Back to skill

Security audit

a2a-wallet

Security checks for vulnerabilities and agentic risk

Overview

The skill’s wallet and payment purpose is clear, but its install path and key-storage model create material security risk users should review before installing.

Install only if you are comfortable with an experimental wallet CLI. Avoid importing or funding any valuable wallet, review or replace the installer with a pinned and verified release, and require explicit confirmation before wallet import/export, signing payments, changing configuration, or interacting with unknown agent URLs.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
INSTALL.md:6
Finding

Unpinned Remote Installation Script Is Executed Directly by a Shell

Content
View full analysis

Vulnerability Details

File Location: INSTALL.md, line 6
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable code:

bash
curl -fsSL https://raw.githubusercontent.com/planetarium/a2a-x402-wallet/main/scripts/install.sh | sh

Technical Analysis

The installation command retrieves a shell script from the mutable main branch of an external repository and immediately executes it. The downloaded content is not pinned to an immutable commit or release, saved for inspection, authenticated with a cryptographic signature, or checked against a trusted digest.

HTTPS protects the connection in transit but does not ensure that the repository account, branch contents, or upstream installation script remain trustworthy. The script is also absent from the audited project, so its actual commands, downloaded artifacts, filesystem changes, and privilege behavior cannot be verified from this package.

Direct execution is not necessary for the Skill's declared wallet and A2A functionality. A versioned binary or locally included, reviewable installer with integrity verification would provide the required installation capability with substantially less supply-chain risk.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or the mutable installation script.
  2. The attacker modifies scripts/install.sh on the main branch or causes it to retrieve a malicious secondary payload.
  3. A user or AI agent follows INSTALL.md and invokes the documented command.
  4. curl streams the attacker-controlled content directly into sh.
  5. The payload runs with the invoking user's privileges and can access files, environment variables, wallet data, authentication tokens, and network resources available to that user.
  6. Because this is a wallet-related tool, the payload could specifically target private keys or alter payment operations.

Impact Assess

...[truncated 451 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe remotely retrieved content directly into a shell.
  • Pin the installer to an immutable release tag and commit rather than the mutable main branch.
  • Download the installer to a local file and require review before execution.
  • Publish SHA-256 or stronger digests through a separately trusted channel and verify them before execution.
  • Cryptographically sign installer scripts and release artifacts, and document mandatory signature verification.
  • Include the installer in the audited Skill package where practical.
  • Ensure the installer runs without administrator privileges unless a narrowly scoped operation explicitly requires elevation.
  • Pin and verify every secondary artifact downloaded by the installer.

T08 · Insecure Dependencies

Error
Location
INSTALL.md:13
Finding

Windows Executable Is Installed from a Floating Release Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: INSTALL.md, line 13
Vulnerability Type: Insecure executable dependency installation
Risk Level: High

Vulnerable instruction:

text
Download `a2a-wallet-windows-x64.exe` from the [Releases](https://github.com/planetarium/a2a-x402-wallet/releases/latest) page, rename it to `a2a-wallet.exe`, and place it in a folder on your PATH.

Technical Analysis

The instructions direct users to install a native executable from a floating latest release and place it on PATH. No fixed release version, expected digest, code-signing certificate, or provenance verification procedure is supplied.

The executable is not present in the audited project, so its behavior cannot be evaluated. A repository or release-account compromise could replace the artifact with a malicious binary. Placing that binary on PATH makes it appear to be the legitimate wallet tool during subsequent commands.

Installing a native executable is compatible with the Skill's declared functionality, but trusting an unverified, mutable release is broader than necessary. The minimum safe mechanism should authenticate a fixed artifact before it receives access to wallet and payment operations.

Attack Path

  1. An attacker compromises the upstream release process, repository account, or release asset storage.
  2. The attacker publishes or replaces the latest Windows asset with a trojanized executable.
  3. The user downloads the asset, renames it to a2a-wallet.exe, and places it on PATH.
  4. The user or agent invokes ordinary commands such as wallet creation, import, balance checks, or payment signing.
  5. The malicious executable runs under the expected tool name and can steal inputs, alter payment destinations, expose private keys, or execute unrelated commands.

