T09 · Insecure Skill Coding Practices
- Location
scripts/writeBitnoteUiCompat.mjs:47- Finding
Dry-run mode unnecessarily decrypts the wallet signing key
- Content
View full analysis
extractIdHexFromBlob(b.toString()) === idHex); if (dup) { console.log('IDEMPOTENT_HIT', 'request-id already present'); console.log('ADDRESS', address); console.log('REQUEST_ID', requestId); console.log('ID_HEX', idHex); process.exit(0); } } const noteHex = await makeBitnotePayload(title, body, ecdhPub.toString(), ecdhPrivPkcs8, idHex); const noteIndex = ethers.keccak256(noteHex); if (dryRun) { console.log('DRY_RUN', 1); console.log('ADDRESS', address); console.log('REQUEST_ID', requestId); console.log('ID_HEX', idHex); console.log('NOTE_INDEX', noteIndex); process.exit(0); } ``` ### Technical Analysis The script decrypts both the ECDH private key and the secp256k1 transaction-signing private key before evaluating the `dryRun` branch. Constructing a preview note requires the ECDH key to encrypt the note payload, but it does not require the wallet’s spending key because no transaction is signed or broadcast. This violates least-privilege principles by ...[truncated 1430 chars]- Remediation
View remediation
