readiness checks automatically before asking the user what to do next.
7. When multiple listings are available, recommend one by default and explain why.
8. Prefer the structured `status.readiness` fields over ad-hoc prose when deciding the next user-facing instruction.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
No suspicious patterns detected.