T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned npm Package Is Downloaded and Executed with Wallet Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to do what it says, but it should be reviewed because it runs unpinned npm code with a wallet private key that can authorize payments.
Install only if you are comfortable using a dedicated, low-balance wallet for Chart Splat payments. Do not use a main wallet or paste a valuable private key into chat, shell history, or commands. Prefer a pinned, reviewed CLI version and a restricted environment with only the required wallet variable exposed. Confirm the expected amount, network, token, and recipient before allowing paid requests.
SKILL.md:24Unpinned npm Package Is Downloaded and Executed with Wallet Credentials
SKILL.md:144Remote Payment Requirements Are Automatically Signed Without an Explicit Local Spending Policy
The manifest description includes broad trigger terms like wallet, USDC, micropayment, and pay-per-call, which can cause the skill to activate in conversations that are only generally about payments rather than about chart generation. In this skill, overbroad activation is risky because invocation can lead an agent toward using a payment-capable tool and wallet-backed workflow unnecessarily.
The install metadata references npm execution paths without pinning an exact package version, which creates a supply-chain risk: a later malicious or compromised package release could be fetched and executed automatically. In this skill, that risk is amplified because the tool is given access to a wallet private key used for payment signing, so arbitrary package code could exfiltrate credentials or trigger unauthorized payments.
The documentation instructs users to export and use a raw private key for payment signing but does not prominently warn that this is highly sensitive secret material that must not be shared, logged, embedded in commands, or exposed to untrusted tools. In the context of an agent skill that also recommends transient package execution, weak secret-handling guidance materially increases the likelihood of credential compromise and financial loss.
npx -y chartsplat-x402-cli executes the latest resolved package version at runtime without an explicit pin, exposing users to package-takeover or malicious-update attacks. Because this skill requires X402_PRIVATE_KEY, any malicious code in that package would run in a highly sensitive context and could steal the key or misuse wallet funds.
This example invokes an unpinned npm package through npx, allowing remote code execution from whatever version is current at execution time. In a wallet-backed payment workflow, that creates meaningful financial and secret-exfiltration risk if the package or dependency chain is compromised.
This command repeats the same unpinned npx pattern, which is a classic software supply-chain weakness. Since the command may execute in an environment holding an EVM private key, a compromise could lead to credential theft or unauthorized payment signing.
Running an unversioned package via npx means behavior can change or become malicious without any change to the skill text. Given that this skill is explicitly designed to work with a private key and paid network requests, the blast radius extends beyond generic code execution to wallet compromise and financial loss.
This unpinned runtime package reference exposes users to malicious updates and dependency hijacking. Because the package participates in payment authorization flows, exploitation could directly affect funds and sensitive signing material.
The skill again instructs execution of a mutable npm package reference with npx, which is unsafe for reproducibility and opens a supply-chain execution path. The skill context makes this more dangerous than a normal utility because it expects access to an EVM private key for payment signing.
This example command carries the same unpinned-package risk: code from a future package release may be executed automatically. In this environment, compromise could lead to wallet key exfiltration, unauthorized x402 settlement approvals, or tampered output.
The candlestick example invokes an unpinned CLI package via npx, preserving the same supply-chain attack surface. Since the package mediates payment flows and file output, a malicious release could both steal secrets and write unexpected local content.
This is another live npx execution of an unpinned package, which is a real software supply-chain vulnerability rather than a mere style issue. The associated private-key-based payment model increases severity because any malicious update would execute where financial credentials are present.
The complex-chart example still relies on unpinned npx execution, meaning the code actually run may differ from the documented tool over time. In a skill that uses wallet signing, this turns a documentation issue into a meaningful financial and credential-security risk.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
registerExactEvmScheme(client, { signer: account });
const fetchWithPayment = wrapFetchWithPayment(fetch, client);
const res = await fetchWithPayment('https://api.chartsplat.com/chart', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({
The testnet example also uses unpinned npx, so even non-mainnet workflows remain exposed to package substitution or malicious updates. While the funds on testnet may be lower value, the same private-key handling patterns and arbitrary-code-execution path remain dangerous.
The documentation explains that wrapFetchWithPayment automatically handles the full payment flow, including retrying the request with a signed payment authorization and eventual on-chain settlement, but it does not pair that with an explicit user-facing warning or consent requirement. In a pay-per-call skill tied to a wallet, this can cause users or downstream integrators to trigger monetary transfers implicitly when generating a chart, increasing the risk of surprise charges and unsafe automation.
No suspicious patterns detected.