AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 41 Monero

Add verbose logging setting

Public commit record

What the developer wrote

Authored by Keeqler

35/100 · Opaque
Add verbose logging setting
✓ Descriptive subject! No meaningful explanatory body
The short version

What changed, and why it matters

This commit adds an optional 'Verbose Logging' setting to the Skylight Wallet app. When enabled, the app writes detailed logs of wallet operations to a plain text file stored in the app's data folder. The logs include sensitive details such as wallet addresses, transaction destinations, amounts, daemon/proxy addresses, and some API responses. The setting is off by default and must be manually enabled by the user. The main risk is that a user who turns this on may later share the log file with a support person or expose it through a backup, accidentally leaking private wallet activity. The commit itself does not appear to be malicious; it is a debugging feature, but it increases the app's overall sensitivity to data exposure.

Recommended action

Treat this as a defensive review note rather than a critical vulnerability. If maintaining or auditing this app, verify that: (1) the verbose log file is excluded from cloud backups and device backups via Android `allowBackup`/iOS `NSFileProtection` or `excludeFromBackup` keys; (2) the settings screen warns users not to share logs without inspecting them for addresses/transaction details; (3) logs are rotated and deleted securely; (4) no future commit logs private keys, seeds, or passwords; and (5) support workflows sanitize or encrypt logs before transmission. End users should only enable verbose logging when instructed and should delete logs afterward.

Security signals we found

01

New opt-in verbose logging toggle writes wallet operation details to a persistent plaintext file in app data storage

02

Logged data includes Monero addresses, transaction destinations/amounts, daemon/proxy addresses, fiat API responses, and FFI pointer addresses

03

Log file is stored in app-accessible external/documents storage on Android, increasing exposure via backups, ADB, or rooted-device access

04

Info-level logs are gated by the verbose setting, but the same file is written once verbose logging is enabled

05

Log retention is capped at 30 days via mtime-based deletion at startup

06

Sensitive credentials (mnemonic, password) are explicitly redacted in the added log statements

07

No encryption, access controls, or in-app warning about log contents are added in this commit

Risk score

Why this scored 41/100

Our methodology →
Potential impact 8/30
Exploitability 6/25
Stealth signal 7/15
Affected reach 9/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.