Back to skill

Security audit

Chart Splat (x402)

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says, but it should be reviewed because it runs unpinned npm code with a wallet private key that can authorize payments.

Install only if you are comfortable using a dedicated, low-balance wallet for Chart Splat payments. Do not use a main wallet or paste a valuable private key into chat, shell history, or commands. Prefer a pinned, reviewed CLI version and a restricted environment with only the required wallet variable exposed. Confirm the expected amount, network, token, and recipient before allowing paid requests.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned npm Package Is Downloaded and Executed with Wallet Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:144
Finding

Remote Payment Requirements Are Automatically Signed Without an Explicit Local Spending Policy

Content
View full analysis
402 Payment Required + PAYMENT-REQUIRED header 3. Client decodes requirements, signs EIP-3009 authorization off-chain 4. Client -> POST /chart with PAYMENT-SIGNATURE header 5. Server verifies signature via Coinbase facilitator 6. Server generates the chart 7. Server settles the payment on-chain (facilitator pays gas) 8. Server -> 200 OK + chart + PAYMENT-RESPONSE header (settlement tx) ``` ```text `@x402/fetch`'s `wrapFetchWithPayment` does the entire dance automatically. ``` ### Technical Analysis The example creates a signer directly from `X402_PRIVATE_KEY` and delegates the complete payment negotiation to `wrapFetchWithPayment`. The remote server supplies payment requirements in its HTTP 402 response, after which the wrapper signs an EIP-3009 authorization and retries the request. The audited Skill does not show an ...[truncated 2851 chars]
Remediation
View remediation
` workflow because command-line secrets may be exposed through shell history or process inspection. Prefer a protected secret manager or narrowly scoped environment injection. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description includes broad trigger terms like wallet, USDC, micropayment, and pay-per-call, which can cause the skill to activate in conversations that are only generally about payments rather than about chart generation. In this skill, overbroad activation is risky because invocation can lead an agent toward using a payment-capable tool and wallet-backed workflow unnecessarily.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install metadata references npm execution paths without pinning an exact package version, which creates a supply-chain risk: a later malicious or compromised package release could be fetched and executed automatically. In this skill, that risk is amplified because the tool is given access to a wallet private key used for payment signing, so arbitrary package code could exfiltrate credentials or trigger unauthorized payments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs users to export and use a raw private key for payment signing but does not prominently warn that this is highly sensitive secret material that must not be shared, logged, embedded in commands, or exposed to untrusted tools. In the context of an agent skill that also recommends transient package execution, weak secret-handling guidance materially increases the likelihood of credential compromise and financial loss.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

npx -y chartsplat-x402-cli executes the latest resolved package version at runtime without an explicit pin, exposing users to package-takeover or malicious-update attacks. Because this skill requires X402_PRIVATE_KEY, any malicious code in that package would run in a highly sensitive context and could steal the key or misuse wallet funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This example invokes an unpinned npm package through npx, allowing remote code execution from whatever version is current at execution time. In a wallet-backed payment workflow, that creates meaningful financial and secret-exfiltration risk if the package or dependency chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command repeats the same unpinned npx pattern, which is a classic software supply-chain weakness. Since the command may execute in an environment holding an EVM private key, a compromise could lead to credential theft or unauthorized payment signing.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Running an unversioned package via npx means behavior can change or become malicious without any change to the skill text. Given that this skill is explicitly designed to work with a private key and paid network requests, the blast radius extends beyond generic code execution to wallet compromise and financial loss.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This unpinned runtime package reference exposes users to malicious updates and dependency hijacking. Because the package participates in payment authorization flows, exploitation could directly affect funds and sensitive signing material.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill again instructs execution of a mutable npm package reference with npx, which is unsafe for reproducibility and opens a supply-chain execution path. The skill context makes this more dangerous than a normal utility because it expects access to an EVM private key for payment signing.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This example command carries the same unpinned-package risk: code from a future package release may be executed automatically. In this environment, compromise could lead to wallet key exfiltration, unauthorized x402 settlement approvals, or tampered output.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The candlestick example invokes an unpinned CLI package via npx, preserving the same supply-chain attack surface. Since the package mediates payment flows and file output, a malicious release could both steal secrets and write unexpected local content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This is another live npx execution of an unpinned package, which is a real software supply-chain vulnerability rather than a mere style issue. The associated private-key-based payment model increases severity because any malicious update would execute where financial credentials are present.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The complex-chart example still relies on unpinned npx execution, meaning the code actually run may differ from the documented tool over time. In a skill that uses wallet signing, this turns a documentation issue into a meaningful financial and credential-security risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
registerExactEvmScheme(client, { signer: account });
const fetchWithPayment = wrapFetchWithPayment(fetch, client);

const res = await fetchWithPayment('https://api.chartsplat.com/chart', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The testnet example also uses unpinned npx, so even non-mainnet workflows remain exposed to package substitution or malicious updates. While the funds on testnet may be lower value, the same private-key handling patterns and arbitrary-code-execution path remain dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation explains that wrapFetchWithPayment automatically handles the full payment flow, including retrying the request with a signed payment authorization and eventual on-chain settlement, but it does not pair that with an explicit user-facing warning or consent requirement. In a pay-per-call skill tied to a wallet, this can cause users or downstream integrators to trigger monetary transfers implicitly when generating a chart, increasing the risk of surprise charges and unsafe automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.