Impact Assessment

The compromised executable would receive the full privileges of the invoking Windows user. It could access user-read ...[truncated 333 chars]

Remediation
View remediation

Remediation Suggestions

  • Link to a specific, immutable release version rather than /releases/latest.
  • Publish trusted checksums for every platform artifact and require users to verify them before installation.
  • Sign the executable with a recognized code-signing certificate and document how to inspect the signer and signature status.
  • Publish signed provenance or attestations for reproducible release artifacts.
  • Fail installation if the digest, signature, expected filename, architecture, or publisher identity does not match.
  • Recommend installation into a dedicated user-owned directory with restrictive permissions rather than an arbitrary writable PATH directory.
  • Document safe upgrade procedures that repeat all integrity checks.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:120
Finding

Local Wallet Private Keys Are Stored as Plaintext Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 120–126
Vulnerability Type: Plaintext storage of cryptocurrency private keys
Risk Level: High

Vulnerable design documentation:

markdown
### Local Wallet Risk

The local wallet stores the private key as a **plain file on disk** (`~/.a2a-wallet/`). As an AI agent using this CLI, you have direct filesystem access — which means the key file is accessible to the agent runtime and any other process on the machine.

- **Do NOT create or use a local wallet that holds significant assets.**
- **Do NOT import or restore a wallet that holds significant assets** into this CLI.
- If the key file is read by any unauthorized process or leaks for any reason, **all assets are permanently unrecoverable**. The user bears full responsibility.

The same behavior is reiterated at SKILL.md:157:

markdown
- **Local wallet** — private key stored locally (`wallet create` / `wallet import`). No login required. **Key is stored as a plain file — use only for small amounts.**

Technical Analysis

A cryptocurrency private key grants signing authority over its associated assets. Storing it as an unencrypted file under ~/.a2a-wallet/ exposes it to every process, agent, backup system, diagnostic collector, or user that can read the file. The Skill explicitly notes that the AI-agent runtime has filesystem access, increasing the risk that unrelated tool activity or malicious instructions could obtain the key.

The warning is transparent and reduces user surprise, but it does not technically protect the secret. Plaintext storage exceeds the minimum privileges necessary for payment signing: keys can instead be held in an operating-system credential store, hardware-backed keystore, or encrypted vault and exposed only through narrowly scoped signing operations.

Attack Path

  1. A user creates a local wallet or imports an existing wallet using the CLI.
  2. The CLI ...[truncated 980 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not store raw private keys as plaintext files.
  • Use platform credential protection such as macOS Keychain, Windows Credential Manager/DPAPI, or Linux Secret Service.
  • Prefer hardware wallets, secure enclaves, or hardware-backed keystores so raw keys are not exposed to the CLI or agent runtime.
  • If file-based storage is unavoidable, encrypt keys using a strong password-based key derivation function and authenticated encryption.
  • Enforce owner-only filesystem permissions and reject wallet operation when the storage directory or key file is accessible by other users.
  • Keep signing behind a narrow interface that returns signatures without returning private-key material.
  • Require explicit user confirmation showing the network, asset, amount, and recipient before each payment signature.
  • Prevent wallet export or secret output from entering AI-agent context, logs, shell history, crash reports, or telemetry.
  • Default to test networks and low-value, isolated wallets; never recommend importing an existing wallet containing meaningful assets.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | sh construct is a classic dangerous chaining pattern because it removes any opportunity for inspection and immediately executes whatever bytes were fetched. In a wallet-related skill, successful exploitation could lead to host compromise, credential theft, wallet key exfiltration, or malicious transaction/payment manipulation.

Content

Scanner excerpt · INSTALL.md (reported line 6)May include surrounding context.

macOS / Linux

bash
curl -fsSL https://raw.githubusercontent.com/planetarium/a2a-x402-wallet/main/scripts/install.sh | sh

Supported platforms: macOS (Apple Silicon, Intel), Linux (x64, arm64).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation command fetches a remote script from the network and immediately executes it in the user's shell without any integrity verification, pinning, or review step. This creates a direct remote code execution path if the upstream repository, branch, hosting account, or network path is compromised, and the risk is amplified because this skill manages wallets and payment signing material.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises very broad triggers such as sending messages, discovering agents, signing payments, managing wallets, and configuring the CLI without defining clear guardrails for when each action is appropriate. In an agentic environment, this can cause the skill to be invoked in loosely related contexts and steer the agent toward sensitive operations like wallet creation, key import, payment signing, or registry interaction without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

This command retrieves executable content from an external URL and treats it as trusted installation logic. Any compromise of the GitHub repository, raw content path, or referenced branch can turn the install step into arbitrary code execution on the user's machine.

Content

Scanner excerpt · INSTALL.md (reported line 6)May include surrounding context.

macOS / Linux

bash
curl -fsSL https://raw.githubusercontent.com/planetarium/a2a-x402-wallet/main/scripts/install.sh | sh

Supported platforms: macOS (Apple Silicon, Intel), Linux (x64, arm64).

Static analysis

No suspicious patterns detected.