Back to skill

Security audit

jerithchain

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent JerithChain wallet skill, but it should be reviewed because it can spend funds and its backup flow misleadingly labels a key-containing tar.gz archive as encrypted.

Install only if you trust this skill with JER funds, the local node token, and files under ~/.config/jerith. Treat wallet-backup output as plaintext-equivalent wallet control material even though the command labels it encrypted; keep it offline and do not upload it. Review the configured RPC/explorer URLs and spending limits before allowing sends.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior promises safety-critical controls and wallet features—such as spending limits, confirmation enforcement, backup/restore handling, deposit watching, and not inventing balances—that static analysis indicates may not actually exist in code. For a cryptocurrency wallet skill, this mismatch is dangerous because users and agents may rely on protections that are absent, potentially leading to unauthorized sends, unsafe restores, false confirmation claims, or incorrect financial decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The backup routine labels the output as an 'ENCRYPTED backup bundle', but the code only creates a gzip-compressed tar archive containing the wallet file and key file. In a wallet skill, this is especially dangerous because users may store or transmit the archive under the false assumption that it is cryptographically protected, and anyone who obtains it may be able to restore and control the wallet.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill requests or implies access to sensitive capabilities (environment variables, filesystem read/write, network, and shell) but does not declare an explicit tool scope or permission boundary. In a wallet-managing skill, this increases the blast radius: an agent runtime may grant broader access than users expect, enabling unintended reading of tokens, wallet files, backups, or invoking shell/network actions beyond the documented use.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill is explicitly designed to persist sensitive state across sessions, including wallet material, key files, API tokens, send-state, and backup archives under user-accessible paths. Persistence itself is expected for a wallet, but it becomes a security concern if these files are insufficiently permissioned, copied into backups, or exposed to other tools/processes, because anyone obtaining both wallet data and key material can control funds.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Setup (one time)

bash
~/.openclaw/plugin-skills/jerithchain/jerith_skill.py wallet-create

Requires a reachable JER node (default http://127.0.0.1:8300) with its

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a JER wallet and chain client, but does not mention reading authentication material from process environment variables or scanning local filesystem locations for node exchange tokens. This grants the skill access to local secrets beyond straightforward RPC usage, which is a broader capability than the stated purpose requires.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code reads an authentication token from an environment variable or local token files, including default paths under the user's home directory. Although the module docstring documents token sourcing, the credential access itself has no user-facing prompt or runtime disclosure, which qualifies as a sensitive credential access without an explicit warning in the operation path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The client performs HTTP requests to the configured RPC endpoint and may transmit addresses, signed transactions, and Discord-related identifiers. While the module docstring describes the API surface, the request path itself provides no confirmation, visible logging, or inline warning about outbound transmission of user/system data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The top-level module docstring presents the skill's available subcommands as its public behavior, but it omits implemented commands such as estimate-fee, supply, watch, wallet-backup, wallet-restore, and validate that are later registered in main(). This creates a documentation-to-code mismatch about what the skill actually does, even though the manifest broadly mentions some of these capabilities.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.