starknet-anonymous-wallet
Warn
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/watch-events-smart.jsuses system commands to modify thecrontabfor persistent task scheduling. - [CREDENTIALS_UNSAFE]: Starknet private keys are generated and stored in the local filesystem at
~/.openclaw/secrets/starknetbyscripts/create-account.js. - [PROMPT_INJECTION]:
scripts/parse-smart.jscontains an advanced multi-layered protection system using regular expressions and thevardsafety library to detect malicious prompt patterns and authorization bypasses. - [DATA_EXFILTRATION]:
scripts/watch-events-smart.jscan send data to external webhooks, creating a potential path for data exfiltration.
Audit Metadata