スキル starknet-wallet
📦

starknet-wallet

v1.0.0 コンテンツリビジョン r2 高リスク 🔑 環境変数⚙️ 外部コマンド🌐 ネットワークアクセス📁 ファイルシステムへのアクセス

Starknetウォレット操作を管理

Starknetのウォレットワークフローでは、アカウント、トークン、RPCを正確に扱う必要があります。このスキルは、残高確認、送金、コントラクト呼び出し、セッションキーのパターンをガイドします。

対応: Claude Codex Code(CC)
⚠️ 38 不十分

自分のエージェントでインストール

このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。

エージェントリクエスト
Review the Skillstore skill "starknet-wallet" from https://skillstore.io/skills/internet-court-starknet-wallet.md and its manifest at https://skillstore.io/api/skills/internet-court-starknet-wallet/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。

エージェントが読めるリソース

AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。

テストする

「starknet-wallet」を使用しています。 StarknetウォレットのSTRK残高を確認してください。

期待される結果:

回答では、ウォレットアドレス、トークンシンボル、トークンコントラクト、整形済み残高、未加工の残高、整形に使用した小数点以下桁数を特定します。

「starknet-wallet」を使用しています。 承認済みの受取人に25 USDCをガスレス送金する計画を作成してください。

期待される結果:

回答では、受取人、トークン、金額、paymasterオプション、手数料トークン、必要な確認事項、および実行前の確認要求を一覧にします。

「starknet-wallet」を使用しています。 サポートエージェントウォレット用のセッションキーポリシーを作成してください。

期待される結果:

回答では、許可するコントラクト、許可するメソッド、トランザクションごとの上限、合計支出上限、有効期限、失効手順を提案します。

セキュリティ監査

高リスク

Most static findings are false positives caused by documentation links, Markdown or TypeScript template literals, and standard configuration reads. Private signing-key and paymaster-key handling are confirmed high-risk credential practices, and the skill also enables autonomous asset operations through transfers, contract calls, swaps, and session keys.

8
スキャンされたファイル
938
解析済み行数
7
レビュー項目
0
誤検知を無視

確認済みのセキュリティ上の懸念 (2)

高
Environment file access
signer: process.env.STARKNET_PRIVATE_KEY,
The skill requires a private signing key or paymaster API key through environment configuration. Exposure of these credentials can authorize asset transfers or consume paid services, although no exfiltration is shown here.
高
Agent-Controlled Asset Operations
The skill instructs an agent to transfer tokens, invoke state-changing contracts, execute swaps, and use session keys for autonomous operations. Misconfiguration or prompt compromise could therefore move wallet assets without per-action human approval.
The cited sections explicitly document state-changing wallet operations and autonomous session-key execution. The risk follows from the stated capability and does not depend on a heuristic pattern.
機能レビュー項目 (7)

これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。

高
Generic API/secret keys
STARKNET_PRIVATE_KEY=0x...
The skill requires a private signing key or paymaster API key through environment configuration. Exposure of these credentials can authorize asset transfers or consume paid services, although no exfiltration is shown here.
高
Environment variable access (dot notation)
signer: process.env.STARKNET_PRIVATE_KEY,
The skill requires a private signing key or paymaster API key through environment configuration. Exposure of these credentials can authorize asset transfers or consume paid services, although no exfiltration is shown here.
高
Environment variable object
signer: process.env.STARKNET_PRIVATE_KEY,
The skill requires a private signing key or paymaster API key through environment configuration. Exposure of these credentials can authorize asset transfers or consume paid services, although no exfiltration is shown here.
高
Generic API/secret keys
STARKNET_PRIVATE_KEY=0x...
The skill requires a private signing key or paymaster API key through environment configuration. Exposure of these credentials can authorize asset transfers or consume paid services, although no exfiltration is shown here.
高
Generic API/secret keys
AVNU_PAYMASTER_API_KEY=your_key (optional, for free gas)
The skill requires a private signing key or paymaster API key through environment configuration. Exposure of these credentials can authorize asset transfers or consume paid services, although no exfiltration is shown here.
高
Generic API/secret keys
signer: process.env.STARKNET_PRIVATE_KEY,
The skill requires a private signing key or paymaster API key through environment configuration. Exposure of these credentials can authorize asset transfers or consume paid services, although no exfiltration is shown here.
高
Generic API/secret keys
| `STARKNET_PRIVATE_KEY` | Agent's signing key | Required |
The skill requires a private signing key or paymaster API key through environment configuration. Exposure of these credentials can authorize asset transfers or consume paid services, although no exfiltration is shown here.

