T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned Global Installation of a Security-Critical Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Web5 helper is mostly coherent, but it handles wallets, private keys, bearer tokens, and irreversible account/DID destruction without enough scoping or user safeguards.
Review this before installing. Use only disposable test identities and low-value testnet funds, pin and verify the web5-cli package, avoid production keys, and require manual confirmation before any delete, destroy, import, export, write, or send-tx operation. Do not keep plaintext private keys or bearer tokens in shared, backed-up, or logged environments.
SKILL.md:11Unpinned Global Installation of a Security-Critical Dependency
SKILL.md:139DID and Wallet Private Keys Are Persisted in Plaintext
scripts/create_account.py:212Bearer Authentication Tokens Embedded in Source-Code Examples
scripts/create_account.py:336Insecure Temporary Transaction File Creation Enables Local File-Race Attacks
The skill is presented as a helper for routine Web5 CLI tasks, but it also includes full account-destruction behavior, including deleting PDS accounts and destroying on-chain DID state. That mismatch is dangerous because users or orchestration logic may invoke the skill under a benign expectation while it still contains irreversible destructive workflows.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
return False
'''
pds create-account --pds web5.bbsfans.dev --username david2 --didkey did:key:zQ3shQmJ8bD79MGya89W1gdtWfHtohXKrrdxd3CEXQyJnzQmW --did did:ckb:xdif6yxk7v37usfdu4xhpacoutzr2mls --ckb-address ckt1qzda0cr08m85hc8jlnfp3zer7xulejywt49kt2rr0vthywaa50xwsqvwae5x73tj6gaqj8n33vft722usg062lg6ds5ky
{
"success": true,
"data": {
"accessJwt": "eyJhbGciOiJFUzI1NksiLCJ0eXAiOiJKV1QifQ.eyJpYXQiOjE3NzIzNjQ5NTksImV4cCI6MTc3MjM3MjE1OSwibmJmIjoxNzcyMzY0OTU5LCJzdWIiOiJkaWQ6Y2tiOnhkaWY2eXhrN3YzN3VzZmR1NHhocGFjb3V0enIybWxzIiwiYXVkIjoiZGlkOndlYjp3ZWI1LmJic2ZhbnMuZGV2Iiwic2NvcGUiOiJjb20uYXRwcm90by5hY2Nlc3MifQ.axniYN_SLJLxCBkv6vq_gO6UAfd2nLZbCStPsEi2CFsxT-tzrE1r3xyE_JSw73IdXSKRtjsQqMOnxo6_ILiKyg",
"refreshJwt": "eyJhbGciOiJFUzI1NksiLCJ0eXAiOiJKV1QifQ.eyJpYXQiOjE3NzIzNjQ5NTksImV4cCI6MTc4MDE0MDk1OSwibmJmIjoxNzcyMzY0OTU5LCJzdWIiOiJkaWQ6Y2tiOnhkaWY2eXhrN3YzN3VzZmR1NHhocGFjb3V0enIybWxzIiwiYXVkIjoiZGlkOndlYjp3ZWI1LmJic2ZhbnMuZGV2IiwianRpIjoidEhKalpQNk41TXBZRGl3TGg3TG53Y1VBakVoeXMxOXIiLC
The module docstring and usage text say the script creates an account, but the implementation actually destroys a PDS account and submits an on-chain DID destruction transaction. In a destructive identity-management skill, this mismatch is dangerous because users, agents, or automation may invoke it under false assumptions, causing irreversible deletion of accounts and DID resources.
The skill exposes shell and environment-backed operational capability but does not declare any tool scope or allowed-tools boundaries. In an agent setting, this increases the chance that the agent can invoke sensitive CLI operations, read local secrets, or perform destructive actions without an explicit permission contract.
The activation condition is broad enough to match general Web5-related requests, which can cause the skill to be selected in situations beyond its safest intended use. Because the skill handles keys, wallets, account state, and destructive operations, overbroad activation materially raises the chance of unnecessary exposure or unintended execution.
The skill persists DID and wallet private keys, and the file later explicitly states they are stored in plaintext under the user's home directory. Persistent plaintext secret storage is dangerous because any local compromise, over-permissive file access, backup leakage, or unintended shell exposure can directly lead to key theft, unauthorized signing, wallet compromise, and identity takeover.
web5-cli keystore new # Create new keypair
web5-cli keystore import --sk <hex> # Import private key
web5-cli keystore get # Get DID key
web5-cli keystore sign --message <hex> # Sign message
The documented export functionality can extract potentially sensitive PDS data, yet the workflow omits an explicit warning, consent step, or guidance on secure output handling. In an agent context, silent or under-signaled export can lead to unintended disclosure of personal data or repository contents to local disk or downstream tools.
The destroy-account workflow deletes the remote PDS account and then removes local account metadata, but it does not require a strong explicit warning about irreversibility or data loss. Because this affects both remote identity state and local recovery/context files, accidental invocation could permanently disrupt account access and user data continuity.
The script prints the full account creation response object, which includes accessJwt and refreshJwt tokens. Those bearer tokens can be captured from terminal scrollback, logs, CI output, shell history capture tools, or shared consoles and then reused to act as the newly created account.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_command(cmd: list, check: bool = True) -> Optional[dict]:
"""Run a command and return exit code, stdout, stderr."""
result = subprocess.run(
cmd,
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_command(cmd: list, check: bool = True) -> Optional[dict]:
"""Run a command and return exit code, stdout, stderr."""
result = subprocess.run(
cmd,
capture_output=True,
text=True,
The script performs irreversible off-chain account deletion and on-chain DID destruction without any interactive confirmation, dry-run mode, or explicit acknowledgement flag. In the context of a Web5 CLI skill for identity and wallet operations, accidental or unintended invocation could permanently remove user identity assets with little opportunity to recover.
The script prints identifiers and wallet details such as DID, didkey, and CKB address at completion. While these are less sensitive than bearer tokens, exposing them unnecessarily can leak account metadata, aid correlation of identities and wallets, and increase privacy and targeting risks in shared or logged environments.
No suspicious patterns detected.