Back to skill

Security audit

create-rustchain-agent

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent as a RustChain agent scaffold, but it creates a private wallet and wires unpinned MCP tooling to that wallet path in a way users should review carefully.

Install only if you trust the publisher and are comfortable with a scaffold that creates a plaintext wallet. Prefer pinning exact versions of create-rustchain-agent and rustchain-mcp, review generated .mcp.json before enabling it, and do not run scaffold commands or --node values copied from untrusted sources.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
create_rustchain_agent/__main__.py:47
Finding

Arbitrary Python Code Injection Through Generated Agent Source

Content
View full analysis

Vulnerability Details

File Location: create_rustchain_agent/__main__.py, lines 47-59 and 141-144
Vulnerability Type: Improper neutralization of user-controlled input during source-code generation
Risk Level: High

Vulnerable Code

python
AGENT_PY = '''#!/usr/bin/env python3
"""{name} — a RustChain-participating agent (scaffolded by create-rustchain-agent).

First run: checks the node is reachable, prints your RTC address + balance, and
shows how to claim the First-Light newcomer bounty so your wallet is funded.
"""
import json, os, urllib.request

NODE_URL = "{node}"
WALLET = os.path.join(os.path.dirname(__file__), "wallet.json")

The user-controlled values are inserted into the template here:

python
with open(os.path.join(name, "agent.py"), "w") as f:
    f.write(AGENT_PY.format(name=name, node=node_url))

The values originate from command-line arguments:

python
p.add_argument("name", help="project/agent directory name to create")
p.add_argument("--node", default=NODE_URL, help=f"node URL (default {NODE_URL})")

Technical Analysis

The name and --node arguments are placed directly into executable Python source using str.format(). They are not validated or encoded as Python string literals.

A malicious --node value can terminate the NODE_URL string, insert Python statements, and comment out the remaining content. Similarly, a crafted project name can terminate the generated module docstring by supplying triple quotes and inject statements into the generated file.

This is a source-code injection vulnerability rather than immediate command injection during scaffolding. The injected code executes when the user follows the documented instruction to run:

bash
cd <generated-directory> && python agent.py

For example, a malicious node argument can conceptually use a structure such as:

text
"; __import__("os").system("
...[truncated 1623 chars]
Remediation
View remediation

Remediation Suggestions

  • Never interpolate untrusted input directly into executable source-code strings.

  • Encode values as valid Python literals before inserting them. For example:

    python
    safe_node = repr(node_url)
    

    The template should use the already encoded literal without surrounding it with an additional pair of quotes.

  • Prefer generating a static agent.py that reads non-executable configuration from a JSON or TOML file. Write node_url with json.dump() rather than embedding it in Python source.

  • Restrict project names to a conservative allowlist such as letters, digits, underscores, periods, and hyphens. Reject path separators, control characters, quotes, and newline characters.

  • Parse and validate --node with urllib.parse.urlparse(). Permit only explicitly supported schemes, normally HTTPS, and reject control characters.

  • Add regression tests covering single and double quotes, triple quotes, backslashes, braces, carriage returns, newlines, and comment characters.

  • After generation, compile agent.py in a non-executing validation step, such as ast.parse(), while recognizing that syntax validation is only defense in depth and does not replace safe encoding.

T08 · Insecure Dependencies

Warning
Location
create_rustchain_agent/__main__.py:76
Finding

Unpinned MCP Package Is Executed With Access to the Private-Wallet Path

Content
View full analysis

Vulnerability Details

File Location: create_rustchain_agent/__main__.py, lines 76-83 and 145-147
Vulnerability Type: Unsafe execution of an unpinned third-party dependency in a sensitive context
Risk Level: Medium

Vulnerable Code

python
MCP_JSON = '''{{
  "mcpServers": {{
    "rustchain": {{
      "command": "uvx",
      "args": ["rustchain-mcp"],
      "env": {{ "RUSTCHAIN_WALLET": "{wallet_path}" }}
    }}
  }}
}}
'''

The configuration is generated with the absolute path of the private wallet:

python
with open(os.path.join(name, ".mcp.json"), "w") as f:
    f.write(MCP_JSON.format(wallet_path=wallet_path))

The generated and printed usage guidance also invokes the package without a version constraint:

python
print(f"  claude mcp add rustchain -- uvx rustchain-mcp")

Technical Analysis

The generated MCP configuration instructs an editor or agent host to resolve and execute rustchain-mcp through uvx without an exact version or integrity constraint. This makes the code ultimately executed dependent on the package version available from the configured package source at invocation time.

