Back to skill

Security audit

web5 cli

Security checks for vulnerabilities and agentic risk

Overview

This Web5 helper is mostly coherent, but it handles wallets, private keys, bearer tokens, and irreversible account/DID destruction without enough scoping or user safeguards.

Review this before installing. Use only disposable test identities and low-value testnet funds, pin and verify the web5-cli package, avoid production keys, and require manual confirmation before any delete, destroy, import, export, write, or send-tx operation. Do not keep plaintext private keys or bearer tokens in shared, backed-up, or logged environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Global Installation of a Security-Critical Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:139
Finding

DID and Wallet Private Keys Are Persisted in Plaintext

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create_account.py:212
Finding

Bearer Authentication Tokens Embedded in Source-Code Examples

Content
View full analysis
Remediation
View remediation
` and ``. - Remove the credentials from repository history where feasible and treat all existing copies as compromised. - Run secret scanning against the current tree, version history, release artifacts, and documentation. - Prevent future examples from being generated by copying live command output. - Avoid passing bearer tokens directly on command lines. Prefer protected standard input, a restricted temporary descriptor, or another secret-delivery mechanism supported by the CLI. - Ensure logs and error messages redact access and refresh tokens. - Add automated pre-commit and CI checks for JWT and secret patterns. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create_account.py:336
Finding

Insecure Temporary Transaction File Creation Enables Local File-Race Attacks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a helper for routine Web5 CLI tasks, but it also includes full account-destruction behavior, including deleting PDS accounts and destroying on-chain DID state. That mismatch is dangerous because users or orchestration logic may invoke the skill under a benign expectation while it still contains irreversible destructive workflows.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/create_account.py (reported line 207)May include surrounding context.

python
return False


'''
pds create-account --pds web5.bbsfans.dev --username david2 --didkey did:key:zQ3shQmJ8bD79MGya89W1gdtWfHtohXKrrdxd3CEXQyJnzQmW --did did:ckb:xdif6yxk7v37usfdu4xhpacoutzr2mls --ckb-address ckt1qzda0cr08m85hc8jlnfp3zer7xulejywt49kt2rr0vthywaa50xwsqvwae5x73tj6gaqj8n33vft722usg062lg6ds5ky
{
  "success": true,
  "data": {
    "accessJwt": "eyJhbGciOiJFUzI1NksiLCJ0eXAiOiJKV1QifQ.eyJpYXQiOjE3NzIzNjQ5NTksImV4cCI6MTc3MjM3MjE1OSwibmJmIjoxNzcyMzY0OTU5LCJzdWIiOiJkaWQ6Y2tiOnhkaWY2eXhrN3YzN3VzZmR1NHhocGFjb3V0enIybWxzIiwiYXVkIjoiZGlkOndlYjp3ZWI1LmJic2ZhbnMuZGV2Iiwic2NvcGUiOiJjb20uYXRwcm90by5hY2Nlc3MifQ.axniYN_SLJLxCBkv6vq_gO6UAfd2nLZbCStPsEi2CFsxT-tzrE1r3xyE_JSw73IdXSKRtjsQqMOnxo6_ILiKyg",
    "refreshJwt": "eyJhbGciOiJFUzI1NksiLCJ0eXAiOiJKV1QifQ.eyJpYXQiOjE3NzIzNjQ5NTksImV4cCI6MTc4MDE0MDk1OSwibmJmIjoxNzcyMzY0OTU5LCJzdWIiOiJkaWQ6Y2tiOnhkaWY2eXhrN3YzN3VzZmR1NHhocGFjb3V0enIybWxzIiwiYXVkIjoiZGlkOndlYjp3ZWI1LmJic2ZhbnMuZGV2IiwianRpIjoidEhKalpQNk41TXBZRGl3TGg3TG53Y1VBakVoeXMxOXIiLC

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module docstring and usage text say the script creates an account, but the implementation actually destroys a PDS account and submits an on-chain DID destruction transaction. In a destructive identity-management skill, this mismatch is dangerous because users, agents, or automation may invoke it under false assumptions, causing irreversible deletion of accounts and DID resources.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill exposes shell and environment-backed operational capability but does not declare any tool scope or allowed-tools boundaries. In an agent setting, this increases the chance that the agent can invoke sensitive CLI operations, read local secrets, or perform destructive actions without an explicit permission contract.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation condition is broad enough to match general Web5-related requests, which can cause the skill to be selected in situations beyond its safest intended use. Because the skill handles keys, wallets, account state, and destructive operations, overbroad activation materially raises the chance of unnecessary exposure or unintended execution.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

The skill persists DID and wallet private keys, and the file later explicitly states they are stored in plaintext under the user's home directory. Persistent plaintext secret storage is dangerous because any local compromise, over-permissive file access, backup leakage, or unintended shell exposure can directly lead to key theft, unauthorized signing, wallet compromise, and identity takeover.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Key Management

bash
web5-cli keystore new                                    # Create new keypair
web5-cli keystore import --sk <hex>                      # Import private key
web5-cli keystore get                                    # Get DID key
web5-cli keystore sign --message <hex>                   # Sign message

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented export functionality can extract potentially sensitive PDS data, yet the workflow omits an explicit warning, consent step, or guidance on secure output handling. In an agent context, silent or under-signaled export can lead to unintended disclosure of personal data or repository contents to local disk or downstream tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The destroy-account workflow deletes the remote PDS account and then removes local account metadata, but it does not require a strong explicit warning about irreversibility or data loss. Because this affects both remote identity state and local recovery/context files, accidental invocation could permanently disrupt account access and user data continuity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script prints the full account creation response object, which includes accessJwt and refreshJwt tokens. Those bearer tokens can be captured from terminal scrollback, logs, CI output, shell history capture tools, or shared consoles and then reused to act as the newly created account.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/create_account.py (reported line 20)May include surrounding context.

python
def run_command(cmd: list, check: bool = True) -> Optional[dict]:
    """Run a command and return exit code, stdout, stderr."""
    result = subprocess.run(
        cmd,
        capture_output=True,
        text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/destroy_account.py (reported line 20)May include surrounding context.

python
def run_command(cmd: list, check: bool = True) -> Optional[dict]:
    """Run a command and return exit code, stdout, stderr."""
    result = subprocess.run(
        cmd,
        capture_output=True,
        text=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script performs irreversible off-chain account deletion and on-chain DID destruction without any interactive confirmation, dry-run mode, or explicit acknowledgement flag. In the context of a Web5 CLI skill for identity and wallet operations, accidental or unintended invocation could permanently remove user identity assets with little opportunity to recover.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script prints identifiers and wallet details such as DID, didkey, and CKB address at completion. While these are less sensitive than bearer tokens, exposing them unnecessarily can leak account metadata, aid correlation of identities and wallets, and increase privacy and targeting risks in shared or logged environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.