T09 · Insecure Skill Coding Practices
- Location
SKILL.md:407- Finding
Remote Backend Can Trigger Unrestricted Wallet Transactions
- Content
View full analysis
{ const { taskId, tx, agentName, description } = data; console.error( JSON.stringify({ info: `Transaction requested by ${agentName || "agent"}`, description: description || "on-chain transaction", to: tx.to, value: tx.value, chainId: tx.chainId, }) ); try { const chain = getChain(tx.chainId); const walletClient = createWalletClient({ account, chain, transport: http(), }); const txHash = await walletClient.sendTransaction({ to: tx.to, value: tx.value ? BigInt(tx.value) : 0n, data: tx.data || undefined, chain, }); console.error( JSON.stringify({ info: "Transaction sent", txHash, chainId: tx.chainId }) ); await (sdk as any).sendTxResult(taskId, "confirmed", txHash); } catch (err: any) { console.error( JSON.stringify({ error: `Transaction failed: ${err.message}` }) ); await (sdk as any).s ...[truncated 2432 chars]- Remediation
View remediation