The same process receives RUSTCHAIN_WALLET, containing the absolute path to wallet.json. That file stores the wallet's plaintext Ed25519 private key. File mode 0600 prevents other operating-system users from reading it, but it does not protect the key from a dependency executed as the wallet owner.

No evidence in the audited repository establishes that the current rustchain-mcp package is malicious. The vulnerability is the unsafe supply-chain trust boundary: a future compromised release, package-index compromise, or dependency resolution attack would be executed automatically in a context where the private-wallet location is explicitly provided.

The documentation also recommends unpinned installation or execution of clawrtc, although the direct private-wa ...[truncated 1572 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin rustchain-mcp to an exact, reviewed version in the generated command, for example:

    json
    "args": ["rustchain-mcp==REVIEWED_VERSION"]
    
  • Use a lock file or controlled environment that verifies package artifacts with cryptographic hashes. An exact version alone does not protect against replacement of an artifact at its source.

  • Resolve dependencies from a trusted, explicitly configured package index and document how users can verify package provenance.

  • Avoid providing the private-wallet path to the MCP process unless the requested operation requires signing.

  • Separate public wallet data from private signing material. Balance checks and identity display should use only the public address.

  • Place signing behind a minimal local signer interface that requires explicit user approval and does not disclose raw private-key bytes to MCP packages.

  • Consider OS-backed key storage or a hardware-backed signing mechanism instead of an unencrypted JSON private key.

  • Pin and verify other executable packages recommended by the generated documentation, including clawrtc.

  • Document that MCP servers execute local code with the user's permissions and that users should review and approve dependency updates before execution.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to execute uvx create-rustchain-agent without pinning an exact version or immutable source. That can cause users to install and run whatever package is current at execution time, increasing supply-chain risk if a malicious or compromised release is published under the same name.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs users to run uvx create-rustchain-agent without pinning an exact package version, which allows whatever the latest published package is at execution time to be installed and run. In a scaffold/init context this is especially risky because the generated tool can create files, inject MCP configuration, and optionally register identities, so a compromised or malicious upstream release could directly affect the developer environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The tool advertises execution via uvx create-rustchain-agent without pinning a specific package version. Because this scaffold generates a wallet containing a private key and configures downstream tooling, an unexpected or compromised newer package release could run attacker-controlled code during installation/execution and immediately access generated secrets or alter the scaffolded files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The generated MCP config runs uvx rustchain-mcp without a pinned version, so future executions may fetch and run whatever package version is current at that time. Since the config also passes the wallet path through RUSTCHAIN_WALLET, a malicious or compromised package update could read the wallet file and exfiltrate the private key or perform unauthorized transactions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The printed setup instruction claude mcp add rustchain -- uvx rustchain-mcp encourages users to register an unpinned MCP server command. In this context, the risk is elevated because the scaffold explicitly creates and stores a cryptocurrency wallet; if the referenced package later becomes malicious or compromised, it could execute with access to that wallet and associated environment/configuration.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: setuptools has 10 known advisory(ies) (CVE-2013-1633 (Setuptools vulnerable to Man-in-the-middle attacks); CVE-2025-47273 (setuptools has a path traversal vulnerability in PackageIndex.download that lead); CVE-2024-6345 (setuptools vulnerable to Command Injection via package URL) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

The build dependency setuptools>=61 is not pinned, so builds may consume different versions over time, including versions with known packaging or download-related vulnerabilities. This is primarily a build-time supply-chain weakness rather than an immediate runtime flaw, but it still matters because compromised build tooling can affect package integrity and developer environments.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: cryptography has 16 known advisory(ies) (GHSA-39hc-v87j-747x (Vulnerable OpenSSL included in cryptography wheels); CVE-2023-50782 (Python Cryptography package vulnerable to Bleichenbacher timing oracle attack); GHSA-537c-gmf6-5ccf (Vulnerable OpenSSL included in cryptography wheels) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The project declares cryptography>=41.0 without an upper bound or exact pin, so dependency resolution may install versions later found to be vulnerable or inconsistent across environments. In a security-sensitive agent scaffold that provisions wallet and MCP-related functionality, leaving a cryptography library version floating increases supply-chain and patch-management risk even if no specific vulnerable version is guaranteed here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.