Back to skill

Security audit

2Captcha

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed 2Captcha command-line helper, with ordinary but important privacy and supply-chain cautions.

Install only if you intend to send CAPTCHA content and related page metadata to 2Captcha and its human solvers. Prefer the reviewed bundled script or a pinned commit/release, keep the API key scoped to 2Captcha, avoid sensitive or internal pages unless approved, and skip sudo/global installation unless you specifically need it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party Installation Sources Can Execute Unaudited Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:28-34 and README.md:34-42
Vulnerability Type: Supply-chain risk through mutable, unpinned installation sources
Risk Level: Medium

Vulnerable Code

SKILL.md:28-34:

bash
# Install this agent skill with skills.sh
npx skills add adinvadim/2captcha-cli

# Or install with ClawHub/OpenClaw
openclaw skills install 2captcha

# Install the CLI after reviewing the source
git clone https://github.com/adinvadim/2captcha-cli.git

README.md:34-42:

bash
# skills.sh: Codex, Claude Code, Cursor, and other supported agents
npx skills add adinvadim/2captcha-cli
npx skills add adinvadim/2captcha-cli --global
npx skills add adinvadim/2captcha-cli --agent codex
npx skills use adinvadim/2captcha-cli@2captcha

# OpenClaw / ClawHub
openclaw skills install 2captcha
clawhub install 2captcha

Technical Analysis

The documented installation procedures retrieve components from npm-backed tooling, skill registries, and the default branch of a Git repository without pinning immutable package versions, release artifacts, or Git commit hashes. No checksum or signature verification is prescribed.

Consequently, the code installed by a user at a later date may differ from the artifact reviewed in this audit. If an upstream account, package, registry entry, repository, or distribution channel is compromised, an attacker could replace the effective installation payload while retaining the expected project name.

This finding concerns the installation guidance rather than malicious behavior in the audited solve-captcha executable. The executable's Base64 image encoding and communication with https://api.2captcha.com are consistent with its declared CAPTCHA-solving function and are explicitly disclosed in the documentation.

Attack Path

  1. An attacker compromises an upstream maintainer account, repository, package, or skill-registry entry.

...[truncated 1194 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin npm-based installer packages to exact reviewed versions rather than relying on the latest package resolution.
  2. Pin skill installations to immutable, versioned releases where the relevant installer supports this.
  3. Replace unpinned repository cloning with checkout of an audited full Git commit hash:
    bash
    git clone https://github.com/adinvadim/2captcha-cli.git
    cd 2captcha-cli
    git checkout --detach <audited-full-commit-hash>
    
  4. Publish SHA-256 checksums for release artifacts and require verification before execution or linking.
  5. Sign releases and document signature verification using a trusted signing identity.
  6. Prefer installing the reviewed bundled executable instead of downloading a second mutable copy from an external source.
  7. Avoid global or privileged installation until integrity verification has completed.
  8. Add provenance information to the documentation, including the exact source revision corresponding to version 2.0.1.
  9. Configure CI to reproduce release artifacts from the pinned source and validate their hashes before publication.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · solve-captcha (reported line 131)May include surrounding context.

text
# ============== API HELPERS ==============

def get_api_key():
    """Get API key from config, env, or file."""
    if config.api_key:
        return config.api_key

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 51)May include surrounding context.

md
git clone https://github.com/adinvadim/2captcha-cli.git
cd 2captcha-cli
python3 solve-captcha --version
mkdir -p ~/.local/bin
ln -sf "$PWD/solve-captcha" ~/.local/bin/solve-captcha

# Or with Homebrew (coming soon)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 61)May include surrounding context.

git clone https://github.com/adinvadim/2captcha-cli.git cd 2captcha-cli chmod +x solve-captcha sudo ln -s $(pwd)/solve-captcha /usr/local/bin/

text

Old `adamvinsky/2captcha-cli` links are obsolete. Use `adinvadim/2captcha-cli`.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly documents access to environment variables, credential files, local filesystem paths, and external network services, but it does not declare any tool scope such as permissions or allowed-tools. That mismatch weakens least-privilege controls and can cause operators or automation frameworks to invoke the skill without clear boundaries around secret access and outbound data transfer.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

Using npx skills add adinvadim/2captcha-cli without pinning a version allows installation of whatever package version is current at execution time. If the upstream package is updated maliciously, compromised, or simply changes behavior, users may fetch and run unexpected code during installation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
77% confidence
Finding

The installation steps create a persistent symlink in ~/.local/bin, causing the cloned script to remain available across sessions and potentially continue pointing at a mutable working directory copy. This persistence increases risk if the repository contents are later modified locally or if users forget the command now resolves to an unversioned script outside a managed package system.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
git clone https://github.com/adinvadim/2captcha-cli.git
cd 2captcha-cli
python3 solve-captcha --version
mkdir -p ~/.local/bin
ln -sf "$PWD/solve-captcha" ~/.local/bin/solve-captcha

# Verify

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · solve-captcha (reported line 182)May include surrounding context.

text
def create_task(task, language_pool=None):
    """Create a captcha solving task."""
    api_key = get_api_key()
    if not api_key:
        error("API key not found",

Static analysis

No suspicious patterns detected.