Back to skill

Security audit

Rustok Agentic Wallet

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly disclosed self-custody crypto wallet skill, but it deserves Review because it combines real-funds transaction authority with a mutable remote installer and broad default execution capabilities.

Only install this if you are comfortable treating it as real wallet software with live-funds risk. Prefer a read-only capability configuration unless you specifically need transaction execution, avoid the curl-to-sh one-liner, inspect and verify installer/container provenance where possible, keep only limited funds in the wallet, and understand how to remove or rotate the local secret and wallet volume.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:129
Finding

Mutable Remote Installer Is Piped Directly into a Shell

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:297
Finding

Wallet Grants Transaction-Execution Capability by Default

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (21)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This one-liner pipes a remote script directly into sh, which is a classic unsafe pattern because it executes whatever the URL serves at retrieval time without an integrity check at the shell boundary. In the context of a self-custody wallet, a compromised upstream or man-in-the-middle position could install malware, alter wallet behavior, or capture recovery material and secrets, leading to total fund loss.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

bash
curl --proto '=https' --tlsv1.2 -fsSL \
  https://raw.githubusercontent.com/rustok-org/mcp/wallet-tui-v0.11.0/scripts/install.sh | sh

Piping to a shell runs whatever the URL serves at that moment, unreviewed. The

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

podman run -i --rm \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

podman run -i --rm \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

podman run -i --rm \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

podman run -i --rm \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

podman run -i --rm \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

podman run -i --rm \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 276)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

podman run -i --rm \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

podman run -i --rm \

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
--label rustok=wallet --label rustok.agent=claude \
  -v rustok-wallet-tui:/data \
  --secret rustok-keyring-claude,type=mount,mode=0400,uid=1000,gid=1000 \
  -e RUSTOK_KEYRING_PASSWORD_FILE=/run/secrets/rustok-keyring-claude \
  -e RUSTOK_ALLOWED_CHAINS="1,8453,42161" \
  -e RUSTOK_RPC_URLS_1="https://your-rpc" \
  ghcr.io/rustok-org/rustok-wallet-tui:v0.11.0

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 217)May include surrounding context.

md
--label rustok=wallet --label rustok.agent=claude \
  -v rustok-wallet-tui:/data \
  --secret rustok-keyring-claude,type=mount,mode=0400,uid=1000,gid=1000 \
  -e RUSTOK_KEYRING_PASSWORD_FILE=/run/secrets/rustok-keyring-claude \
  -e RUSTOK_ALLOWED_CHAINS="1,8453,42161" \
  -e RUSTOK_RPC_URLS_1="https://your-rpc" \
  ghcr.io/rustok-org/rustok-wallet-tui:v0.11.0

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

md
--label rustok=wallet --label rustok.agent=claude \
  -v rustok-wallet-tui:/data \
  --secret rustok-keyring-claude,type=mount,mode=0400,uid=1000,gid=1000 \
  -e RUSTOK_KEYRING_PASSWORD_FILE=/run/secrets/rustok-keyring-claude \
  -e RUSTOK_ALLOWED_CHAINS="1,8453,42161" \
  -e RUSTOK_RPC_URLS_1="https://your-rpc" \
  ghcr.io/rustok-org/rustok-wallet-tui:v0.11.0

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
--label rustok=wallet --label rustok.agent=claude \
  -v rustok-wallet-tui:/data \
  --secret rustok-keyring-claude,type=mount,mode=0400,uid=1000,gid=1000 \
  -e RUSTOK_KEYRING_PASSWORD_FILE=/run/secrets/rustok-keyring-claude \
  -e RUSTOK_ALLOWED_CHAINS="1,8453,42161" \
  -e RUSTOK_RPC_URLS_1="https://your-rpc" \
  ghcr.io/rustok-org/rustok-wallet-tui:v0.11.0

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

This skill explicitly supports autonomous on-chain fund transfers once a user enables autonomous mode, and it also states there are no hard-coded spending limits. In the context of a wallet skill handling real funds, autonomous execution materially increases the blast radius of prompt injection, agent malfunction, or unsafe transaction generation because approved autonomy removes per-transaction human review.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
- **The wallet states what it does not promise.** A `## Legal` section below, and
  a full [DISCLAIMER](https://github.com/rustok-org/mcp/blob/main/DISCLAIMER.md)
  that names the limit of every safeguard — starting with the one easiest to read
  as absolute: autonomous mode sends without asking once confirmed.

## What changed in 0.9.5

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
> **Rule of two windows:** never run `rustok init`, `rustok restore`,
> `rustok set-pin` or the approval console through an agent shell/command — the
> seed and PIN would leak into the agent's context. These belong only in the
> user's own terminal (window 2). Do not ask the user for their PIN or their
> phrase in this chat, ever.

## Where the balance you show comes from

Session Persistence

Medium
Category
Rogue Agent
Confidence
74% confidence
Finding

The Podman secret created here persists beyond the current session, which means a sensitive wallet-unlock credential remains stored locally for future runs. In a wallet context, that persistence increases exposure if the local host, user account, or container tooling is later compromised, especially since the wallet controls real funds and the skill admits shell/exec access can reach the signing surface.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

bash
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
  printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw

podman run -i --rm \

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 347)May include surrounding context.

md
`execute_transaction` only parks the transaction (`state: "pending"`) — the user
   releases it in a separate terminal window by running `rustok console` (see
   the onboarding above). Never offer to run the console command yourself
   and never ask the user to paste the approval PIN into this chat.
3. **`executed` means the transaction was broadcast, not that it succeeded.**
   The wallet reports the hash the moment the network accepted the transaction
   for inclusion; a transaction that reverts on-chain still costs its gas and

External Script Fetching

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The onboarding instructs users to fetch and run an external installer script from GitHub. Although it recommends reviewing the script first and notes some supply-chain safeguards, it still normalizes execution of remote code, and a compromise of the source repo, distribution path, or tag contents could deliver malicious installation logic to users managing a real-funds wallet.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

and one look costs less than that trade.

bash
curl --proto '=https' --tlsv1.2 -fsSL \
  https://raw.githubusercontent.com/rustok-org/mcp/wallet-tui-v0.11.0/scripts/install.sh -o install.sh
less install.sh      # ~321 lines of POSIX sh
sh install.sh

Static analysis

No suspicious patterns detected.