T09 · Insecure Skill Coding Practices
- Location
scripts/musashi-core/internal/storage/og_storage.go:90- Finding
Wallet Private Key Exposed Through Child Process Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/musashi-core/internal/storage/og_storage.go:90-96
Vulnerability Type: Sensitive credential exposure through command-line arguments
Risk Level: HighVulnerable Code
go out, err := runCLI("upload", "--url", c.rpcURL, "--key", c.privateKey, "--indexer", c.indexer, "--file", filePath, )The value of
c.privateKey, sourced fromOG_CHAIN_PRIVATE_KEY, is passed directly to0g-storage-clientthrough the--keycommand-line argument.Technical Analysis
Process command-line arguments are not an appropriate secret-transport mechanism. Depending on the operating system and security configuration, process arguments may be observable through process inspection interfaces, monitoring software, audit logs, diagnostic tools, crash reports, or container orchestration telemetry.
Although
exec.Commandsafely separates arguments and does not introduce shell injection, it places the complete private key in the child process argument vector for the duration of the upload. This exposure is unnecessary because the key only needs to be provided securely to the storage client.The key is also the same
OG_CHAIN_PRIVATE_KEYused by the project to sign on-chain operations. Consequently, compromise is not limited to evidence storage.Attack Path
- A user configures publish mode by setting
OG_CHAIN_PRIVATE_KEY. - The Skill reaches the evidence-storage step after the user approves publishing.
UploadFilelaunches0g-storage-clientwith the private key as the value of--key.- A local process, monitoring component, or administrator with permission to inspect process arguments captures the argument vector while the upload is running.
- The observer extracts the private key.
- The recovered key is imported into another wallet or signing program.
- The attacker signs arbitrary transactions permitted by the compromised w ...[truncated 993 chars]
- A user configures publish mode by setting
- Remediation
View remediation
Remediation Suggestions
- Do not pass private keys through command-line arguments.
- Use a supported secure input mechanism, in this order of preference:
- Integrate the official 0G Storage library directly and sign in process.
- Pass the key through a dedicated inherited file descriptor.
- Use standard input if the client explicitly supports non-interactive secret input.
- Use an OS keyring, hardware signer, or external signing service.
- Use a narrowly scoped environment variable only if the client supports it and the deployment prevents environment inspection.
- Use a separate, least-privileged storage-signing key rather than reusing the chain wallet key where the platform permits it.
- Ensure errors, debug logs, and child-process output never contain the key.
- Add an automated test that inspects the generated child-process arguments and fails if any secret value is present.
- Rotate the configured wallet key after deploying the fix if the affected publish path has previously been used on a system where process arguments may have been logged or observed.
