Back to skill

Security audit

Locus

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent crypto payment integration, but it needs Review because it can handle wallet-linked credentials and payment authority with some under-scoped setup and credential-handling risks.

Before installing, only use narrowly scoped Locus API keys with low limits and recipient controls, review every payment or token approval manually, and avoid running the setup in recorded or shared terminals. Consider installing a reviewed pinned mcporter version yourself instead of accepting a global unpinned npm install during setup, and rotate the API key if it may have appeared in logs, screenshots, or process telemetry.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:11
Finding

Unpinned Global npm Package Installation Executes Unverified Supply-Chain Code

Content
View full analysis
/dev/null; then echo "mcporter is required but not installed." read -rp "Install mcporter now? (Y/n): " install_mcporter if [[ "$install_mcporter" =~ ^[Nn]$ ]]; then echo "Cannot continue without mcporter. Install with: npm i -g mcporter" exit 1 fi echo "Installing mcporter..." npm i -g mcporter ``` The same unpinned installation command is also recommended in `SKILL.md` lines 16–19 and `README.md` line 27. ### Technical Analysis The setup script installs the latest package published under the `mcporter` name without specifying an audited version, integrity hash, lockfile, or trusted package provenance. npm installations may execute package lifecycle scripts such as `preinstall`, `install`, and `postinstall`. Consequently, the code executed by the setup process can differ from the code that was reviewed. A compromised maintainer account, malicious newly published release, registry compromise, or dependency-chain compromise could cause arbitrary code to run during setup. The global installation flag expands the potential impact because the package is installed into the user's global npm environment. The installer executes with the privileges of the account running the script; if a user invokes setup through a privileged npm configuration or elevated shell, the package lifecycle code receives those elevated privileges. ### Attack Path 1. An attacker compromises the `mcporter` npm package, one of its install-time dependencies, or its publishing account. 2. The attacker publishes a new release containing a malicious lifecycle script or runtime payload. 3. A user without `mcporter` runs `scripts/setup.sh`. 4. The script offers to install the dependency and invokes `npm i -g mcporter` without ...[truncated 1093 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.sh:41
Finding

Locus API Key Is Echoed During Entry and Exposed in a Child Process Command Line

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises tools that can send tokens and approve ERC-20 spending without clearly warning that these are financially sensitive, potentially irreversible actions. In an agent skill specifically designed to process payment requests, lack of explicit cautions increases the chance that users enable autonomous transfers or token approvals without understanding the consequences, including loss of funds or excessive allowance exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation text is broad enough to trigger this skill for many generic payment-related requests, including cases where the user may only want advice, analysis, or non-wallet tasks. Because this skill can lead to wallet configuration, email scanning, token approvals, and payment execution, overbroad routing increases the chance of an agent invoking sensitive payment capabilities in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase 'anything payment-related' is ambiguous and can cause the agent to enter setup or payment workflows for loosely related requests. In this skill's context, that is more dangerous than usual because the workflow may collect an API key, connect wallet tooling, enumerate dynamic payment tools, and potentially process emails that contain payment instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.