リスク要因

🔑 環境変数 (34)
⚙️ 外部コマンド (50)
🌐 ネットワークアクセス (14)
📁 ファイルシステムへのアクセス (3)
監査者: codex 監査履歴を表示 →
このレポートを共有・引用

バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。

バージョン別レポートを開く
セキュリティ評価

レポートリンクをコピー

https://skillstore.io/skills/internet-court-starknet-wallet/audits/3?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdownバッジ

[![Skillstore security assessment](https://skillstore.io/badges/skills/internet-court-starknet-wallet/security.svg)](https://skillstore.io/skills/internet-court-starknet-wallet?utm_source=security_passport_badge)

HTMLバッジ

<a href="https://skillstore.io/skills/internet-court-starknet-wallet?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/internet-court-starknet-wallet/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

埋め込みカード

<iframe src="https://skillstore.io/embed/skills/internet-court-starknet-wallet.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
学術引用 (APA · BibTeX · CFF)

APA形式の引用

internet-court. (2026). starknet-wallet security audit report (audit version 3) [Author version 1.0.0]. Skillstore. https://skillstore.io/skills/internet-court-starknet-wallet/audits/3

BibTeX形式の引用

@techreport{internet-court-internet-court-starknet-wallet-2026, author = {internet-court}, title = {starknet-wallet security audit report (audit version 3)}, institution = {Skillstore}, year = {2026}, number = {3}, url = {https://skillstore.io/skills/internet-court-starknet-wallet/audits/3}, note = {Author version 1.0.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "starknet-wallet security audit report (audit version 3)" version: "1.0.0" type: report authors: - name: "internet-court" date-released: "2026-08-07" url: "https://skillstore.io/skills/internet-court-starknet-wallet/audits/3" identifiers: - type: other value: "skillstore:internet-court-starknet-wallet:audit:3" description: "Skillstore immutable audit report identifier"

Skillstore スコア

このスコアの理由 証拠の信頼度: 中
45
アーキテクチャ
100
保守性
87
コンテンツ
67
コミュニティ
83
仕様準拠

作成できるもの

エージェントウォレットのワークフローを構築

Starknetエージェントウォレット向けに、残高確認、送金、コントラクト呼び出しのフローを作成します。

トークン残高を監視

ウォレット操作を実行する前に、ETH、STRK、USDC、USDTの残高を確認します。

セッションキーポリシーを設計

エージェントの自律性のために、支出上限、有効期限ルール、許可するコントラクトメソッドを定義します。

これらのプロンプトを試す

ウォレット残高を確認
Starknet wallet skillを使用して、このアカウントアドレスのETH残高を確認してください。トークンアドレス、整形済み金額、未加工の金額を説明してください。
バッチ残高を確認
このStarknetアカウントのETH、STRK、USDC、USDTの残高を確認してください。ゼロ以外の残高を要約し、使用したクエリ方法を説明してください。
安全な送金計画を準備
この受取人と金額に対するSTRK送金計画を準備してください。入力を検証し、手数料を見積もり、状態を変更するアクションの前に明示的な確認を求めてください。
エージェントのセッションキーを設計
承認済みアドレスにのみ限られたUSDCを送金できるエージェントのセッションキーポリシーを設計してください。支出上限、有効期限、失効、監視ルールを含めてください。

ベストプラクティス

  • 状態を変更するすべてのトランザクションの前に、明示的なユーザー確認を必須にします。
  • 支出上限と有効期限を持つ最小権限のセッションキーを使用します。
  • 秘密鍵をプロンプト、ログ、リポジトリ、共有ファイルに含めないでください。

回避

  • 長期間有効な秘密鍵を、コミット済みまたは共有の環境ファイルに保存しないでください。
  • エージェントが制御するウォレットに無制限の支出承認を与えないでください。
  • 受取人確認、手数料レビュー、シミュレーションなしにmainnet送金を実行しないでください。

よくある質問

このスキルだけでウォレットを作成できますか?
ウォレット操作に関するガイダンスと例を提供します。実際のアカウント作成は、設定済みのStarknetツールと署名者に依存します。
トークンを送信できますか?
はい。このスキルはトークン送金ワークフローを文書化しています。送金を実行する前には、明示的な確認を必須にする必要があります。
ガスレス取引をサポートしていますか?
はい。AVNUおよびStarknet account abstractionパターンを通じた、paymasterベースのガス処理について説明します。
どのシークレットが必要ですか?
状態を変更する操作には、通常、署名認証情報が必要です。可能な場合は、安全なシークレットストアまたは権限を制限したセッションキーを使用してください。
複数のトークン残高を一度に確認できますか?
はい。複数のトークンシンボルまたはコントラクトアドレスに対応するバッチ残高パターンが含まれています。
これはスマートコントラクト監査ツールですか?
いいえ。ウォレット操作とコントラクト連携はサポートしますが、コントラクトの安全性を監査するものではありません。

開発者情報

作成者

internet-court

ライセンス

Apache-2.0

作者バージョン

v1.0.0

Skillstore リビジョン

r2

バージョンに関する注意

インストール可能な内容は変更されましたが、作者は宣言バージョンを更新していません。

参照

1c2ebded2116f8124f45dba86a2e567f56e64d8e

メンテナンスの新しさ

2026/8/8

利用状況

5 ダウンロード · 0 閲覧

ファイル構成

internet-court のその他のスキル

すべて表示
すべて表示
📦

information-security-manager-iso27001

84

ISO 27001セキュリティガバナンスの実装

作成者 davila7

HealthcareおよびMedTechチームには、リスク、管理策、インシデント、監査を結び付ける体系的なISO 27001セキュリティプログラムが必要です。このスキルは、ISO 27001およびISO 27002を使用して、ISMS計画、リスクアセスメント、管理策の選定、認証準備を支援します。

セキュリティ&コンプライアンス 表示