Back to skill

Security audit

Agentic Wallet

Security checks for vulnerabilities and agentic risk

Overview

This wallet skill is purpose-aligned but should be reviewed carefully because it repeatedly tells agents to run an unpinned npm wallet tool that may handle passwords, API keys, seed phrases, backups, and funds.

Install only after you are comfortable trusting the `agentic-wallet` npm package and its publisher. Prefer a pinned, reviewed version in an isolated environment, avoid putting real secrets directly in shell commands, secure any secret directory before writing files, independently verify funding addresses before transferring money, and treat seed phrases, wallet backups, password files, and API keys as full wallet-control secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:10
Finding

Unpinned npm Package Execution in Security-Sensitive Wallet Workflows

Content
View full analysis
`. No global installation required. ``` ```bash npx agentic-wallet providers --json ``` ### Technical Analysis The skill directs agents to run the unversioned `agentic-wallet` npm package through `npx`. No exact version, lockfile, integrity hash, verified local installation, or package provenance check is specified. Depending on the local npm and `npx` configuration, the command can download and execute the package currently published under that name. Consequently, the effective executable payload can change after this skill has been reviewed. This creates a supply-chain trust boundary between the audited skill documentation and the externally maintained npm package. The risk is particularly significant because subsequent documented commands handle cryptocurrency wallets, recovery seed phrases, wallet encryption passwords, backup files, and Crossmint server API keys. npm package code and applicable installation lifecycle scripts execute with the permissions of the user running `npx`. There is no evidence in the reviewed file that the current `agentic-wallet` package is malicious. The vulnerability is the unsafe, unpinned execution model and the absence of controls that ensure future executions use the reviewed artifact. ### Attack Path 1. An attacker compromises the npm publisher account, package repository, release process, or another component of the package supply chain. 2. The attacker publishes a malicious version under the existing `agentic-wallet` package name. 3. An agent follows `SKILL.md` and executes an unversioned command such as `npx agentic-wallet providers --json`. 4. `npx` retrieves or resolves the attacker-controlled release. 5. Package code or installation lifecycle scripts execute wit ...[truncated 1141 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:101
Finding

Secret Files Are Secured Only After Creation

Content
View full analysis
~/.secrets/wallet-pw.txt chmod 600 ~/.secrets/wallet-pw.txt ``` ```bash echo "your-crossmint-server-api-key" > ~/.secrets/crossmint-key.txt chmod 600 ~/.secrets/crossmint-key.txt ``` ### Technical Analysis The documented workflow creates each secret file through shell redirection and applies restrictive mode `0600` only afterward. When the destination file does not already exist, its initial permissions are determined by the process umask. Under a common umask of `022`, a newly created file can initially receive mode `0644`. This creates a time-of-check and time-of-use exposure window between file creation and the subsequent `chmod`. Another local user or process may be able to read the file during that interval. The parent directory's permissions may reduce exploitability, but the instructions neither create the directory securely nor verify that it is mode `0700`. The examples also encourage placing the actual password or API key directly in the shell command. If users replace the placeholders with real credentials, those credentials may be retained in shell history, terminal logging, process auditing, or session-recording systems. ### Attack Path 1. The victim replaces the placeholder with a real wallet password or Crossmint server API key. 2. The victim runs the documented `echo` command. 3. Shell redirection creates the new file according to the current umask, potentially as a locally readable `0644` file. 4. Before the following `chmod 600` completes, a local attacker monitoring the directory opens and reads the file. 5. Alternatively, the attacker obtains the command from shell-history files, terminal logs, or system auditing records. 6. The attacker uses the recovered password to acc ...[truncated 1100 chars]
Remediation
View remediation
~/.secrets/wallet-pw.txt unset wallet_password ``` 4. Apply the same procedure to API keys and ensure the secret is not followed by an unintended newline if the consuming application treats it as significant. 5. Disable or temporarily suspend shell history while accepting secrets if interactive secure input is unavailable. 6. Verify both the parent directory and secret-file permissions before invoking the wallet CLI. 7. Prefer an operating-system credential store, secret manager, or ephemeral file descriptor where supported. 8. Document secure deletion and credential rotation procedures for files that are no longer required. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (33)

