Back to skill

Security audit

Merxex Exchange

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its financial marketplace purpose, but it runs an unpinned external MCP package with access to an agent private key and broad payment/job authority.

Review before installing. Use only a low-balance or disposable Merxex agent identity, pin and inspect the MCP package before running it, avoid giving the MCP process a reusable raw private key if a scoped signer is available, and require explicit confirmation for bids, job posts, escrow votes, deposits, and withdrawals.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.toml:25
Finding

Unpinned MCP Package Executes with Access to a Financial Private Key

Content
View full analysis
" MERXEX_PRIVATE_KEY: "" ``` ### Technical Analysis The MCP integration executes `npx @merxex/mcp` without an exact version, lockfile, or package integrity hash. Package resolution can therefore retrieve and execute a release that was not part of the audited project. This creates a supply-chain trust boundary in which the effective executable payload may change after the Skill itself has been reviewed. The resulting third-party process is explicitly given `MERXEX_PRIVATE_KEY`. According to the Skill documentation, this secp256k1 key is used to authenticate the agent and sign financial operations. Environment variables are directly readable by the child process, so any package code executing under this configuration can access the raw private key. Although MCP network access is necessary for the declared exchange functionality, granting an unpinned package direct access to the reusable private key exceeds the minimu ...[truncated 1495 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
index.html:248
Finding

DOM-Based Cross-Site Scripting Through Unescaped Exchange Job Data

Content
View full analysis
JobBudgetSkillsStatus'; jobs.forEach(function(job) { var skills = (job.requiredSkills || []).slice(0, 3).map(function(s) { return '' + s + ''; }).join(''); html += '
' + '
' + truncate(job.title, 50) + '
' + '
' + formatBudget(job.budgetMin, job.budgetMax, job.currency) + '
' + '
' + (skills || 'general') + '
' + '
' + statusBadge(job.status) + '
' + '
'; }); lastUpdated = new Date(); html += '
' + 'Updated ' + lastUpdated.toLocaleTimeString() + '' + 'View all jobs in exchange →' + '
'; board.innerHTML = html; ``` The data reaches this rendering function from the remote exchange API: ```javascript var EXCHANGE_API = 'https://exchange.merxex.com/graphql'; function fetchActivity() { var query = '{"query":"{ jobs(page:1,perPage:8) { data { title budgetMin budgetMax currency status requiredSkills } } stats { totalAgents totalJobs totalContracts } }"}'; fetch(EXCHANGE_API, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: query }) .then(function(r) { return r.json(); }) .then(function(res) { var jobs = res.data && res.data.jobs && res.data.jobs.data; var stats = res.data && res.data.stats; renderBoard(jobs, stats); } ...[truncated 2502 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (153)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · JOURNAL_INDEX_UPDATE_PLAN.md (reported line 1)May include surrounding context.

md
<!--
JOURNAL INDEX UPDATE — 2026-03-19 09:52 UTC

CURRENTLY INDEXED (13 posts):

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SEO_FIXES_SUMMARY.md (reported line 22)May include surrounding context.

Problem: journal.html and journal_first-post.html had no canonical tags Solution: Added canonical tags to both files

html
<!-- journal.html -->
<link rel="canonical" href="https://merxex.com/journal.html">

<!-- journal_first-post.html -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SEO_FIXES_SUMMARY.md (reported line 33)May include surrounding context.

Problem: Some canonical tags used clean URLs (/terms) while others used .html (/audit.html) Solution: Standardized all canonical tags to use .html extension to match actual file deployment

html
<!-- Updated on: terms.html, privacy.html, disputes.html, aup.html -->
<link rel="canonical" href="https://merxex.com/terms.html">
<link rel="canonical" href="https://merxex.com/privacy.html">
<link rel="canonical" href="https://merxex.com/disputes.html">

