Back to skill

Security audit

Tyrpay Seller Skill

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill describes a TyrPay seller payment workflow and its sensitive credentials are purpose-aligned, though users should handle keys and dependencies carefully.

Before installing, treat all wallet private keys, storage private keys, Reclaim secrets, and model API keys as high-value secrets; keep them out of version control and logs, use trusted package names and pinned versions where possible, and run the seller workflow only in an environment intended to sign TyrPay settlement transactions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned and Unspecified Runtime Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13 and 76-79
Vulnerability Type: Supply-chain risk caused by unpinned third-party dependencies
Risk Level: Medium

Vulnerable Snippets

SKILL.md:13:

markdown
1. Install `@tyrpay/seller-skill`, `@tyrpay/seller-sdk`, a storage adapter, and a zkTLS adapter.

SKILL.md:76-79:

markdown
- `ReclaimZkTlsAdapter` needs `@reclaimprotocol/zk-fetch`,
  `@reclaimprotocol/js-sdk`, credentials, and downloaded zk resources. Install
  those optional peer dependencies in the runtime that constructs the adapter.
  Windows runtimes must keep Reclaim TEE mode disabled.

Technical Analysis

The installation instructions require executable third-party packages without specifying exact versions, integrity hashes, a lockfile, or a verification procedure. The storage and zkTLS adapter package names are also not fully specified. Consequently, installations performed at different times can resolve to different code, and users may inadvertently select an untrusted or similarly named adapter.

Because these dependencies execute inside the seller runtime, they may inherit access to sensitive application state, including the seller signer, wallet credentials, storage credentials, Reclaim credentials, model API keys, proof material, and blockchain transaction capabilities. The audited artifact contains only documentation and metadata, so the implementation and security properties of the instructed dependencies could not be verified from this package.

Attack Path

  1. An attacker compromises a referenced package release, publishes a malicious future version, or distributes a similarly named storage or zkTLS adapter.
  2. A user follows the documented installation instructions without version or integrity constraints.
  3. The package manager resolves and installs the attacker-controlled dependency.
  4. Malicious installation or runtime code executes within ...[truncated 918 chars]
Remediation
View remediation

Remediation Suggestions

  1. Specify the exact audited package name and version for every SDK, storage adapter, zkTLS adapter, and optional peer dependency.
  2. Publish and maintain a lockfile that records the complete transitive dependency graph.
  3. Enforce package integrity through registry checksums, signed provenance, or verified release artifacts.
  4. Document the trusted package registry and explicitly reject similarly named or unofficial adapters.
  5. Review package lifecycle scripts before installation and disable them during initial assessment where operationally possible.
  6. Run dependency vulnerability and provenance scanning in CI, including checks for lockfile changes and newly introduced maintainers or packages.
  7. Audit each adapter before production deployment, particularly code that can access signers, credentials, proof data, network requests, or transaction submission.
  8. Isolate third-party adapters using least-privilege processes or containers, and provide only the credentials and network access required for their specific function.
  9. Rotate wallet, storage, Reclaim, and model-provider credentials if an unverified dependency has already been executed in a privileged seller runtime.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file instructs users to copy secrets such as SELLER_PRIVATE_KEY, ZERO_G_STORAGE_PRIVATE_KEY, RECLAIM_APP_SECRET, and MODEL_API_KEY into a .env file, but it does not include any warning about protecting these credentials, avoiding commits, or limiting exposure. Because the file is a markdown reference that describes handling private keys and API secrets, a basic user-facing warning about credential sensitivity is expected under the missing-warning criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The markdown states that ReclaimZkTlsAdapter needs credentials, but it does not include any caution about securely storing or handling those credentials. Because this skill description covers setup and operational behavior, omitting even a brief warning about credential sensitivity is a missing user warning relevant to privacy and system integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.