T03 · Remote Payload Retrieval and Execution
- Location
README.md:18- Finding
Mutable Remote Repository Is Cloned and Executed Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not clearly malicious, but it gives an agent real social-posting and wallet powers with under-scoped install, network, and file behaviors that deserve review before use.
Install only if you are comfortable giving the agent its own public Nostr identity and spend-capable wallet. Treat ~/.cocod/config.json and ~/.nostr/secret.key as high-value secrets, avoid funding the wallet until payment confirmations and dependency pinning are improved, and prefer reviewed, pinned installs over the documented GitHub clone or unpinned npx flows.
README.md:18Mutable Remote Repository Is Cloned and Executed Without Integrity Verification
scripts/nostr.js:969Caller-Controlled State Path Allows Arbitrary File Overwrite
scripts/nostr.js:399Attacker-Controlled LNURL Callback Enables Server-Side Request Forgery
install.sh:6Installation and Wallet Commands May Execute Mutable npm Packages
The skill description understates the breadth of capabilities actually exposed, including DMs, relay management, mention processing, and financial operations. Security reviewers and users may consent to a narrow identity bootstrap while unknowingly granting a much broader social and wallet automation surface.
The skill description understates the breadth of capabilities actually exposed, including DMs, relay management, mention processing, and financial operations. Security reviewers and users may consent to a narrow identity bootstrap while unknowingly granting a much broader social and wallet automation surface.
The script reads another application's wallet mnemonic from ~/.cocod/config.json and reuses it to derive a Nostr identity without an explicit consent gate at the point of access. A wallet mnemonic is highly sensitive root secret material; cross-application secret reuse increases blast radius, and compromise or unexpected behavior in this skill can expose both social identity and wallet backup domain together.
The lockfile pins ws to version 8.19.0, which the finding reports as affected by two HIGH severity advisories: an uninitialized memory disclosure and a memory-exhaustion denial of service. In this skill, WebSocket connectivity is part of the Nostr networking stack, so a vulnerable ws library could expose sensitive agent traffic or allow a remote peer/relay to crash or degrade the agent service.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
The README makes a reassuring security claim that the agent never displays or transmits private keys, but later instructs the user to retrieve the mnemonic from a local config file. This contradiction can mislead users about secret-handling behavior and reduce caution around highly sensitive wallet and identity recovery material.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The README states the skill does not read local files, yet other sections explicitly say it pulls profile data from SOUL.md and integrates with HEARTBEAT.md and TOOLS.md. This inconsistency is dangerous because it obscures the skill's actual local-data access, preventing users from accurately assessing privacy exposure and file-trust boundaries.
The skill performs networked actions and accesses persistent local files containing keys and wallet state, but it does not declare any explicit tool scope or permissions boundaries. That makes review, sandboxing, and policy enforcement weaker, increasing the chance the agent invokes sensitive capabilities without the operator realizing the full blast radius.
The skill establishes long-lived credentials and stores a wallet mnemonic in a persistent config file, creating durable compromise impact if the host or agent later reads or leaks those files. Persistence is expected for wallets, but it is still security-sensitive because one secret recovers both the Nostr identity and ecash wallet.
### Step 1: Secure Setup (User Consent Required)
**SECURITY NOTICE:** This skill will create cryptographic keys for your agent. This requires:
- Creating Nostr identity keypair in `~/.nostr/secret.key`
- Creating Cashu wallet with backup seed in `~/.cocod/config.json`
- User must explicitly backup the mnemonic seed phrase
Using npx cocod without pinning a version allows whatever package version is current at execution time to be fetched and run. In a key-management and wallet context, this is especially dangerous because a malicious or compromised upstream release could exfiltrate mnemonics, keys, invoices, or funds.
The unpinned npx cocod invocation executes third-party code in a workflow that handles wallet initialization and sensitive seed material. That creates a supply-chain execution path where upstream changes can alter security behavior without notice.
Using DiceBear with seed=${NPUB} causes the agent's persistent public identifier to be transmitted to an external service. While the key is public, this creates third-party correlation of the identity bootstrap event and ties the agent's profile generation to an external observer.
If skipped, use DiceBear (deterministic, unique per npub):
AVATAR="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}&size=400"
BANNER="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}-banner&size=1500x500"
node {SKILL_DIR}/scripts/nostr.js profile-set '{"picture":"'$AVATAR'","banner":"'$BANNER'"}'
The banner URL similarly transmits a deterministic value derived from the public identifier to a third party, enabling correlation and external logging of profile setup. In a privacy-sensitive identity skill, unnecessary external disclosure should be minimized.
If skipped, use DiceBear (deterministic, unique per npub):
AVATAR="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}&size=400"
BANNER="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}-banner&size=1500x500"
node {SKILL_DIR}/scripts/nostr.js profile-set '{"picture":"'$AVATAR'","banner":"'$BANNER'"}'
Broad natural-language triggers for posting and wallet actions can cause unintended invocation, especially in agents that interpret conversational text opportunistically. In this skill, accidental activation could publish unwanted messages, follow accounts, or initiate financial flows based on ambiguous user phrasing.
The markdown documents direct payment sending but does not require an explicit irreversible-transfer warning or confirmation at the point of execution. In a wallet skill, that omission materially raises the chance of accidental or socially engineered fund loss.
This command path depends on an unpinned external package for payment-related operations. In a financial workflow, dynamic package resolution can turn a documentation command into arbitrary code execution with access to wallet state.
The skill documents balance and wallet operations through unversioned npx cocod calls, exposing users to upstream package compromise. Because these commands interact with a live wallet, the consequences can include fund loss or secret disclosure.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
npx cocod balance
npx cocod receive bolt11 1000 # Create invoice
npx cocod send bolt11 <invoice> # Pay invoice
npx cocod npc address # Lightning address
An unpinned package is used for invoice creation and payment, which are highly sensitive financial actions. If the package changes maliciously or unexpectedly, it could redirect funds, alter invoices, or leak transaction metadata.
Paying invoices through an unpinned npx dependency introduces avoidable supply-chain risk into irreversible financial transfers. In this context, even a brief upstream compromise could directly lead to loss of funds.
Retrieving wallet identity data via unpinned third-party code still exposes sensitive local wallet context to upstream code. In a skill that manages long-lived credentials, this is a meaningful trust-boundary failure.
Detected: suspicious.env_credential_access