Back to skill

Security audit

FourMeme

Security checks for vulnerabilities and agentic risk

Overview

This skill is review-worthy because it can move wallet funds and run mutable npm code with a private key, although its main blockchain actions are mostly disclosed.

Install only after reviewing the exact npm package version you will run. Use a dedicated low-balance wallet, avoid putting private keys in project .env files, pin dependencies where possible, and confirm every transaction recipient, token, amount, approval, and slippage limit before allowing writes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
scripts/create-token-instant.ts:53
Finding

Unpinned Runtime Dependency Execution Exposes Wallet Credentials to Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:91, SKILL.md:117, and scripts/create-token-instant.ts:53-57
Vulnerability Type: Unpinned and dynamically resolved executable dependencies
Risk Level: High

Vulnerable Code

SKILL.md:91:

markdown
**Installation (required):** `npm install -g @four-meme/four-meme-ai@latest`. After install, run `fourmeme <command> [args]`; with local install only, use `npx fourmeme <command> [args]` from the project root.

SKILL.md:117:

markdown
- **Invocation**: The agent must run commands only via the **fourmeme** CLI: `fourmeme <command> [args]` or `npx fourmeme <command> [args]` (allowed-tools).

scripts/create-token-instant.ts:53-57:

ts
const child = spawnSync('npx', ['tsx', apiScript, ...args], {
  env: process.env,
  encoding: 'utf8',
  stdio: ['inherit', 'pipe', 'inherit'],
});

Technical Analysis

The documented installation command selects the mutable latest version of @four-meme/four-meme-ai rather than an audited, immutable release. The documented npx fourmeme invocation may also resolve or download executable npm content at runtime.

In addition, create-token-instant.ts invokes npx tsx and passes the complete parent environment through env: process.env. Write-capable operations require PRIVATE_KEY, so a dynamically resolved or compromised executable can read that credential. The effective CLI package and its dispatcher are not included in the audited artifact, preventing their behavior and dependency integrity from being verified as part of this review.

Although npx can use an already-installed local package, the implementation does not enforce local-only resolution, an exact version, or package integrity. Consequently, the executed code may differ from the code originally reviewed.

Attack Path

  1. An attacker compromises the npm publisher account, a transitive dependency, the package registry ...[truncated 1547 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin @four-meme/four-meme-ai and tsx to exact audited versions rather than using @latest or unconstrained npx resolution.
  2. Include a lockfile with integrity hashes and install dependencies using npm ci.
  3. Bundle the CLI entry point and required runtime dependencies with the reviewed Skill artifact.
  4. Prevent network package retrieval during command execution. Prefer an explicitly resolved local executable, and fail if it is unavailable.
  5. Replace runtime npx tsx execution with compiled JavaScript or a pinned, locally installed runtime invoked by an absolute verified path.
  6. Pass a minimal environment to child processes instead of process.env. Include only variables strictly required by that child.
  7. Avoid giving API-only subprocesses direct access to PRIVATE_KEY where possible. Derive the wallet address and required login signature in a narrowly scoped signer component, then pass only those outputs.
  8. Verify package provenance and signatures in CI, audit transitive dependencies, and use automated dependency-review controls.
  9. Run signing operations in an isolated process or hardware-backed wallet that requires explicit transaction confirmation and does not expose raw key material to npm packages.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (68)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill also exposes a generic send command for transferring native BNB or arbitrary ERC20s, which is broader and riskier than the declared meme-token trading/config scope. In practice, this hidden breadth matters because a user may enable the skill expecting limited Four.Meme interactions while actually granting a tool path capable of directly moving wallet funds anywhere.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill also exposes a generic send command for transferring native BNB or arbitrary ERC20s, which is broader and riskier than the declared meme-token trading/config scope. In practice, this hidden breadth matters because a user may enable the skill expecting limited Four.Meme interactions while actually granting a tool path capable of directly moving wallet funds anywhere.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill also exposes a generic send command for transferring native BNB or arbitrary ERC20s, which is broader and riskier than the declared meme-token trading/config scope. In practice, this hidden breadth matters because a user may enable the skill expecting limited Four.Meme interactions while actually granting a tool path capable of directly moving wallet funds anywhere.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill instructs users to place PRIVATE_KEY in a .env file in the current working directory and have the CLI auto-load it. Storing hot wallet secrets in project-local plaintext files is dangerous because they are easily exposed through accidental commits, backups, workspace sharing, malware, or execution from the wrong directory; in this skill context the secret directly authorizes on-chain transfers and trades.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
**When not using OpenClaw (standalone)**  
Set **PRIVATE_KEY** and optionally **BSC_RPC_URL** via the process environment so they are available when running `npx fourmeme` or `node bin/fourmeme.cjs`:

- **.env file**: Put a `.env` file in **the directory where you run the `fourmeme` command** (i.e. your project / working directory). Example: if you run `fourmeme quote-buy ...` from `/path/to/my-project`, place `.env` at `/path/to/my-project/.env`. The CLI automatically loads `.env` from that current working directory. Use lines like `PRIVATE_KEY=...` and `BSC_RPC_URL=...`. Do not commit `.env`; add it to `.gitignore`.
- **Shell export**: `export PRIVATE_KEY=your_hex_key` and `export BSC_RPC_URL=https://bsc-dataseed.binance.org` (or another BSC RPC), then run `npx fourmeme <command> ...`.

