Skip to main content

emblem-ai-agent-wallet

EmblemAI Agent Wallet enables seamless management of multi-chain crypto wallets with operator-controlled actions and review-first workflows.

Install this skill

or
54/100

Security score

The emblem-ai-agent-wallet skill was audited on Apr 1, 2026 and we found 8 security issues across 3 threat categories, including 1 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

medium line 11

Access to hidden dotfiles in home directory

SourceSKILL.md
11openclaw: '{"emoji":"🛡️","requires":{"bins":["node","npm","emblemai"]},"config_paths":["~/.emblemai/active-profile","~/.emblemai/profiles/"],"install":[{"id":"npm","kind":"npm","package":"@emblemvaul
medium line 125

Access to hidden dotfiles in home directory

SourceSKILL.md
125**Fail closed rule:** if more than one profile exists in `~/.emblemai`, every `--agent` invocation must include `--profile <name>`. Agent mode never guesses which wallet identity to use.
medium line 145

Access to hidden dotfiles in home directory

SourceSKILL.md
1452. Stored encrypted password in `~/.emblemai/profiles/<name>/.env` and `.env.keys`
medium line 167

Access to hidden dotfiles in home directory

SourceSKILL.md
167- **Never use `rm -rf ~/.emblemai` as a logout step.**
medium line 145

Access to .env file

SourceSKILL.md
1452. Stored encrypted password in `~/.emblemai/profiles/<name>/.env` and `.env.keys`
medium line 170

Access to .env file

SourceSKILL.md
170- The auto-generated password stored in `.env` and `.env.keys` is the only key to that wallet. If those files are lost without backup, the wallet is unrecoverable.
high line 162

Prompting for password/secret input

SourceSKILL.md
1624. Terminal password prompt
low line 10

External URL reference

SourceSKILL.md
10homepage: https://emblemvault.dev
Scanned on Apr 1, 2026
View Security Dashboard
Installation guide →