T09 · Insecure Skill Coding Practices
- Location
src/wallet.ts:65- Finding
Transaction Safety Controls Are Not Enforced by Value-Transferring APIs
- Content
View full analysis
{ if (!ethers.isAddress(to)) { throw new Error('Invalid address format. Expected 0x + 40 hex characters.'); } const wallet = this.requireWallet(); const tx = await wallet.sendTransaction({ to, value: ethers.parseEther(amount), gasLimit: opts?.gasLimit, }); ``` The ERC-20 transfer path similarly submits the transaction without invoking the security policy: ```ts async transfer( tokenAddress: string, to: string, amount: string, signer: ethers.Wallet, ): Promise { const connected = signer.connect(this.provider); const contract = new ethers.Contract(tokenAddress, ERC20_ABI, connected); const decimals = await contract.decimals(); const parsedAmount = ethers.parseUnits(amount, decimals); const tx = await contract.transfer(to, parsedAmount); ``` The project contains a policy implementation, but it is not integrated into these transaction paths: ```ts preTransactionCheck(tx: TransactionCheck): CheckResult { // Rule 1: Validate address format first — reject before any other processing if (tx.to.includes(' ') || tx.to.length !== 42 || !tx.to.startsWith('0x')) { return { approved: false, requiresConfirmation: false, warnings: ['Invalid address format — possible injection attempt'], }; } const warnings: string[] = []; let requiresConfirmation = this.config.requireConfirmAlways; // Rule 2: Large transaction (>100 QFC) if (tx.amount > 100) { warnings.push(`Large transaction: ${tx.amount} QFC exceeds 100 QFC threshold`); ...[truncated 2900 chars]- Remediation
View remediation
