Commit Graph
11 Commits
Author SHA1 Message Date
clawbot e10ecfc1df fix: add warning styling to contract address display
check / check (push) Successful in 22s
The contract address in AddressToken view was visually indistinguishable
from the wallet address, creating a risk of users sending funds to the
contract address. Changes:

- Red warning border around contract info section
- Warning icon and 'DO NOT send funds to this address' label
- Muted text color for the contract address itself
- Updated README.md with documentation on the safety treatment
2026-02-27 12:17:50 -08:00
clawbot 31b22c1325 style: format README.md and RULES.md with Prettier
check / check (push) Successful in 21s
2026-02-27 11:39:44 -08:00
clawbot eec96f9054 security: clear decrypted secrets after use (best-effort)
check / check (push) Successful in 21s
2026-02-27 11:36:56 -08:00
clawbot f13cd0fd47 security: add TODO comments for password plaintext over runtime.sendMessage 2026-02-27 11:36:19 -08:00
clawbot b478d9efa9 security: validate sender URL for popup-only messages 2026-02-27 11:35:42 -08:00
clawbot d59ebfd461 security: derive RPC origin from sender instead of trusting msg.origin 2026-02-27 11:35:31 -08:00
clawbot 13e2bdb0b0 security: add prominent danger warning for eth_sign requests 2026-02-27 11:35:21 -08:00
clawbot 95314ff229 security: replace predictable sequential approval IDs with crypto.randomUUID() 2026-02-27 11:34:48 -08:00
clawbot 1237cf8491 security: increase minimum password length from 8 to 12 characters 2026-02-27 11:34:32 -08:00
clawbot afc4868001 docs: document Blockscout as third external service in README
check / check (push) Failing after 13s
2026-02-27 03:25:02 -08:00
clawbot a6017ce32c docs: add agent-protection notice to RULES.md 2026-02-27 03:25:01 -08:00