### Declared and optional environment variables

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script mints an EIP-8004 identity NFT, which is unrelated to the declared Four.Meme meme-token creation/trading functionality. Capability drift like this is dangerous because users may run the skill expecting trading operations, while the package quietly performs unrelated on-chain actions that create persistent blockchain state and potential financial cost.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script reads PRIVATE_KEY, constructs a wallet, and submits a blockchain transaction to register an identity NFT unrelated to the advertised skill purpose. In the context of an agent skill, this is especially dangerous because it normalizes handing over signing authority for a hidden or misleading operation, exposing users to gas loss, unintended identity linkage, and erosion of trust boundaries around wallet use.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script performs an ERC-20 approve followed by an on-chain sell with no interactive confirmation, no simulation, and no default slippage/minimum-funds protection in the simple path. Because these blockchain actions are irreversible and move user assets, a typo, malicious wrapper, or automation error can result in immediate token loss or execution at unexpectedly poor terms.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

At the manifest level, the skill advertises npx fourmeme * as an allowed tool without version pinning, enabling execution of mutable code with access to wallet secrets. This is especially dangerous in the skill context because the same tool can create tokens, transfer assets, and register NFTs on-chain.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The manifest allows execution via npx fourmeme *, which can fetch and run whatever version of the package resolves at runtime rather than a reviewed, pinned artifact. In a skill that handles PRIVATE_KEY and performs on-chain writes, this materially increases supply-chain risk because a compromised or newly published package version could immediately gain access to signing capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states that if the user is not writing in Traditional Chinese, the agent must use the English block. This imposes a language policy on all other users rather than offering a language choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This instruction tells users to install @four-meme/four-meme-ai@latest, which causes future executions to drift to unreviewed code. Because the tool can access PRIVATE_KEY and submit transactions, an upstream package compromise or malicious update could steal funds or execute unauthorized transactions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The standalone usage guidance explicitly recommends running npx fourmeme with environment-provided secrets, again relying on unpinned package resolution at execution time. Combining runtime package fetch with wallet credentials is dangerous because any compromised dependency version could read PRIVATE_KEY or alter transaction destinations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The shell export example pairs export PRIVATE_KEY=... with npx fourmeme <command>, which is a risky pattern because it exposes a hot wallet key to whatever package version npx resolves. In a blockchain trading skill, that expands the blast radius of any npm account compromise, dependency hijack, or typo-squatted package resolution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Although this line says not to invoke npx tsx directly, it still references npx-based execution patterns and the skill generally normalizes remote package execution. That sustains supply-chain risk, though the immediate text is cautionary rather than instructing use of npx tsx for privileged actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Although this line says not to invoke npx tsx directly, it still references npx-based execution patterns and the skill generally normalizes remote package execution. That sustains supply-chain risk, though the immediate text is cautionary rather than instructing use of npx tsx for privileged actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file describes sending a wallet signature, address, region/lang metadata, access token, and an image file to remote private endpoints. Under the markdown-specific warning rule, skills should warn users when behavior may affect privacy or transmit user data, but no such warning appears here.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documentation instructs users to run npx tsx without pinning a specific package version. npx may fetch the latest package from the registry at execution time, creating a supply-chain risk where a compromised, typosquatted, or maliciously updated package version could execute arbitrary code on the user's machine. This is especially sensitive here because the surrounding workflow uses PRIVATE_KEY and blockchain transaction tooling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example again uses npx tsx without an exact version, which can cause runtime retrieval of unpinned code from the npm ecosystem. If an attacker controls or compromises the resolved package, they can run arbitrary code in the same environment that holds wallet credentials and transaction data. In a crypto-token creation workflow, that raises the risk beyond a generic developer-tool example.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command at this line relies on unpinned npx tsx, introducing a supply-chain execution path outside the repository's audited dependencies. Because the workflow exports PRIVATE_KEY and prepares on-chain actions, compromise of the fetched package could lead to credential theft or transaction manipulation before submission.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This line continues the same pattern of invoking npx tsx without version pinning. The danger is arbitrary code execution through package substitution or malicious updates, with elevated consequences here because the script consumes stdin data from the token-creation flow and may run in a wallet-enabled shell session.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The example at this line uses npx tsx unpinned while handling token creation parameters and writing API output that includes values later used for on-chain submission. An attacker able to influence the resolved tsx package could execute code to exfiltrate environment secrets, alter outputs, or tamper with the transaction preparation pipeline.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This tax-token example still instructs execution through unpinned npx tsx. In the context of blockchain tooling, arbitrary code execution from a supply-chain event could not only steal PRIVATE_KEY but also substitute token parameters or recipient addresses, causing financial loss.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This final instance repeats the same unpinned npx tsx invocation pattern, leaving users exposed to npm supply-chain compromise at execution time. The surrounding skill is more dangerous than a generic scripting example because it is explicitly tied to token creation, fee configuration, and use of a private key in the environment.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/create-token-instant.ts:53

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/create-token-api.ts:38