Back to skill

Security audit

EVM Crypto Wallet for Your Agent

Security checks for vulnerabilities and agentic risk

Overview

This wallet skill has a clear purpose, but it installs unpinned remote code for high-impact crypto actions and includes a risky token-address error.

Review this skill carefully before installing. Do not fund the wallet with meaningful value unless the implementation is pinned to a reviewed commit or bundled in the artifact, dependencies are locked and verified, token addresses are corrected against authoritative sources, and signing operations require clear per-transaction confirmation. Treat ~/.evm-wallet.json as a real private key: anyone or any code that can read it can take the funds.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:37
Finding

Unpinned Remote Wallet Code Is Retrieved and Executed

Content
View full analysis
/dev/null rm -rf /tmp/evm-wallet-tmp cd "$SKILL_DIR" && npm install fi ``` The update instructions provide another mutable execution path: ```bash node src/check-update.js --json ``` ```bash cd "$SKILL_DIR" && git pull && npm install ``` ### Technical Analysis The installation procedure clones the repository's mutable default branch and immediately runs `npm install`. Neither a reviewed commit hash nor a signed release, checksum, or other integrity constraint is specified. The update procedure similarly runs `git pull` and reinstalls dependencies without verifying the resulting source. This is a remote payload execution boundary: the effective wallet implementation can change after the Skill document has been reviewed. In addition, `npm install` may execute lifecycle scripts supplied by the downloaded project or its dependencies. The supplied audit artifact contains only `SKILL.md`; it does not include the downloaded wallet source, package manifest, or lockfile. Therefore, the behavior of wallet generation, private-key handling, RPC communication, transaction construction, and dependency installation cannot be independently verified from the audited artifact. ### Attack Path 1. An attacker compromises the upstream repository, a maintainer account, release process, or dependency chain. 2. The attacker adds malicious wallet code or an npm lifecycle script to the mutable branch or dependency graph. 3. An agent follows the documented bootstrap or update instructions. 4. `git clone` or `git pull` retrieves the attacker-c ...[truncated 1177 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:174
Finding

Incorrect Ethereum USDC Contract Address Can Cause Unintended Contract Interaction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The installation instructions delete a temporary directory with 'rm -rf /tmp/evm-wallet-tmp'. While the path is specific, recursive forced deletion in agent-executed setup logic is risky because path confusion, symlink attacks, or variable/path manipulation in adjacent steps could cause unintended file deletion, especially in multi-user or compromised environments.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

git clone https://github.com/surfer77/evm-wallet-skill.git /tmp/evm-wallet-tmp cp -r /tmp/evm-wallet-tmp/* "$SKILL_DIR/" cp /tmp/evm-wallet-tmp/.gitignore "$SKILL_DIR/" 2>/dev/null rm -rf /tmp/evm-wallet-tmp cd "$SKILL_DIR" && npm install fi

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The installation instructions delete a temporary directory with 'rm -rf /tmp/evm-wallet-tmp'. While the path is specific, recursive forced deletion in agent-executed setup logic is risky because path confusion, symlink attacks, or variable/path manipulation in adjacent steps could cause unintended file deletion, especially in multi-user or compromised environments.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

git clone https://github.com/surfer77/evm-wallet-skill.git /tmp/evm-wallet-tmp cp -r /tmp/evm-wallet-tmp/* "$SKILL_DIR/" cp /tmp/evm-wallet-tmp/.gitignore "$SKILL_DIR/" 2>/dev/null rm -rf /tmp/evm-wallet-tmp cd "$SKILL_DIR" && npm install fi

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill is explicitly designed to create and persist a locally stored EVM private key, enabling the agent to perform financial actions across sessions. Persisting wallet credentials substantially raises risk because compromise of the host, logs, backups, or agent tool access can lead directly to unauthorized transfers and irreversible loss of funds.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: evm-wallet-skill
description: Self-sovereign EVM wallet for AI agents. Use when the user wants to create a crypto wallet, check balances, send ETH or ERC20 tokens, swap tokens, or interact with smart contracts. Supports Base, Ethereum, Polygon, Arbitrum, and Optimism. Private keys stored locally — no cloud custody, no API keys required.
metadata: {"clawdbot":{"emoji":"💰","homepage":"https://github.com/surfer77/evm-wallet-skill","requires":{"bins":["node","git"]}}}
---

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
Returns: `{ "success": true, "address": "0x..." }`

The private key is stored at `~/.evm-wallet.json` (chmod 600). **Never share this file.**

## Commands

Static analysis

No suspicious patterns detected.