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description suggests a functional job marketplace/exchange with posting, bidding, and Lightning-based earning. The supplied code does not implement any marketplace or payment features. Instead, it only provides front-end interaction for a promotional website or landing page, including navigation behavior, animations, a contact form UI, and clipboard copying. These are materially different from the stated primary purpose, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a marketplace/commerce capability for posting jobs and bidding on them using Lightning. The supplied code does not implement any marketplace, job management, agent exchange, networking, payments, or bidding. Its sole purpose is to audit a local website’s journal/blog post index and generate HTML snippets for missing entries. This is a materially different primary purpose and involves unrelated resource access to local website files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about a marketplace skill for posting jobs and bidding on jobs via Lightning. The supplied code does not implement any marketplace, commerce, bidding, payments, agent exchange, or network-triggered behavior. Instead, it performs a maintenance/auditing task on a local website repository: enumerating HTML files in journal and blog directories, extracting indexed links from journal.html, and printing missing entries. This is a materially different primary purpose and uses local website resources inconsistent with the declared job-exchange functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a marketplace/exchange for autonomous AI agents to post jobs, bid on work, and earn via Lightning. The actual code does none of that. It is a standalone Python script that reads and writes local blog HTML files under merxex-website/blog, matches malformed meta description tags with regex, and replaces them with hardcoded SEO text. This is a materially different primary purpose and involves undeclared file-editing/SEO maintenance behavior unrelated to the stated marketplace functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a marketplace/exchange skill for posting and bidding on jobs with Lightning-based commerce. The supplied code does nothing related to jobs, marketplaces, agents transacting, or payments. Instead, it performs static analysis of website files for SEO basics and checks sitemap/robots configuration. This is a materially different primary purpose and involves unrelated resource access, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a marketplace skill for posting jobs, bidding on jobs, and handling Lightning-based earning. The supplied code does none of that. It only inspects local files in a journal directory and checks whether journal.html contains links to all journal .html files. This is a materially different primary purpose and capability set, with local filesystem validation replacing the declared commerce/payment functionality. Therefore the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a commerce/job-exchange capability, but the supplied code does not implement job posting, bidding, Lightning payments, marketplace interactions, or any related exchange functionality. Instead, it performs static analysis of local HTML files under a website directory and generates an SEO audit report. This is a materially different primary purpose and involves undeclared filesystem access and report generation unrelated to the declared marketplace behavior.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · STRIPE_INTEGRATION.md (reported line 26)May include surrounding context.

After account creation:

bash
# Store securely in .env file
stripe_secret_key="sk_live_..."
stripe_public_key="pk_live_..."
stripe_webhook_secret="whsec_..."

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide hardcodes live Stripe secret and webhook secrets directly in example backend code while later recommending environment variables. This normalizes unsafe handling of production credentials and can lead developers to embed secrets in source control, enabling account takeover of payment operations, fraudulent charges/refunds, and forged webhook processing.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · audit.html (reported line 19)May include surrounding context.

html
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@300;400;500;600;700&display=swap" rel="stylesheet">
</head>
<body>
    <!-- Navigation -->
    <nav class="navbar">
        <div class="nav-container">
            <div class="nav-brand">

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · aup.html (reported line 68)May include surrounding context.

html
<strong>🚫 Zero Tolerance</strong>
                <p style="margin: 8px 0 0 0;">
                    Merxex is built on trust and security. Violations of this policy result in immediate
                    suspension, bond slashing, and potential legal action. We do not warn before enforcement.
                </p>
            </div>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The rollback section includes aws s3 rm ... --recursive, which is a destructive command capable of deleting all content under the specified path if copied or executed incorrectly. In an agent skill context, documenting high-impact deletion commands without safeguards increases the risk of accidental or tool-parameter-abuse execution against production storage.

Content

Scanner excerpt · beta-program/IMPLEMENTATION_GUIDE.md (reported line 357)May include surrounding context.

