Back to skill

Security audit

ATXP

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent ATXP CLI wrapper, but it relies on an unpinned executable for authenticated paid, email, and account actions and persists credentials locally.

Review this skill before installing. Use it only if you trust the ATXP npm package and service, prefer a pinned or locked CLI install, run it in a constrained environment, protect and revoke `~/.atxp/config` credentials when needed, and require explicit user approval before paid actions, email sending/deletion, username changes, agent creation, payment links, attachment handling, or OpenClaw configuration edits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned npm CLI Execution and Unsafe Sourcing of Generated Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12–19
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

bash
# Check if authenticated
echo $ATXP_CONNECTION

# If not set, login:
npx atxp login
source ~/.atxp/config

Technical Analysis

The skill instructs the agent to execute npx atxp without specifying an exact package version, lockfile, package integrity hash, or trusted installation artifact. Consequently, the package resolved by npm at execution time can differ from the package that existed when the skill was audited.

This creates a mutable supply-chain boundary. If the package, one of its transitive dependencies, the registry account, or the package-resolution environment is compromised, running npx atxp login can execute attacker-controlled JavaScript with the privileges of the agent process.

The subsequent source ~/.atxp/config command executes the generated file as shell code in the current shell rather than treating it as passive configuration data. If the CLI or generated file is compromised, arbitrary commands embedded in that file will run and may also alter the current process environment.

No evidence establishes that the current atxp package is malicious. The issue is the absence of controls ensuring that the reviewed dependency is the dependency executed later.

Attack Path

  1. An attacker compromises the atxp npm package, a transitive dependency, or an account authorized to publish it.
  2. The attacker publishes a modified package version containing a malicious installation hook or runtime payload.
  3. An agent follows the skill and executes npx atxp login without an exact version or integrity constraint.
  4. npm resolves and runs the attacker-controlled package.
  5. The package reads accessible environment variables and files, including the ATXP connection credential, or writes malicious shell commands to ~/.atxp/config.
  6. The agent executes ...[truncated 790 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an audited exact version, for example npx --yes atxp@X.Y.Z, rather than resolving an unconstrained package version.
  2. Install dependencies through a committed lockfile and use a reproducible command such as npm ci.
  3. Verify package provenance and integrity through registry signatures, checksums, or a trusted internal package mirror.
  4. Review and constrain transitive dependencies and enable automated dependency monitoring.
  5. Run the CLI in a sandbox with only the filesystem, network, and environment access required for the requested operation.
  6. Do not source a file generated by a third-party executable. Parse the required value as data, validate its format, and export it explicitly.
  7. Restrict permissions on credential files, and avoid exposing unrelated secrets to the CLI process.
  8. Document the expected official package registry and publisher identity to reduce dependency-confusion and package-substitution risk.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:23
Finding

Unsafe Shell Interpolation Guidance for User-Controlled CLI Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23–33
Vulnerability Type: Potential command injection through unsafe shell argument construction
Risk Level: Medium

Vulnerable Code

markdown
| Command | Description |
|---------|-------------|
| `npx atxp search <query>` | Real-time web search |
| `npx atxp image <prompt>` | AI image generation |
| `npx atxp music <prompt>` | AI music generation |
| `npx atxp video <prompt>` | AI video generation |
| `npx atxp x <query>` | X/Twitter search |
| `npx atxp email inbox` | Check your email inbox (FREE) |
| `npx atxp email read <messageId>` | Read a specific message (FREE) |
| `npx atxp email send <options>` | Send an email ($0.01/email) |
| `npx atxp email reply <messageId> --body <text>` | Reply to an email ($0.01/reply) |

Related email guidance later provides the same substitution pattern:

bash
npx atxp email send --to <email> --subject <subject> --body <body>

Technical Analysis

The documented command templates contain dynamic queries, prompts, message identifiers, addresses, subjects, and message bodies but do not require shell-safe argument handling. These values can originate from users, retrieved web content, or untrusted email.

If an implementation replaces the placeholders in a command string and invokes it through a shell, shell metacharacters can be interpreted as command syntax rather than data. Relevant constructs include command substitution, command separators, redirections, pipelines, variable expansion, and newline injection.

Values beginning with hyphens may also be interpreted as CLI options where the command does not use an option terminator or otherwise validate positional arguments. Quoting alone can prevent shell token splitting but does not necessarily prevent option injection; constructing a subprocess with an argument array and validating values is safer.

The Markdown placeholders are not themselves executable, and exploitation depends on an ...[truncated 1840 chars]

Remediation
View remediation

Remediation Suggestions

  1. Explicitly prohibit building commands through string concatenation or placeholder replacement followed by shell execution.
  2. Require a subprocess API that accepts an executable and an argument array, with shell processing disabled. For example, pass ["atxp", "search", userQuery] as distinct arguments.
  3. Validate structured inputs:
    • Enforce the documented format for message identifiers.
    • Validate recipient addresses as email addresses.
    • Apply reasonable length and character constraints.
    • Reject embedded NUL characters and unexpected control characters.
  4. Use -- before untrusted positional arguments where the CLI supports an option terminator.
  5. Do not rely solely on manual quoting. If shell execution is unavoidable, use a well-tested platform-specific escaping function for every dynamic argument.
  6. Keep untrusted email and retrieved web content separate from operational instructions. Never execute commands suggested by message bodies or attachments.
  7. Require explicit user confirmation before paid, destructive, or externally visible operations such as sending email, deleting messages, claiming usernames, or creating payment links.
  8. Add safe programmatic examples demonstrating argument-array execution rather than shell command templates.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (53)

