Back to skill

Security audit

Eth Payment

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local Ethereum payment-link generator, but it needs review because it can overwrite caller-chosen files and can generate invalid or misleading payment requests.

Review this skill before installing. Use it only with explicit recipient addresses, amounts, tokens, and networks that you independently verify, avoid relying on Ethereum DAI output until the configuration is corrected, and only write QR files to safe new paths in a disposable or controlled directory. Install the Python dependencies in an isolated environment if QR generation is needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/eth_payment.py:78
Finding

Payment requests accept malformed addresses and unsafe numeric amounts

Content
View full analysis
Remediation
View remediation
bool: return ( len(address) == 42 and address.startswith("0x") and all(c in "0123456789abcdefABCDEF" for c in address[2:]) ) amount_decimal = Decimal(args.amount) if not amount_decimal.is_finite() or amount_decimal <= 0: raise ValueError("Amount must be finite and greater than zero") scaled = amount_decimal * (Decimal(10) ** decimals) if scaled != scaled.to_integral_value(): raise ValueError(f"Amount exceeds the token's {decimals}-decimal precision") amount_raw = int(scaled) ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/eth_payment.py:145
Finding

Caller-controlled QR output path permits arbitrary file overwrite

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned QR-generation dependencies create supply-chain exposure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
config/chains.json:50
Finding

Malformed Ethereum DAI contract address compromises generated payment requests

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill metadata declares no explicit tool scope or permissions even though the skill clearly instructs use of Python, pip installation, and script execution, which implies shell access and likely file reads. In an agent ecosystem, missing scope boundaries can cause the skill to be invoked with broader capabilities than necessary, increasing the chance of unintended command execution or filesystem interaction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description markets the skill for broadly generating payment requests 'when you need' them, without clear trigger constraints or narrower invocation criteria. In an agent setting, vague activation language can cause over-invocation in adjacent payment or crypto contexts, leading an agent to prepare payment artifacts when not explicitly requested, which is especially sensitive because recipient addresses and amounts affect financial transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code creates directories and writes an image file to the filesystem based on the --qr argument. Although the behavior is implemented intentionally, there is no confirmation prompt or explicit warning in user-facing output that the command will create or overwrite files at the specified path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.