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill repeatedly instructs agents to execute npx agentic-wallet without pinning an exact package version. npx will resolve the latest published package at execution time, so a compromised maintainer account, malicious update, or dependency hijack could cause arbitrary code execution on the host and expose wallet material, API keys, or funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command uses npx agentic-wallet without a pinned version, allowing runtime retrieval of whatever package version is current on npm. In a wallet-management skill, that increases risk substantially because the fetched code may handle secrets, addresses, API keys, and signing flows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The setup flow invokes an unpinned npm package via npx, which is effectively remote code execution from a mutable registry artifact. Because this specific command creates wallets and may initialize credentials, compromise here could directly lead to wallet takeover or secret exfiltration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This non-interactive wallet setup example executes npx agentic-wallet without version pinning while also referencing a password file. That combination is especially dangerous because a malicious package version could silently read local secret files and transmit them off-host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The Crossmint non-interactive setup example fetches and runs an unpinned package despite requiring an API key file. If the npm package or one of its dependencies were compromised, the attacker could harvest server-side API keys and create or control wallets.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

bash
# --- OpenWallet (self-custody) ---
echo "your-strong-password" > ~/.secrets/wallet-pw.txt
chmod 600 ~/.secrets/wallet-pw.txt

npx agentic-wallet setup \
  --provider openwallet \

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This setup example again relies on an unpinned npx invocation in an autonomous-agent context. In context, that is more dangerous than a normal CLI example because the workflow encourages unattended execution with local secret files present.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
# --- Crossmint (custodial, no browser needed) ---
echo "your-crossmint-server-api-key" > ~/.secrets/crossmint-key.txt
chmod 600 ~/.secrets/crossmint-key.txt

npx agentic-wallet setup \
  --provider crossmint \

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

An unpinned npx package is executed in a non-interactive API-key-based workflow. This raises a direct supply-chain risk where compromised package contents could capture API keys, alter wallet configuration, or redirect funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Even read-oriented commands like balance still execute arbitrary package code when invoked via unpinned npx. In a wallet skill, that code can enumerate local wallet records, scrape environment variables, and exfiltrate sensitive metadata.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This provider-specific balance command is still an unpinned runtime package execution. While presented as harmless status checking, it grants full code execution to mutable third-party package contents.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The filtered-balance example uses the same unpinned npx pattern. The context remains sensitive because the command operates in environments likely to have wallet files and credentials available.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The status command is documented with unpinned npx, exposing users to supply-chain compromise even for seemingly low-risk authentication checks. A malicious package can still run arbitrary code and inspect local state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This provider-specific status invocation uses the same mutable npx fetch-and-execute model. Because the skill is for wallet operations, even authentication status checks occur in a high-value environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The fund example executes an unpinned npm package to retrieve wallet funding instructions. If compromised, the tool could return attacker-controlled deposit addresses, causing direct loss of funds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents backup and seed-phrase recovery workflows but does not prominently warn that backup files, password files, and especially seed phrases are equivalent to wallet control material. In a crypto-wallet context, insufficient warning materially increases the chance that operators will store, transmit, or log these artifacts insecurely, leading to irreversible fund theft.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The backup command uses unpinned npx in a flow that handles encrypted wallet backups and password files. A malicious package version could copy backup material or capture the backup password, defeating the intended encryption.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The recovery-from-backup command runs mutable npm code in a workflow that processes backup files and decryption passwords. Compromise here could steal restored key material or alter recovery behavior to redirect wallet ownership.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Seed-phrase recovery via an unpinned npx package is particularly dangerous because the command will handle the highest-sensitivity wallet secret. Any supply-chain compromise could directly expose the seed phrase and permanently compromise funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The schema command is less sensitive operationally, but it still relies on unpinned npx execution and therefore inherits arbitrary code execution risk. In the context of a wallet skill, any execution environment may contain useful secrets or wallet files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This specific schema setup example is still an unpinned package fetch and execute. Although lower impact than backup/recovery, it unnecessarily exposes users to the same supply-chain attack surface.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The workflow step to list providers invokes the package without version pinning, normalizing unsafe execution patterns. Since this appears in the standard workflow, it amplifies exposure by encouraging repeated execution in production-like environments.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

text
1. CHECK     → npx agentic-wallet providers --json
2. CREATE    → npx agentic-wallet setup --provider openwallet --name my-agent --json
3. VERIFY    → npx agentic-wallet balance --all --json
4. FUND      → npx agentic-wallet fund --provider openwallet --json
5. USE       → Make payments via x402 or MPP using wallet address

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The standard workflow explicitly tells agents to create wallets using unpinned npx code. That is high risk because wallet initialization is a privileged step where compromise can taint all future wallet usage and secret handling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The verification step uses unpinned runtime package execution, continuing the insecure pattern in the core workflow. Attackers could exploit this to scrape wallet metadata or tamper with balance reporting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.