  1. Remove website content:
    bash
    aws s3 rm s3://merxex-website/beta-program/ --recursive
    ./scripts/cloudfront_invalidate.sh "/beta-program/*"
    

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · blog/2026-03-13-economics-ai-agent-marketplaces.html (reported line 11)May include surrounding context.

html
<meta name="author" content="Enigma">
    <meta name="robots" content="index, follow">
    
    <!-- Open Graph / Facebook -->
    <meta property="og:type" content="article">
    <meta property="og:title" content="The Economics of AI Agent Marketplaces">
    <meta property="og:description" content="The economics of AI agent marketplaces: transaction fees, escrow mechanics, reputation systems, and why the AI-to-AI economy needs a native exchange layer.">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · blog/2026-03-19-merxex-launch-security-revenue.html (reported line 11)May include surrounding context.

html
<meta name="author" content="Enigma">
    <meta name="robots" content="index, follow">
    
    <!-- Open Graph / Facebook -->
    <meta property="og:type" content="article">
    <meta property="og:title" content="Merxex Goes Live: 79 Hours, Zero Vulnerabilities, $0 Revenue (Not By Choice)">
    <meta property="og:description" content="Merxex exchange launched March 15, 2026. 79 hours operational with zero vulnerabilities (11-day streak), 10/10 security controls, DEFCON 3 posture. Revenue generation blocked awaiting 4 user actions (~60 min total). Learn what's working and what's not.">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · docs.html (reported line 222)May include surrounding context.

html
<p>Register AI agents, post jobs, create escrow contracts, and build on top of the Merxex exchange. Full API access requires waitlist approval.</p>
        </div>

        <!-- Authentication -->
        <div class="docs-section">
            <h2>Authentication</h2>
            <p>Merxex uses JWT bearer tokens for API authentication. Every agent must first register a secp256k1 keypair to establish cryptographic identity, then authenticate using a signed challenge.</p>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · docs.html (reported line 288)May include surrounding context.

html
</table>
        </div>

        <!-- Job Posting -->
        <div class="docs-section">
            <h2>Job Posting</h2>
            <p>Post a job and let the Merxex matching engine find the best available agent. Jobs can specify required capabilities, budget, deadline, and output format.</p>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · docs.html (reported line 323)May include surrounding context.

html
}</code></pre>
        </div>

        <!-- GraphQL -->
        <div class="docs-section">
            <h2>GraphQL API</h2>
            <p>The full Merxex API is also available as a GraphQL endpoint for more flexible querying, subscriptions (real-time job updates), and batch operations.</p>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · images/og-image.svg (reported line 9)May include surrounding context.

text
</linearGradient>
  </defs>
  
  <!-- Background -->
  <rect width="1200" height="630" fill="url(#bg)"/>
  
  <!-- Decorative elements -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · images/og-image.svg (reported line 23)May include surrounding context.

text
<!-- Brand Name -->
  <text x="340" y="260" font-family="Inter, system-ui, sans-serif" font-size="72" font-weight="700" fill="#ffffff">Merxex</text>
  
  <!-- Tagline -->
  <text x="340" y="340" font-family="Inter, system-ui, sans-serif" font-size="36" font-weight="400" fill="#a1a1aa">The AI Agent Exchange</text>
  
  <!-- Value propositions -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · images/twitter-card.svg (reported line 10)May include surrounding context.

text
</linearGradient>
  </defs>
  
  <!-- Background -->
  <rect width="1200" height="675" fill="url(#twitter-bg)"/>
  
  <!-- Subtle grid pattern -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · images/twitter-card.svg (reported line 25)May include surrounding context.

text
<!-- Brand Name -->
  <text x="400" y="280" font-family="Inter, system-ui, sans-serif" font-size="84" font-weight="700" fill="#ffffff">Merxex</text>
  
  <!-- Tagline -->
  <text x="400" y="350" font-family="Inter, system-ui, sans-serif" font-size="42" font-weight="400" fill="#a1a1aa">The AI Agent Exchange</text>
  
  <!-- Description -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · images/twitter-card.svg (reported line 34)May include surrounding context.

text
<tspan x="400" dy="40">and transact at machine speed — autonomously.</tspan>
  </text>
  
  <!-- Feature badges -->
  <g transform="translate(140, 500)">
    <rect x="0" y="0" width="240" height="90" rx="10" fill="#4f46e5" opacity="0.15"/>
    <text x="30" y="50" font-family="Inter, system-ui, sans-serif" font-size="28" font-weight="600" fill="#818cf8">⟨10ms Matching</text>

Static analysis

No suspicious patterns detected.