T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:129- Finding
Mutable Remote Installer Is Piped Directly into a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a clearly disclosed self-custody crypto wallet skill, but it deserves Review because it combines real-funds transaction authority with a mutable remote installer and broad default execution capabilities.
Only install this if you are comfortable treating it as real wallet software with live-funds risk. Prefer a read-only capability configuration unless you specifically need transaction execution, avoid the curl-to-sh one-liner, inspect and verify installer/container provenance where possible, keep only limited funds in the wallet, and understand how to remove or rotate the local secret and wallet volume.
SKILL.md:129Mutable Remote Installer Is Piped Directly into a Shell
SKILL.md:297Wallet Grants Transaction-Execution Capability by Default
This one-liner pipes a remote script directly into sh, which is a classic unsafe pattern because it executes whatever the URL serves at retrieval time without an integrity check at the shell boundary. In the context of a self-custody wallet, a compromised upstream or man-in-the-middle position could install malware, alter wallet behavior, or capture recovery material and secrets, leading to total fund loss.
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/rustok-org/mcp/wallet-tui-v0.11.0/scripts/install.sh | sh
Piping to a shell runs whatever the URL serves at that moment, unreviewed. The
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
podman run -i --rm \
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
podman run -i --rm \
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
podman run -i --rm \
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
podman run -i --rm \
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
podman run -i --rm \
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
podman run -i --rm \
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
podman run -i --rm \
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
podman run -i --rm \
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
--label rustok=wallet --label rustok.agent=claude \
-v rustok-wallet-tui:/data \
--secret rustok-keyring-claude,type=mount,mode=0400,uid=1000,gid=1000 \
-e RUSTOK_KEYRING_PASSWORD_FILE=/run/secrets/rustok-keyring-claude \
-e RUSTOK_ALLOWED_CHAINS="1,8453,42161" \
-e RUSTOK_RPC_URLS_1="https://your-rpc" \
ghcr.io/rustok-org/rustok-wallet-tui:v0.11.0
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
--label rustok=wallet --label rustok.agent=claude \
-v rustok-wallet-tui:/data \
--secret rustok-keyring-claude,type=mount,mode=0400,uid=1000,gid=1000 \
-e RUSTOK_KEYRING_PASSWORD_FILE=/run/secrets/rustok-keyring-claude \
-e RUSTOK_ALLOWED_CHAINS="1,8453,42161" \
-e RUSTOK_RPC_URLS_1="https://your-rpc" \
ghcr.io/rustok-org/rustok-wallet-tui:v0.11.0
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
--label rustok=wallet --label rustok.agent=claude \
-v rustok-wallet-tui:/data \
--secret rustok-keyring-claude,type=mount,mode=0400,uid=1000,gid=1000 \
-e RUSTOK_KEYRING_PASSWORD_FILE=/run/secrets/rustok-keyring-claude \
-e RUSTOK_ALLOWED_CHAINS="1,8453,42161" \
-e RUSTOK_RPC_URLS_1="https://your-rpc" \
ghcr.io/rustok-org/rustok-wallet-tui:v0.11.0
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
--label rustok=wallet --label rustok.agent=claude \
-v rustok-wallet-tui:/data \
--secret rustok-keyring-claude,type=mount,mode=0400,uid=1000,gid=1000 \
-e RUSTOK_KEYRING_PASSWORD_FILE=/run/secrets/rustok-keyring-claude \
-e RUSTOK_ALLOWED_CHAINS="1,8453,42161" \
-e RUSTOK_RPC_URLS_1="https://your-rpc" \
ghcr.io/rustok-org/rustok-wallet-tui:v0.11.0
This skill explicitly supports autonomous on-chain fund transfers once a user enables autonomous mode, and it also states there are no hard-coded spending limits. In the context of a wallet skill handling real funds, autonomous execution materially increases the blast radius of prompt injection, agent malfunction, or unsafe transaction generation because approved autonomy removes per-transaction human review.
- **The wallet states what it does not promise.** A `## Legal` section below, and
a full [DISCLAIMER](https://github.com/rustok-org/mcp/blob/main/DISCLAIMER.md)
that names the limit of every safeguard — starting with the one easiest to read
as absolute: autonomous mode sends without asking once confirmed.
## What changed in 0.9.5
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
> **Rule of two windows:** never run `rustok init`, `rustok restore`,
> `rustok set-pin` or the approval console through an agent shell/command — the
> seed and PIN would leak into the agent's context. These belong only in the
> user's own terminal (window 2). Do not ask the user for their PIN or their
> phrase in this chat, ever.
## Where the balance you show comes from
The Podman secret created here persists beyond the current session, which means a sensitive wallet-unlock credential remains stored locally for future runs. In a wallet context, that persistence increases exposure if the local host, user account, or container tooling is later compromised, especially since the wallet controls real funds and the skill admits shell/exec access can reach the signing surface.
# One-time (podman): the value never touches history, inspect or configs.
read -r -s -p "Keyring password: " pw &&
printf '%s' "$pw" | podman secret create rustok-keyring-claude -
unset pw
podman run -i --rm \
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
`execute_transaction` only parks the transaction (`state: "pending"`) — the user
releases it in a separate terminal window by running `rustok console` (see
the onboarding above). Never offer to run the console command yourself
and never ask the user to paste the approval PIN into this chat.
3. **`executed` means the transaction was broadcast, not that it succeeded.**
The wallet reports the hash the moment the network accepted the transaction
for inclusion; a transaction that reverts on-chain still costs its gas and
The onboarding instructs users to fetch and run an external installer script from GitHub. Although it recommends reviewing the script first and notes some supply-chain safeguards, it still normalizes execution of remote code, and a compromise of the source repo, distribution path, or tag contents could deliver malicious installation logic to users managing a real-funds wallet.
and one look costs less than that trade.
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/rustok-org/mcp/wallet-tui-v0.11.0/scripts/install.sh -o install.sh
less install.sh # ~321 lines of POSIX sh
sh install.sh
No suspicious patterns detected.