T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/play-blinko.js:45- Finding
Autonomous Real-Fund Spending Without Per-Transaction Approval or Cumulative Limits
- Content
View full analysis
MAX_BET) { throw new Error(`Bet out of range (0.0001-0.1 ETH). Got: ${betEth}`); } // ... const tx1 = await contract.createGame(params, serverSig, ethers.randomBytes(32), { value: betWei }); console.log(`⛓️ createGame tx: ${tx1.hash}`); await tx1.wait(); ``` ### Technical Analysis The Skill loads `WALLET_PRIVATE_KEY` and uses it to sign and broadcast a payable transaction without requesting per-transaction user confirmation. Although each individual bet is constrained to between 0.0001 and 0.1 ETH, no cumulative, daily, session, invocation-count, or gas-spending limit is enforced. The declared ability for agents to invoke the Skill autonomously expands possession of the environment variable into direct authority to spend wallet funds. This exceeds a least-privilege design because checking statistics does not require transaction-signing authority, and even the gameplay function does not technically require unrestricted repeated authorization. The script also defaults to a 0.001 ETH bet if no amount is supplied, meaning an accidental or incomplete invocation can still initiate a ...[truncated 1406 chars]- Remediation
View remediation
