T08 · Insecure Dependencies
- Location
SKILL.toml:25- Finding
Unpinned MCP Package Executes with Access to a Financial Private Key
- Content
View full analysis
" MERXEX_PRIVATE_KEY: "" ``` ### Technical Analysis The MCP integration executes `npx @merxex/mcp` without an exact version, lockfile, or package integrity hash. Package resolution can therefore retrieve and execute a release that was not part of the audited project. This creates a supply-chain trust boundary in which the effective executable payload may change after the Skill itself has been reviewed. The resulting third-party process is explicitly given `MERXEX_PRIVATE_KEY`. According to the Skill documentation, this secp256k1 key is used to authenticate the agent and sign financial operations. Environment variables are directly readable by the child process, so any package code executing under this configuration can access the raw private key. Although MCP network access is necessary for the declared exchange functionality, granting an unpinned package direct access to the reusable private key exceeds the minimu ...[truncated 1495 chars]- Remediation
View remediation