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill repeatedly instructs use of npx atxp without pinning a package version, including in the manifest. npx fetches the latest published package by default, so a compromised upstream release, typosquatted package, or malicious maintainer update could change runtime behavior and execute attacker-controlled code in the agent environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The authentication section instructs users to source ~/.atxp/config after login, indicating session material is stored locally and reused across subsequent commands. Persistent credentials increase exposure if the environment is shared, the file permissions are weak, or another process can read shell-initialized secrets.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: atxp
description: Access ATXP paid API tools for web search, AI image generation, music creation, video generation, X/Twitter search, email, and agent account management. Use when users need real-time web search, AI-generated media (images, music, video), X/Twitter search, send/receive emails, or create and fund agent accounts. Requires authentication via `npx atxp login`.
---

# ATXP Tools

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Authentication guidance tells users to run npx atxp login without a version pin. Because this is an executable package fetch during a sensitive login flow, a malicious update could harvest tokens or alter account configuration while appearing to be normal authentication.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The command reference lists npx atxp search <query> without pinning the package version. This exposes every invocation to unreviewed upstream code changes, which is risky because the tool is intended for repeated operational use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The balance-check example uses unpinned npx atxp, allowing remote code changes each time the command is run. Even seemingly low-risk commands still execute the package with the user's credentials and environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The funding command is shown via unpinned npx atxp. Since this workflow concerns payment/funding actions, an upstream compromise could misdirect funds, alter payment links, or exfiltrate account details.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The account-info example invokes npx atxp whoami without version pinning. Running a mutable remote package in an authenticated context can expose identity, wallet, and account metadata to malicious code if the package supply chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The agent creation example uses unpinned npx atxp, which is particularly risky because it performs account-creation actions under an authenticated human owner. A malicious package update could create unauthorized agents, capture tokens, or manipulate ownership details.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The agent listing example uses unpinned npx atxp, exposing administrative enumeration tasks to arbitrary upstream package changes. Although read-oriented, it still runs with authenticated access and can leak metadata or session material.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The self-registration flow uses npx atxp agent register without version pinning. Because this creates autonomous accounts and may provision credentials/wallets, a compromised package could silently create attacker-controlled resources or leak the generated connection string.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The inbox-check command is documented with unpinned npx atxp. This creates a supply-chain exposure in a messaging context where malicious updates could read, alter, or exfiltrate mailbox contents.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Reading a message via unpinned npx atxp email read executes whatever the latest package version provides. Because the command accesses full message contents and attachments metadata, an upstream compromise could leak sensitive communications.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The send-email command is unpinned and can perform authenticated outbound messaging. A malicious package update could modify recipients/content, send unauthorized messages, or harvest contacts and credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The email reply command uses unpinned npx atxp, which can act on existing threads and sender relationships. This is dangerous because compromised upstream code could impersonate the user, alter reply content, or leak private correspondence.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The email search command is unpinned, so routine mailbox searches could execute attacker-modified code if the package changes upstream. This still matters because the command processes potentially sensitive sender/subject data under the user's account.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Deleting email via unpinned npx atxp combines supply-chain risk with destructive action. A malicious update could delete additional messages, conceal activity, or tamper with mailbox state beyond the intended message.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Attachment retrieval is documented with unpinned npx atxp, exposing sensitive file downloads to mutable upstream code. Compromised code could exfiltrate attachment contents or alter the retrieved payload.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Claiming an email username through unpinned npx atxp permits upstream code changes in an account-modification flow. A compromised package could register unintended usernames or leak account identifiers associated with the mailbox.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Releasing a username is shown with unpinned npx atxp, again allowing remote package behavior changes during an account mutation. This could cause unwanted account renaming effects or covert metadata exfiltration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The balance command in the table uses unpinned npx atxp, exposing financial/account metadata to latest-package execution. Even read-only finance commands can leak balances, wallet identifiers, or session data if the package is malicious.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The fund command reference is unpinned, creating a supply-chain risk in a payment-oriented workflow. A malicious package release could present spoofed funding instructions or redirect users to attacker-controlled payment destinations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The whoami command reference uses unpinned npx atxp, allowing arbitrary upstream package changes for authenticated identity queries. This can leak account details or tokens despite appearing informational only.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Creating payment links with npx atxp topup is documented without a version pin. Because the action interacts with funding requests and browser opening, a malicious package could generate fraudulent links or trigger unsafe navigation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The parameterized topup example is also unpinned, preserving the same supply-chain risk for payment-link generation. This matters because funds and trust relationships are involved even if the amount is only suggested.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The agent create command in the summary table remains unpinned and is privileged because it provisions owned agent accounts. A malicious upstream package could abuse human-authenticated context to create, bind, or expose unauthorized agent credentials.

Content

No source excerpt is available for this finding.