T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Automatic Execution of an Unpinned Remote npm Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Mayar payment skill is broadly legitimate, but its setup and examples handle live payment credentials and payment events in ways that need careful review before use.
Install only if you are comfortable giving the agent access to a Mayar payment account and customer transaction data. Before production use, pin and review the MCP dependency, avoid putting live tokens directly in command arguments or committed config, verify webhooks before fulfillment, avoid shell-string examples for user-controlled fields, and add consent/redaction controls for WhatsApp and reporting workflows.
SKILL.md:35Automatic Execution of an Unpinned Remote npm Package
references/integration-examples.md:403Shell Command Injection Through Interpolated Invoice Fields
references/api-reference.md:409Webhook Example Processes Payment Events Without Sender Authentication
The example explicitly discusses sending access credentials after payment and pairs that with WhatsApp delivery of account-access information. Delivering credentials or sensitive access details through chat increases the chance of account compromise through device theft, message interception on linked devices, or disclosure on shared phones, especially because messaging platforms are not ideal channels for secret distribution.
// 3. Grant course access
await grantCourseAccess(paidInvoice.customer.email);
// 4. Send access credentials
message({
action: 'send',
channel: 'whatsapp',
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
---
name: mayar-payment
description: Mayar.id payment integration for generating invoices, payment links, and tracking transactions via MCP. Use when needing to: (1) Create payment invoices/links for customers, (2) Track payment status and transactions, (3) Generate WhatsApp-friendly payment messages, (4) Handle Indonesian payment methods (bank transfer, e-wallet, QRIS), (5) Manage subscriptions/memberships, or (6) Automate payment workflows for e-commerce, services, or digital products.
---
# Mayar Payment Integration
The skill instructs users to place a live API token into a local credentials file but does not warn about secret handling, shell history exposure, file backup/sync leakage, or avoiding committing such files to source control. In a payment integration context, compromise of this token could allow unauthorized access to invoices, transactions, balances, and customer/payment workflows.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
cat > ~/.config/mayar/credentials << EOF MAYAR_API_TOKEN="your-jwt-token-here" EOF chmod 600 ~/.config/mayar/credentials
### 2. Configure MCP Server
The MCP configuration example places the Authorization token directly in a persistent JSON config entry, creating a strong risk of accidental disclosure through source control, backups, support bundles, or workstation compromise. Because this is a payment platform credential, exposure could enable unauthorized API use against financial and customer data.
The authentication section tells users to use Bearer tokens and obtain API keys, but it does not warn against hardcoding, exposing, or improperly storing those secrets. In practice, documentation omissions like this often lead to keys being committed to source control, embedded in client-side code, or leaked through logs, enabling unauthorized API access.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Production:
https://api.mayar.id/hl/v1/
Sandbox (Testing):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Production:
https://api.mayar.id/hl/v1/
Sandbox (Testing):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Sandbox (Testing):
https://api.mayar.club/hl/v1/
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Sandbox (Testing):
https://api.mayar.club/hl/v1/
The webhook payload example includes customer name, email, and mobile number, but the document does not instruct users to minimize, protect, redact, or securely store this PII. In a payment-processing context, implementers may log or forward webhook bodies by default, which increases privacy, compliance, and data-exposure risk if systems are compromised or misconfigured.
This markdown file includes example flows that transmit customer phone numbers, payment links, invoice codes, amounts, and related transactional details via WhatsApp. The surrounding documentation does not warn readers that these examples handle and send user data through external messaging channels, which matches the markdown-specific missing-warning criterion.
The payment-status polling example retrieves transaction records and automatically messages customers based on payment state, and the later reminder flow does the same for unpaid invoices. The markdown presents this as routine automation but does not disclose the privacy, consent, or operational implications of monitoring payment data and initiating outbound messages.
Multiple examples hard-code Indonesian locale conventions, such as toLocaleString('id-ID'), Rupiah formatting, Indonesian-language message text, and later guidance to always use Jakarta timezone. This effectively forces a specific language/locale behavior without offering opt-in or clearly stating that the skill is limited to an Indonesia-specific deployment context.
The best-practices section explicitly instructs implementers to always use Jakarta timezone, creating a hard locale requirement. Because the document does not provide a user/deployment choice or narrowly justify the regional constraint, this matches the natural-language locale policy violation criteria.
The documentation instructs users to submit personally identifiable information such as name, email, phone number, and customer transaction details to payment and portal tools, but provides no privacy, minimization, retention, or consent guidance. In an agent skill context, this omission can normalize unsafe handling of customer data and increase the risk of over-collection, accidental disclosure, or noncompliant processing when downstream tools are invoked automatically.
The daily revenue report example aggregates transaction data and sends sales details to an admin over WhatsApp. The markdown does not warn that the report may expose sensitive financial or customer-linked business information through a third-party messaging platform.
No suspicious patterns detected.